Monday, September 25, 2023
NEVERFOMOAGAIN
en English▼
X
ar Arabicen Englishfr Frenchde Germanpt Portugueseru Russianes Spanish
  • PASSIVE INCOME
    • How to Earn Cryptocurrencies for free ?
    • Play Games & apps to earn
  • Reviews
  • BLOCKCHAIN ACADEMY
  • TOP 10
  • News
No Result
View All Result
NEVERFOMOAGAIN
NEVERFOMOAGAIN
en English▼
X
ar Arabicen Englishfr Frenchde Germanpt Portugueseru Russianes Spanish
Home CryptoCurrency News

Attackers Steal $24 Million From Several DeFi Projects in Curve Pool Exploits

André Beganski by André Beganski
July 30, 2023
in CryptoCurrency News
Reading Time: 7 mins read
0
Attackers Steal $24 Million From Several DeFi Projects in Curve Pool Exploits
74
SHARES
1.2k
VIEWS
Share on FacebookShare on TwitterShare on Reddit



Several decentralized finance protocols were hit on Sunday by attackers who stole more than $24 million worth of crypto. The attackers leveraged a vulnerability in liquidity pools on Curve, the automated market maker platform.

You might also like

Terra Classic Community Votes to End Minting, Reminting of USTC Tokens

Writers Guild, Studios Reach Tentative Deal Covering AI, Streaming Services

South Korea’s UpBit Temporarily Freezes Withdrawals Following Scam Token Airdrop

The vulnerability was traced back to Vyper, an alternative, third-party programming language for Ethereum smart contracts, according to Curve on Twitter. Curve said other liquidity pools that don’t leverage the language are fine.

A number of stablepools (alETH/msETH/pETH) using Vyper 0.2.15 have been exploited as a result of a malfunctioning reentrancy lock. We are assessing the situation and will update the community as things develop.

Other pools are safe. https://t.co/eWy2d3cDDj

— Curve Finance (@CurveFinance) July 30, 2023

Liquidity pools are smart contracts that hold tokens, and they can provide liquidity to crypto markets in a way that doesn’t rely on financial intermediaries. But, as several projects learned on Sunday, a small flaw can yield substantial losses.

$11 million worth of cryptocurrency was stolen from the NFT lending protocol JPEG’d, according to decentralized finance security firm Decurity. JPEG’d was among the first to identify an issue with its pool on Curve.

“There was an attack,” JPEG’d said on Twitter. “We’ve been looking into the issue the moment we were made aware and […] the issue seems to be related to the Curve pool.”

JPEG’d enables users to post NFTs as collateral for loans. In terms of assets deposited into JPEG’d, the protocol has a total value locked (TVL) of around $32 million. JPEG’d said code responsible for safekeeping NFTs and treasury funds was unaffected.

The protocol’s governance token JPEG was down 23% as of this writing, according to data from CoinGecko. On Sunday, the coin scraped by an all-time low of $0.000347.

In a now-deleted Tweet, Curve initially described the vulnerability as a run-of-the-mill, read-only “re-entrancy” attack that could’ve been avoided. A re-entrancy attack happens when a smart contract interacts with another contract, which in turn calls back to the first contract before fully executing.

Re-entrancy vulnerabilities allow an attacker to cram multiple calls into a single function and trick a smart contract into calculating improper balances. One of the most prominent examples of was the $55 million 2016 DAO hack on Ethereum.

Replying to a Twitter account that reprised the scrubbed statement later, however, Curve said its initial impression was wrong. 

“Yep, not read-only,” Curve said, adding there was “no wrongdoing on the side of projects who integrated, or even users of vyper.”

Yep, not read only. No wrongdoing on the side of the projects who integrated, or even users of vyper here

— Curve Finance (@CurveFinance) July 30, 2023

Re-entrancy attacks are an all-too-common vector for attackers to pilfer protocols, Meir Dolev, co-founder and CTO of cybersecurity firm Cyvers, told Decrypt.

“They are quite common,” Dolev said. “And it’s possible to avoid them with the proper design and development.”

The issue wasn’t specific to JPEG’d. Not long after the NFT lending protocol was exploited, Alchemix and Metronome DAO lost $13.6 million and $1.6 million respectively in a similar manner, he said.

Alchemix acknowledged on Twitter that it is actively working to fix a problem with its liquidity pool. MetronomeDAO said on Twitter its investigation of what happened is ongoing, describing the attack as “part of a broader set of exploits.”

In the case of JPEG’d, the attacker was front-run by a maximal extractable value (MEV) bot, Dolev said. The bot identified the would-be attacker’s transaction and paid a fee to execute a similar transaction ahead of them.

Vyper said on Twitter that it was the programming language’s compiler that had failed. When a developer is finished writing code, it is then compiled from a human-readable format into a form that computers can execute. 

