Subscribe
CryptoWeb.xyz
No Result
View All Result
  • Home
  • News
  • Altcoin
  • Bitcoin
  • Blockchain
  • Ethereum
  • Litecoin
  • Home
  • News
  • Altcoin
  • Bitcoin
  • Blockchain
  • Ethereum
  • Litecoin
No Result
View All Result
CryptoWeb.xyz
No Result
View All Result

‘Huge Blow’ to DeFi as Hackers Exploit Known Vulnerability

'Huge Blow' to DeFi as Hackers Exploit Known Vulnerability 101
Source: Adobe/lensw0rld

The DeFi (decentralized finance) industry just suffered another blow that reminds us that DeFi is still very much uncharted territory. What makes it worse is that the vulnerability used has reportedly been known.

A blockchain security company PeckShield offered a detailed look into the attacks and their execution, stating that this was a known reentrancy vulnerability that first occurred on April 18 on Uniswap, a protocol for automated token exchange on Ethereum (ETH), against the imBTC (an Ethereum token valued at 1:1 rate with bitcoin (BTC)) liquidity pool. This was followed by a similar attack on Lendf.Me, the lending protocol in the “decentralized finance protocol” dForce network, a day later.

'Huge Blow' to DeFi as Hackers Exploit Known Vulnerability 102
Source: Defi Pulse

The vulnerability allows a hacker to hijack a transaction and sell the same batch of tokens multiple times. Some ETH 1,278 (USD 232,000) were stolen in the first attack, and c. USD 25.2 million from the second.

Related articles

Bitcoin Price and Ethereum Prediction: Can the Fed Rate Hike Amid Banking Turmoil Boost BTC and ETH?

Long Liquidations Spike Bitcoin Suffers “Sell the Fact” Reaction to Dovish Fed, But BTC Dip-Buyers Will Probably Pounce

Lendf.Me site at the time of writing is offline. On its official Twitter account, dForce Foundation CEO Mindao Yang shared the network’s explanation as to what happened this weekend, confirming the attack as described by PeckShield. “The callback mechanism of ERC777 (imBTC) enabled the hacker to supply and withdraw imBTC repeatedly before the balance was updated,” writes Yang.

Here you can see the loss distribution among top 7 lenders on @LendfMe for these pools. More charts, analysis and also the data will be in DefiWeekly (@kermankohli) in the coming days.

P.S.: I don’t have much time for designing charts now😅 pic.twitter.com/U1ji8IoHl2

— Frank Topbottom (@FrankResearcher) April 19, 2020

Furthermore, Yang states that the hackers “attempted to contact us and we intend to enter into discussions with them.” There are reports that the attacker returned PAX 126,014, HBTC 320, and HUSD 381,000.

Hacker repay assets from @compoundfinance and @AaveAave https://t.co/2CcYkuaqybhttps://t.co/kyBNba6YEl

— Frank Topbottom (@FrankResearcher) April 19, 2020

While the company is working with the law enforcement and exchanges on identifying the attackers, as well as on a more comprehensive security assessment of Lendf.Me as they say, Yang states that the attack was his failure. “While I did not execute it, I should have anticipated it and taken actions to prevent it,” he writes.

There’s even a mitigation mechanism to block such reentrancy attacks, the so-called Checks-Effects-Interactions design pattern, according to PeckShield. They conclude that “The Lendf.Me hack is a huge blow to the current DeFi community.”

Also, their report finds that, while “ERC777 itself is a community-established token standard with its advanced features for various scenarios,[…] these advanced features might not be compatible with certain DeFi scenarios. Worse, such incompatibility could further lead to undesirable consequences (e.g., reentrancy). We also notice that other token standards (e.g., ERC1155) have been similarly designed to have a callback function.”

Furthermore, Tokenlon, the company behind imBTC, wrote in a post mortem report that “The ERC-777 token standard has — to our knowledge — no security vulnerabilities. However, the combination of using ERC777 tokens and Uniswap/Lendf.Me contracts enables the above-mentioned reentrancy attacks.” They note that this exploit was already published on GitHub back in July 2019 by OpenZeppelin, a company that performs security audits for cryptocurrency platforms.

Per Jason Choi, Head of Research at Spartan Group, a blockchain advisory and investment firm, it has happened before, back in 2016.

This exploit was used in the $150M DAO hack:

In simplistic terms, during the hack, you:

– Submit a legitimate withdrawal
– Before the contract could update your balance…
– …recursively withdrew more than you are entitled tohttps://t.co/yPCZL1nprd

4/x

— Jason Choi 蔡浩霆 (@mrjasonchoi) April 19, 2020

Spencer Noon, head of crypto investments at DTC Capital, finds that the attack on Lendf.Me wasn’t surprising, while Twitter user Patrcik Tsoi believes this vulnerability “should be part of the auditing in smart contract before Defi product launching.”

