Sushiswap Smart Contract Bug Results in Over $3M in Losses; Head Chef Says Hundreds of ETH Recovered – Defi Bitcoin News

0

[ad_1]

According to several reports, a bug introduced to the decentralized exchange (dex) protocol Sushiswap’s smart contract has resulted in more than $3 million in losses. The blockchain and smart contract security firm Peckshield explained the exploited contract was “deployed in multiple blockchains.”

Dex Platform Sushiswap Suffers From Smart Contract Exploit

Over the weekend, the dex platform Sushiswap saw its RouteProcess02 contract exploited and then distributed across various blockchain networks. Blockchain security firm Certik published an alert after discovering the exploit. The company Peckshield also updated the crypto community via Twitter, noting that Sushiswap’s “RouterProcessor2 contract has an approve-related bug.” It has also been reported that the victim was a well-known crypto advocate called Sifu, who reportedly lost 1,800 ether.

Sifu may not have been the only victim, as Certik’s alert mentions that a few USDC users may have been affected. “We have detected suspicious activity on [0x15d], which is a malicious router,” Certik tweeted. “Revoke permissions if you have approved this router to spend your tokens. Stay safe. Multiple users who had approved the malicious contract have seen their USDC being transferred to [0x29e]. The wallet has taken about $20,000 in the last two hours,” the company added.

A developer known as 0xngmi has detailed that the exploit should only be problematic for those who used Sushiswap during the last four days. “Only users impacted by Sushiswap hack should be those that swapped on Sushiswap in the last 4 days. If you did so, revert approvals ASAP or move your funds in the affected wallet to a new wallet,” 0xngmi tweeted. Sushiswap’s head chef Jared Grey also confirmed the exploit and later detailed that “recovery efforts were underway.”

“We’ve secured a large portion of affected funds in a whitehat security process. If you have performed a whitehat recovery please contact security@sushi.com for next steps,” Grey said at 9:42 a.m. Eastern Time on April 9. “We’ve confirmed recovery of more than 300 ETH from Coffeebabe of Sifu’s stolen funds. We’re in contact with Lido’s team regarding 700 more ETH,” Grey added. Sushiswap’s CTO, Matthew Lilley, followed up later in the day and said that there are currently no issues with using the Sushiswap dex platform.

“There is no risk at this time with using Sushi Protocol, and the UI. All exposure to RouterProcessor2 has been removed from the front end, and all LPing / current swap activity is safe to do,” the Sushiswap CTO explained. “We do ask that all users double-check their approvals, and if an address within this list below has an allowance for any of your tokens to please unapprove as soon as you can,” Lilley added. Just recently, Grey told the community that the Sushiswap team received a subpoena from the U.S. Securities and Exchange Commission (SEC).

Tags in this story

2023 defi hack, Advocate, approval, Blockchain, certik, Coffeebabe, Crypto, CTO, decentralized exchange, decentralized finance, DeFi, Defi Hack, DEX, ether, Exploit, Funds, Hacker, Head Chef, Jared Grey, Lido, LPing, Matthew Lilley, Peckshield, recovery, RouteProcess02, RouterProcessor2, SEC, Security, Sifu, Smart Contract, Subpoena, Sushi Protocol, Sushiswap, swap, UI, USDC, Vulnerability, vulnerability disclosure, whitehat

What do you think can be done to prevent smart contract bugs like this in the future? Share your thoughts in the comments below.

Jamie Redman

Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 6,000 articles for Bitcoin.com News about the disruptive protocols emerging today.

Image Credits: Shutterstock, Pixabay, Wiki Commons

Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.

More Popular News

In Case You Missed It

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 0.000000
ethereum
Ethereum (ETH) $ 0.000000
tether
Tether (USDT) $ 0.000000
bnb
BNB (BNB) $ 0.000000
xrp
XRP (XRP) $ 0.000000
usd-coin
USDC (USDC) $ 0.000000
staked-ether
Lido Staked Ether (STETH) $ 0.000000
tron
TRON (TRX) $ 0.000000
dogecoin
Dogecoin (DOGE) $ 0.000000
cardano
Cardano (ADA) $ 0.000000
figure-heloc
Figure Heloc (FIGR_HELOC) $ 0.000000
whitebit
WhiteBIT Coin (WBT) $ 0.000000
wrapped-steth
Wrapped stETH (WSTETH) $ 0.000000
bitcoin-cash
Bitcoin Cash (BCH) $ 0.000000
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 0.000000
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 0.000000
usds
USDS (USDS) $ 0.000000
chainlink
Chainlink (LINK) $ 0.000000
wrapped-eeth
Wrapped eETH (WEETH) $ 0.000000
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.000000
leo-token
LEO Token (LEO) $ 0.000000
weth
WETH (WETH) $ 0.000000
hyperliquid
Hyperliquid (HYPE) $ 0.000000
monero
Monero (XMR) $ 0.000000
stellar
Stellar (XLM) $ 0.000000
zcash
Zcash (ZEC) $ 0.000000
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 0.000000
ethena-usde
Ethena USDe (USDE) $ 0.000000
litecoin
Litecoin (LTC) $ 0.000000
sui
Sui (SUI) $ 0.000000
avalanche-2
Avalanche (AVAX) $ 0.000000
hedera-hashgraph
Hedera (HBAR) $ 0.000000
shiba-inu
Shiba Inu (SHIB) $ 0.000000
susds
sUSDS (SUSDS) $ 0.000000
usdt0
USDT0 (USDT0) $ 0.000000
dai
Dai (DAI) $ 0.000000
mantle
Mantle (MNT) $ 0.000000
the-open-network
Toncoin (TON) $ 0.000000
world-liberty-financial
World Liberty Financial (WLFI) $ 0.000000
paypal-usd
PayPal USD (PYUSD) $ 0.000000
crypto-com-chain
Cronos (CRO) $ 0.000000
uniswap
Uniswap (UNI) $ 0.000000
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 0.000000
polkadot
Polkadot (DOT) $ 0.000000
memecore
MemeCore (M) $ 0.000000
aave
Aave (AAVE) $ 0.000000
bittensor
Bittensor (TAO) $ 0.000000
usd1-wlfi
USD1 (USD1) $ 0.000000
canton-network
Canton (CC) $ 0.000000
rain
Rain (RAIN) $ 0.000000
Shares