This prevented re-entry guards—protections that were included in the projects’ code and should guard against re-entry attacks—from working, Dolev said. 

“The compiler, in some versions, failed to compile it in the right way,” Dolev said. “It has some bugs or failures.”

Stay on top of crypto news, get daily updates in your inbox.





Source link

Share30Tweet19Share
André Beganski

André Beganski

Recommended For You

Terra Classic Community Votes to End Minting, Reminting of USTC Tokens

by Nicholas Morgan
September 25, 2023
0
Terra Classic Community Votes to End Minting, Reminting of USTC Tokens

The Terra Classic community has voted to end the minting and reminting of Terra Classic USD (USTC) tokens more than a year after its collapse sparked a widespread...

Read more

Writers Guild, Studios Reach Tentative Deal Covering AI, Streaming Services

by Decrypt AI, Edited by Ryan Ozawa
September 25, 2023
0
AI Emerges as a Common Enemy for Actors and Writers in Hollywood

The Writers Guild of America has reached a tentative agreement with the Alliance of Motion Picture and Television Producers after a 146-day strike that crippled Hollywood, the guild...

Read more

South Korea’s UpBit Temporarily Freezes Withdrawals Following Scam Token Airdrop

by Nicholas Morgan
September 25, 2023
0
Aptos Jumps 10% Overnight as South Korea Trading Volumes Spike

Upbit, the largest centralized cryptocurrency exchange in South Korea, temporarily suspended deposits and withdrawals after reportedly mistaking a scam token for legitimate ones from Aptos (APT). The freeze took...

Read more

Inscription Craze Leaves Thousands of Bitcoin Transactions Unconfirmed

by Pedro Solimano
September 24, 2023
0
What's a Bitcoin Drivechain and Why Are Devs At Odds Over Its Proposal?

Over the years, Bitcoin’s network has been no stranger to long lines of transactions waiting to get confirmed, which forces fees to skyrocket and triggers alarms across Crypto...

Read more

Coinbase Bitcoin Holdings Rival Those of Cryptocurrency Creator Satoshi Nakamoto: Arkham

by Nicholas Morgan
September 24, 2023
0
Coinbase Bitcoin Holdings Rival Those of Cryptocurrency Creator Satoshi Nakamoto: Arkham

Coinbase, the largest cryptocurrency exchange in the United States, is holding onto $25 billion in Bitcoin reserves, an amount that rivals the holdings of Bitcoin’s founder Satoshi Nakamoto. In...

Read more
Next Post
Embattled U.S. Rep. George Santos Pitched Crypto Deal to Donor: NYT

Embattled U.S. Rep. George Santos Pitched Crypto Deal to Donor: NYT

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

three − one =

Support Us.

Donate

  • Donate withMetaMask
  • Donate With MetaMask

  • Donate withNano
  • Donate Nano

    Scan to Donate Nano to nano_38oxm7kwnysjeyz1mdcp9d5rrq55wyox3gm9ejeed3uhdieurwe4r3k39ntt

Cloud

#Avoid Crypto Scam #Banano #BAT #Bitcoin #Brave Browser #Coinbase #Coinbase Earn #CoinMarketCap #CoinMarketCap Earn #Counter-Strike: Global Offensive #Crypto App #Cryptocurrency Faucet #Cryptocurrency glossary #Cryptocurrency scam #Crypto redflags #CryptoRoyale #Crypto scam #Cryptos Wallet #Do Your Own Research #DYOR #DYOR Checklist #Earn Cryptocurrencies #Earning while browsing #Earn NFT #Folding@Home #Free cryptocurrencies #Free NFT #Hi Dollar #Just cause 2 #Learn Crypto #LIKE #Low-cap cryptocurrencies #NANO #NFT #PERP #Play to earn #PRE #Princeton University #Redflags #Review #ROY #Top 10 #URUS #xMOON #XMS
NEVERFOMOAGAIN

© 2021 By NEVERFOMOAGAIN - All rights reserved.

Navigate Site

  • Best Play to Earn Crypto games and Apps
  • Contact Us
  • Content licensing
  • Cryptocurrency News
  • Cryptocurrency Rankings
  • Home
  • How to Earn Cryptocurrencies for free ?
  • How to Learn about Crypto and Blockchain ?
  • Legal Information.
  • Privacy policy
  • Reviews
  • Terms & Conditions

Follow Us

No Result
View All Result
  • PASSIVE INCOME
    • How to Earn Cryptocurrencies for free ?
    • Play Games & apps to earn
  • Reviews
  • BLOCKCHAIN ACADEMY
  • TOP 10
  • News

© 2021 By NEVERFOMOAGAIN - All rights reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Go to mobile version