Popular DeFi platform Sturdy Finance hacked losing $800,000

TL;DR Breakdown

  • Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000.
  • The attack began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols.
  • BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system.

Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000. The attack was carried out by an unknown individual who exploited a reentrancy vulnerability within the system, enabling them to manipulate a faulty price oracle and siphon off funds.

In decentralized finance (DeFi) applications like Sturdy Finance, price oracles play a crucial role by providing real-world price data. However, they can also serve as a prime target for hackers seeking to exploit vulnerabilities and compromise the security of the platform.

The attack on Sturdy Finance began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols. This type of attack takes advantage of the ability to call a function repeatedly within a single transaction before the original function call is completed. By leveraging this loophole, the attacker was able to withdraw more funds than they were legitimately entitled to.

Sturdy Finance security breach

Once the attacker gained control over the function calls, they proceeded to exploit the price oracle. Sturdy Finance relied on a separate “read-only” smart contract to derive its price oracle, which was responsible for accurately determining the market value of assets in a liquidity pool managed by the protocol on the Balancer decentralized exchange. However, the attacker successfully manipulated the oracle, allowing them to drain funds from Sturdy Finance.

BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system, combined with the manipulation of the price of B-stETH-STABLE.

In response to the attack, Sturdy Finance took immediate action by suspending all of its markets to prevent further potential losses. The team assured users that no additional funds were at risk and that no immediate action was required from the users. They pledged to provide more information as soon as it became available.

Following the attack, on-chain data revealed that the attacker utilized the Tornado Cash mixer to obfuscate their activities. This mixer is a tool used to enhance privacy and make it difficult to trace transactions on the blockchain.

The incident highlights the ongoing challenges and risks associated with decentralized finance and the importance of robust security measures. Sturdy Finance’s swift response in suspending the markets demonstrates its commitment to protecting user funds and mitigating potential losses. As the investigation unfolds, it is hoped that further insights will be gained to prevent similar attacks in the future and strengthen the overall security of decentralized lending protocols.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Popular DeFi platform Sturdy Finance hacked losing $800,000

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月14日 15:11
Next 2023年6月14日 16:10

Related articles

  • Binance Pay’s grand entry into Brazil: Paving the way for cryptocurrency payments

    TL;DR Breakdown Binance Pay, a contactless and secure cryptocurrency payment platform, has been introduced in Brazil, supporting over 70 cryptocurrencies and offering merchants flexible payment options. With global crypto adoption on the rise, Binance Pay’s launch in Brazil signifies the country’s commitment to innovative payment solutions and its position as a leader in the crypto revolution. Description In a groundbreaking move, Binance, the world’s premier cryptocurrency exchange, has unveiled Binance Pay in Brazil. This innovative payment platform promises to offer local merchants a seamless, efficient, and cost-effective alternative to traditional payment methods, marking a significant shift in the country’s financial landscape. Contents hide 1 Binance Pay: A revolutionary payment solution for Brazil … Read more In a groundbreaking move, Binance, the world’s premier cryptocurrency exchange, has unveiled Binance Pay in Brazil. This innovative payment platform promises to offer local merchants a seamless, efficient, and cost-effective alternative to traditional payment methods, marking a significant shift in the country’s financial landscape. Contents hide 1 Binance Pay: A revolutionary payment solution for Brazil 2 The global crypto adoption wave and Binance Pay’s impressive…

    Article 2023年8月23日
  • Deloitte and Chainalysis Form Strategic Alliance to Enhance Digital Asset Compliance Solutions

    TL;DR Breakdown Deloitte and Chainalysis partner to provide mutual clients with access to Chainalysis’ blockchain dataset and analytics software, complemented by Deloitte’s services for enhanced compliance and risk management. The alliance seeks to meet the rising demand for innovative technology solutions and services amidst evolving regulatory expectations and growing digital asset adoption. With a focus on forensic, investigative, and compliance programs, the collaboration empowers clients with cutting-edge tools to thrive in the dynamic world of digital assets. Description In a transformative move set to redefine the landscape of digital asset compliance, two industry giants, Deloitte and Chainalysis, have joined forces to announce a strategic alliance. With the soaring adoption of digital assets and the evolving regulatory landscape, businesses face unprecedented challenges in navigating the complex world of risk management and compliance. In response … Read more In a transformative move set to redefine the landscape of digital asset compliance, two industry giants, Deloitte and Chainalysis, have joined forces to announce a strategic alliance. With the soaring adoption of digital assets and the evolving regulatory landscape, businesses face unprecedented challenges in…

    Article 2023年7月26日
  • EOS network foundation initiates legal action against Block.one

    TL;DR Breakdown EOS network foundation has taken legal action against Block.one over failure to pay investment commitments. Implications of the lawsuit on the companies and the wider crypto community. Description The EOS Network Foundation (ENF) has taken legal action against major investor Block.one (B1), alleging a failure to fulfill $1 billion in investment commitments. ENF founder and CEO, Yves La Rose, recently announced on Twitter that the foundation is preparing a lawsuit against B1 for its failure to follow through on its $1 billion commitment. … Read more The EOS Network Foundation (ENF) has taken legal action against major investor Block.one (B1), alleging a failure to fulfill $1 billion in investment commitments. ENF founder and CEO, Yves La Rose, recently announced on Twitter that the foundation is preparing a lawsuit against B1 for its failure to follow through on its $1 billion commitment. EOS network wants Block.one to pay $1 billion in investment commitments Block.one is currently working to settle another class-action lawsuit for $22 million after a previously proposed $27.5 million settlement with lead plaintiff Crypto Assets Opportunity was…

    Article 2023年7月27日
  • There is a global race to regulate AI innovations

    TL;DR Breakdown A global race to regulate AI is underway as governments grapple with the implications of advanced tools like ChatGPT. Australia is seeking advice from scientific bodies, the UK is formulating guidelines with input from the Alan Turing Institute, and China requires security assessments for new AI services. The race is on. A worldwide pursuit to reign in the boundless frontiers of artificial intelligence (AI) is underway, reflecting our global society’s struggle to grapple with the implications of rapidly progressing technology. Emerging AI tools like ChatGPT, backed by tech behemoth Microsoft, are finding themselves under scrutiny from national and international governing bodies. This global endeavor underlines a growing realization of the pressing need to determine rules for the game as AI continues its relentless advance. A global shifting legal landscape for AI Australia is looking to fortify its legal stance on AI, inviting input from the nation’s key scientific advisory bodies. Aiming to craft a comprehensive strategy to regulate AI, the government is on the brink of a new era in technology policy. Meanwhile, in the United Kingdom, the…

    Article 2023年6月7日
  • Can You Buy Cryptocurrency With A Credit Card?

    The answer is yes. Many users prefer credit cards for a variety of reasons. Here’s why you should consider using one to buy crypto. Some users prefer wallets or bank transfers to buy crypto. These methods incur the lowest fees, but they can be slow for someone that likes convenience and speed. In this case, credit cards are the best option. At Toobit, you can buy crypto with everyday fees using a VISA or Mastercard credit card. Alternatively, Toobit also provides crypto purchases via fiat deposit. If you’re interested in buying crypto with a credit card, check if your card issuer and payment network allow the transaction type. Credit card issuers that block crypto purchases have varying reasons. Capital One, for example, decided to decline cryptocurrency purchases to protect cardholders from fraud, losses, and market volatility. Note: To ensure your credit card is suitable, we recommend double-checking before initiating any crypto transaction with your credit card issuer. Why Should I Buy Crypto With a Credit Card? Here are all the benefits of using one to buy crypto — which often…

    2023年5月30日
TOP