Popular DeFi platform Sturdy Finance hacked losing $800,000

TL;DR Breakdown

  • Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000.
  • The attack began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols.
  • BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system.

Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000. The attack was carried out by an unknown individual who exploited a reentrancy vulnerability within the system, enabling them to manipulate a faulty price oracle and siphon off funds.

In decentralized finance (DeFi) applications like Sturdy Finance, price oracles play a crucial role by providing real-world price data. However, they can also serve as a prime target for hackers seeking to exploit vulnerabilities and compromise the security of the platform.

The attack on Sturdy Finance began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols. This type of attack takes advantage of the ability to call a function repeatedly within a single transaction before the original function call is completed. By leveraging this loophole, the attacker was able to withdraw more funds than they were legitimately entitled to.

Sturdy Finance security breach

Once the attacker gained control over the function calls, they proceeded to exploit the price oracle. Sturdy Finance relied on a separate “read-only” smart contract to derive its price oracle, which was responsible for accurately determining the market value of assets in a liquidity pool managed by the protocol on the Balancer decentralized exchange. However, the attacker successfully manipulated the oracle, allowing them to drain funds from Sturdy Finance.

BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system, combined with the manipulation of the price of B-stETH-STABLE.

In response to the attack, Sturdy Finance took immediate action by suspending all of its markets to prevent further potential losses. The team assured users that no additional funds were at risk and that no immediate action was required from the users. They pledged to provide more information as soon as it became available.

Following the attack, on-chain data revealed that the attacker utilized the Tornado Cash mixer to obfuscate their activities. This mixer is a tool used to enhance privacy and make it difficult to trace transactions on the blockchain.

The incident highlights the ongoing challenges and risks associated with decentralized finance and the importance of robust security measures. Sturdy Finance’s swift response in suspending the markets demonstrates its commitment to protecting user funds and mitigating potential losses. As the investigation unfolds, it is hoped that further insights will be gained to prevent similar attacks in the future and strengthen the overall security of decentralized lending protocols.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Popular DeFi platform Sturdy Finance hacked losing $800,000

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月14日 15:11
Next 2023年6月14日 16:10

Related articles

  • Prosecutors appeal bail decision for Terra founder amid allegations of market manipulation

    TL;DR Breakdown Kwon is accused of operating a fraudulent cryptocurrency firm in South Korea. Kwon and Han were apprehended at Podgorica airport in Montenegro, accused of trying to leave the country using counterfeit passports. The Montenegrin court charged them with forging travel documents. The prosecutors in Montenegro have appealed against a local court’s decision that granted bail to Kwon Do-hyeong, the founder of Terraform Labs, and his associate Han Chang-joon. During the hearing, accusations were made against Do Kwon, the founder of Terraform Labs, stating that he operated and organized a fraudulent cryptocurrency firm in South Korea and the United States (U.S.). As a result of these actions, the firm’s TerraUSD and Luna coins experienced a collapse. On March 23, authorities apprehended Kwon and Han, Terra’s former chief financial officer, at Podgorica airport in Montenegro. They were accused of trying to leave the country using counterfeit passports and were subject to an Interpol Red Notice, which urged law enforcement agencies to arrest them. On April 21, the Montenegrin court formally charged both South Korean individuals with the offense of forging…

    Article 2023年5月19日
  • Japan gets ready to dominate global AI chip war

    TL;DR Breakdown Tokyo-based JSR accepted a $6.4 billion buyout offer from the JIC to strengthen Japan’s position in the global semiconductor supply chain. Despite some concerns of covert nationalization, JSR maintains the move is to enhance Japan’s global competitiveness. Analysts see the buyout as a landmark move to prioritize national strategy over financial reasoning. Description A global tech battle is brewing as Japan prepares to carve out its niche in the increasingly contentious AI chip war. Fueled by a government-backed deal, Tokyo-based JSR is poised to strengthen Japan’s stronghold in this heated US-China race for semiconductor supremacy. Unraveling the JSR puzzle Securing a pivotal position in the global semiconductor supply … Read more A global tech battle is brewing as Japan prepares to carve out its niche in the increasingly contentious AI chip war. Fueled by a government-backed deal, Tokyo-based JSR is poised to strengthen Japan’s stronghold in this heated US-China race for semiconductor supremacy. Unraveling the JSR puzzle Securing a pivotal position in the global semiconductor supply chain, JSR recently welcomed a surprising buyout offer from the Japan Investment…