The attack on Lendf.Me follows the announcement by crypto venture capital firm Multicoin Capital that they led a USD 1.5 million round in dForce.
___

Other reactions:

Decentralized finance. Decentralized. We paused it. We paused decentralized finance. 🤥 pic.twitter.com/7ATrBWstR6

— ungrubles (@notgrubles) April 19, 2020

__

Is @MulticoinCap going to do the right thing and make the users whole?https://t.co/Hh2arusMRd

— Pierrrrrrrrrrrrre Rrrrrrrrrrrrocharrrrrrrrrrrrrrrd (@pierre_rochard) April 19, 2020

__

@Excellion The average person only heard about capitalism when something implodes.

— Eating and breathing are both important, mkay? (@SchalkDormehl)

Share122Tweet77Share31
Previous Post

Tencent Taps DAML Smart Contract Language for Chinese State Blockchain Network

Next Post

Ethereum, Tezos Start New Week as Top Weekly Performers

Related Posts

Bitcoin Price and Ethereum Prediction: Can the Fed Rate Hike Amid Banking Turmoil Boost BTC and ETH?
News

Bitcoin Price and Ethereum Prediction: Can the Fed Rate Hike Amid Banking Turmoil Boost BTC and ETH?

Long Liquidations Spike Bitcoin Suffers “Sell the Fact” Reaction to Dovish Fed, But BTC Dip-Buyers Will Probably Pounce
Bitcoin

Long Liquidations Spike Bitcoin Suffers “Sell the Fact” Reaction to Dovish Fed, But BTC Dip-Buyers Will Probably Pounce

Bankruptcy Judge: Celsius Account Holders Can Retrieve 72.5% of Crypto Holdings, Permitted They Opt-In to Settlement Plan
News

Bankruptcy Judge: Celsius Account Holders Can Retrieve 72.5% of Crypto Holdings, Permitted They Opt-In to Settlement Plan

Bitcoin Price Prediction as Fed Announces Interest Rate Decision – Can BTC Reach $30,000 This Week?
News

Bitcoin Price Prediction as Fed Announces Interest Rate Decision – Can BTC Reach $30,000 This Week?

Best Crypto to Buy Now 22 March – LHINU, XLM, FGHT, ALGO, METRO, ETC, CCHG, TARO
News

Best Crypto to Buy Now 22 March – LHINU, XLM, FGHT, ALGO, METRO, ETC, CCHG, TARO

Ethereum Price Prediction as ETH Rallies 6% in 7 Days – How High Can ETH Go in 2023?
Ethereum

Ethereum Price Prediction as ETH Rallies 6% in 7 Days – How High Can ETH Go in 2023?

ADS SIDE

More News

Bitcoin Price and Ethereum Prediction: Can the Fed Rate Hike Amid Banking Turmoil Boost BTC and ETH?

Bitcoin Price and Ethereum Prediction: Can the Fed Rate Hike Amid Banking Turmoil Boost BTC and ETH?

Aussie crypto exchange hints interest in Hong Kong base, but it’ll depend

Aussie crypto exchange hints interest in Hong Kong base, but it’ll depend

Xapo Bank to enable USDC deposits and withdrawals

Xapo Bank to enable USDC deposits and withdrawals

Long Liquidations Spike Bitcoin Suffers “Sell the Fact” Reaction to Dovish Fed, But BTC Dip-Buyers Will Probably Pounce

Long Liquidations Spike Bitcoin Suffers “Sell the Fact” Reaction to Dovish Fed, But BTC Dip-Buyers Will Probably Pounce

Arbitrum’s ARB token signifies the start of airdrop season — Here are 5 to look out for

Arbitrum’s ARB token signifies the start of airdrop season — Here are 5 to look out for

Bankruptcy Judge: Celsius Account Holders Can Retrieve 72.5% of Crypto Holdings, Permitted They Opt-In to Settlement Plan

Bankruptcy Judge: Celsius Account Holders Can Retrieve 72.5% of Crypto Holdings, Permitted They Opt-In to Settlement Plan

Deloitte dives into immersive experiences as more industries turn to Web3

Deloitte dives into immersive experiences as more industries turn to Web3

Ethereum price at $1.4K was a bargain, and a rally toward $2K looks like the next step

Ethereum price at $1.4K was a bargain, and a rally toward $2K looks like the next step

Bitcoin price whipsaws as Fed says rate hikes may not be ‘appropriate’

Bitcoin price whipsaws as Fed says rate hikes may not be ‘appropriate’

French lawmakers propose ban on crypto influencer promotions

French lawmakers propose ban on crypto influencer promotions

  • Advertise with us
  • Contact Us
  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Sitemap

© 2020 Copyright - All rights reserved.

No Result
View All Result
  • Home
  • News
  • Altcoin
  • Bitcoin
  • Blockchain
  • Ethereum
  • Litecoin

© 2020 Copyright - All rights reserved.

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT