Popular DeFi platform Sturdy Finance hacked losing $800,000

TL;DR Breakdown

  • Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000.
  • The attack began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols.
  • BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system.

Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000. The attack was carried out by an unknown individual who exploited a reentrancy vulnerability within the system, enabling them to manipulate a faulty price oracle and siphon off funds.

In decentralized finance (DeFi) applications like Sturdy Finance, price oracles play a crucial role by providing real-world price data. However, they can also serve as a prime target for hackers seeking to exploit vulnerabilities and compromise the security of the platform.

The attack on Sturdy Finance began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols. This type of attack takes advantage of the ability to call a function repeatedly within a single transaction before the original function call is completed. By leveraging this loophole, the attacker was able to withdraw more funds than they were legitimately entitled to.

Sturdy Finance security breach

Once the attacker gained control over the function calls, they proceeded to exploit the price oracle. Sturdy Finance relied on a separate “read-only” smart contract to derive its price oracle, which was responsible for accurately determining the market value of assets in a liquidity pool managed by the protocol on the Balancer decentralized exchange. However, the attacker successfully manipulated the oracle, allowing them to drain funds from Sturdy Finance.

BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system, combined with the manipulation of the price of B-stETH-STABLE.

In response to the attack, Sturdy Finance took immediate action by suspending all of its markets to prevent further potential losses. The team assured users that no additional funds were at risk and that no immediate action was required from the users. They pledged to provide more information as soon as it became available.

Following the attack, on-chain data revealed that the attacker utilized the Tornado Cash mixer to obfuscate their activities. This mixer is a tool used to enhance privacy and make it difficult to trace transactions on the blockchain.

The incident highlights the ongoing challenges and risks associated with decentralized finance and the importance of robust security measures. Sturdy Finance’s swift response in suspending the markets demonstrates its commitment to protecting user funds and mitigating potential losses. As the investigation unfolds, it is hoped that further insights will be gained to prevent similar attacks in the future and strengthen the overall security of decentralized lending protocols.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Popular DeFi platform Sturdy Finance hacked losing $800,000

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月14日 15:11
Next 2023年6月14日 16:10

Related articles

  • NEAR Foundation and Alibaba Cloud forge powerful partnership to drive Web3 development in Asia

    TL;DR Breakdown The NEAR Foundation and Alibaba Cloud are working together to speed up the growth of Web3 in Asia and the Middle East. The partnership will give NEAR access to the developer community of Alibaba Cloud. Customers can also use the NEAR BOS, a platform coders can build and talk to other users while using Alibaba Cloud’s infrastructure. Description The NEAR Foundation and Alibaba Cloud have formed a strategic relationship to collaborate and speed up the development of dApps and blockchain technology, marking a significant milestone for the Web3 ecosystem in Asia. This partnership is a huge step forward in encouraging creativity, improving scalability, and facilitating widespread use of Web3 solutions in the area. … Read more The NEAR Foundation and Alibaba Cloud have formed a strategic relationship to collaborate and speed up the development of dApps and blockchain technology, marking a significant milestone for the Web3 ecosystem in Asia. This partnership is a huge step forward in encouraging creativity, improving scalability, and facilitating widespread use of Web3 solutions in the area. NEAR Foundation partners with Alibaba Cloud The…

    Article 2023年6月28日
  • TON network announces its new encrypted messaging feature

    TL;DR Breakdown TON Network has announced the release of a new encrypted messaging feature within its network. The foundation wants to drive growth with the new feature. Description The TON network, developed by the TON Foundation, recently unveiled a new on-chain encrypted messaging feature, allowing users to send private messages within the network. TON, which originated from code created by the Telegram instant messaging app team, was forked and open-sourced after Telegram abandoned the project in July 2020 before its mainnet launch. TON … Read more The TON network, developed by the TON Foundation, recently unveiled a new on-chain encrypted messaging feature, allowing users to send private messages within the network. TON, which originated from code created by the Telegram instant messaging app team, was forked and open-sourced after Telegram abandoned the project in July 2020 before its mainnet launch. TON network rolls out a new encrypted feature on the network The TON Foundation has since taken charge of building the current TON network, which is designed to provide greater scalability and transaction throughput while maintaining decentralization within the Web3…