    Article 2023年7月6日
  • Visa explores credit card payments for blockchain gas fees

    TL;DR Breakdown Visa successfully trials payment system for blockchain gas fees using fiat currency. The experiment eliminates the need for Ether holdings, enabling credit card payment of gas costs. Paymaster contract, ERC-4337 integration, and Visa cards central to the innovative approach. Description In a significant step towards enhancing user accessibility to blockchain transactions, Visa, one of the two major credit card networks, has announced successful trials of a pioneering payment system. This innovative approach allows customers to settle on-chain gas fees using conventional fiat currency, eliminating the need for holding Ethereum‘s native tokens solely for covering gas … Read more In a significant step towards enhancing user accessibility to blockchain transactions, Visa, one of the two major credit card networks, has announced successful trials of a pioneering payment system. This innovative approach allows customers to settle on-chain gas fees using conventional fiat currency, eliminating the need for holding Ethereum‘s native tokens solely for covering gas costs. The experimentation phase occurred on the Ethereum Goerli testnet and centered around a paymaster contract strategy. By leveraging this contract with account abstraction and…

    Article 2023年8月12日
  • Exodus wallet empowers users with Sovryn Dollar integration and financial freedom

    TL;DR Breakdown   Exodus integrates Bitcoin-backed stablecoin Sovryn Dollar (DLLR) into its platform. The integration allows Exodus to access operating cash without relying on traditional banking services. Sovryn’s Mynt protocol combines multiple Bitcoin-backed stablecoins, providing distinct options and flexibility for users. Description In a groundbreaking move, Exodus, the renowned cryptocurrency software wallet, has announced the integration of Sovryn Dollar (DLLR), a stablecoin backed by Bitcoin, into its platform. This strategic partnership marks a significant milestone for both companies and signifies the beginning of a new era in financial autonomy and custody. With its extensive experience in the … Read more In a groundbreaking move, Exodus, the renowned cryptocurrency software wallet, has announced the integration of Sovryn Dollar (DLLR), a stablecoin backed by Bitcoin, into its platform. This strategic partnership marks a significant milestone for both companies and signifies the beginning of a new era in financial autonomy and custody. With its extensive experience in the crypto industry since 2015, Exodus boasts a user base of approximately 4 million individuals. The company’s co-founder and CEO, JP Richardson, expressed excitement over including…

    Article 2023年6月29日
  • Kenya’s president really just hates the US dollar

    TL;DR Breakdown Kenyan President, William Ruto, urges African nations to use local currencies in cross-border trades instead of the USD. The African Export-Import Bank (Afreximbank) provides a system for smooth financial exchanges between African traders. Ruto’s call isn’t a rejection of the USD, but a push for African economic independence. Description Kenya’s President, William Ruto, a firm advocate for local currency reliance in Africa, intensifies his campaign against the dollar. The message is clear: it’s high time African nations abandon the use of the currency in cross-border trade and embrace their national currencies. Afreximbank: A tool for currency liberation Ruto’s conviction is not just theoretical but … Read more Kenya’s President, William Ruto, a firm advocate for local currency reliance in Africa, intensifies his campaign against the dollar. The message is clear: it’s high time African nations abandon the use of the currency in cross-border trade and embrace their national currencies. Afreximbank: A tool for currency liberation Ruto’s conviction is not just theoretical but based on existing continental infrastructure, the African Export-Import Bank (Afreximbank). The bank offers a system enabling…

    Article 2023年6月20日
TOP