    Article 2023年7月6日
  • Gemini Teases XRP Relisting Soon Following Ripple’s SEC Lawsuit Victory

    TL;DR Breakdown Gemini teases the potential relisting of XRP following Ripple’s legal win against the SEC, which has led to a surge in XRP’s trading volume and price. Gemini’s CEO, Cameron Winklevoss, expresses optimism about Bitcoin accumulation, as spot Bitcoin ETF filings signal growing institutional interest in the leading cryptocurrency. Description United States-based cryptocurrency exchange Gemini has hinted at plans to relist the XRP token on its platform, following Ripple‘s recent legal victory in the U.S. Securities and Exchange Commission (SEC) lawsuit. The development comes in the wake of several top crypto exchanges, including Coinbase and Kraken, already reinstating XRP trading after the July 13, 2023 … Read more United States-based cryptocurrency exchange Gemini has hinted at plans to relist the XRP token on its platform, following Ripple‘s recent legal victory in the U.S. Securities and Exchange Commission (SEC) lawsuit. The development comes in the wake of several top crypto exchanges, including Coinbase and Kraken, already reinstating XRP trading after the July 13, 2023 Summary Judgment by Judge Analisa Torres. Her ruling effectively reopened the doors for XRP trading on…

    Article 2023年7月22日
  • Janet Yellen’s surprising eagerness for collaboration with China

    TL;DR Breakdown Treasury Secretary Janet Yellen exhibits eagerness to collaborate with China, seeking to cultivate beneficial conditions for U.S. corporations in China. Yellen is focusing on debt restructurings, promoting active involvement of bilateral official creditors in pending cases. She advocates for comprehensive reforms in multilateral development banks to meet global challenges like climate change and pandemics. Description Treasury Secretary Janet Yellen’s recent expressions of willingness to foster stronger ties with China heralds a surprising turn of events, reflecting an ambitious perspective on future bilateral relationships. Her refreshing stance has resulted in several key strategies aiming for collaboration with the global powerhouse. Building bridges: The genesis of mutual progress Yellen demonstrated an enthusiastic … Read more Treasury Secretary Janet Yellen’s recent expressions of willingness to foster stronger ties with China heralds a surprising turn of events, reflecting an ambitious perspective on future bilateral relationships. Her refreshing stance has resulted in several key strategies aiming for collaboration with the global powerhouse. Building bridges: The genesis of mutual progress Yellen demonstrated an enthusiastic desire to engage with China during her recent trip to…

    Article 2023年7月17日
  • Robinhood Ventures into Credit Card Market with Acquisition of Fintech X1

    TL;DR Breakdown Robinhood, the popular crypto and stock trading app, is expanding its services by acquiring credit card startup X1 in a $95 million deal. The acquisition allows Robinhood to enter the credit card market, diversify its revenue streams, and strengthen its relationship with customers, offering them additional financial services beyond trading. Description Robinhood, the popular crypto and stock trading app, is set to diversify its offerings through the acquisition of credit card startup X1. The $95 million deal will provide Robinhood with a new revenue stream and deepen its relationship with existing customers. With X1’s income-based credit card and unique features like rewards, free trial, and single-use … Read more Robinhood, the popular crypto and stock trading app, is set to diversify its offerings through the acquisition of credit card startup X1. The $95 million deal will provide Robinhood with a new revenue stream and deepen its relationship with existing customers. With X1’s income-based credit card and unique features like rewards, free trial, and single-use cards, Robinhood aims to enhance its financial services ecosystem. This article delves into the…

    Article 2023年6月25日
TOP