Popular DeFi platform Sturdy Finance hacked losing $800,000

TL;DR Breakdown

  • Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000.
  • The attack began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols.
  • BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system.

Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000. The attack was carried out by an unknown individual who exploited a reentrancy vulnerability within the system, enabling them to manipulate a faulty price oracle and siphon off funds.

In decentralized finance (DeFi) applications like Sturdy Finance, price oracles play a crucial role by providing real-world price data. However, they can also serve as a prime target for hackers seeking to exploit vulnerabilities and compromise the security of the platform.

The attack on Sturdy Finance began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols. This type of attack takes advantage of the ability to call a function repeatedly within a single transaction before the original function call is completed. By leveraging this loophole, the attacker was able to withdraw more funds than they were legitimately entitled to.

Sturdy Finance security breach

Once the attacker gained control over the function calls, they proceeded to exploit the price oracle. Sturdy Finance relied on a separate “read-only” smart contract to derive its price oracle, which was responsible for accurately determining the market value of assets in a liquidity pool managed by the protocol on the Balancer decentralized exchange. However, the attacker successfully manipulated the oracle, allowing them to drain funds from Sturdy Finance.

BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system, combined with the manipulation of the price of B-stETH-STABLE.

In response to the attack, Sturdy Finance took immediate action by suspending all of its markets to prevent further potential losses. The team assured users that no additional funds were at risk and that no immediate action was required from the users. They pledged to provide more information as soon as it became available.

Following the attack, on-chain data revealed that the attacker utilized the Tornado Cash mixer to obfuscate their activities. This mixer is a tool used to enhance privacy and make it difficult to trace transactions on the blockchain.

The incident highlights the ongoing challenges and risks associated with decentralized finance and the importance of robust security measures. Sturdy Finance’s swift response in suspending the markets demonstrates its commitment to protecting user funds and mitigating potential losses. As the investigation unfolds, it is hoped that further insights will be gained to prevent similar attacks in the future and strengthen the overall security of decentralized lending protocols.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Popular DeFi platform Sturdy Finance hacked losing $800,000

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月14日 15:11
Next 2023年6月14日 16:10

Related articles

  • Binance Australia’s head is optimistic about crypto regulation

    TL;DR Breakdown Ben Rose, Binance Australia’s General Manager, is optimistic about the future of crypto regulations in Australia despite current challenges. Binance Australia faced issues when traditional banking entities pulled their support, citing concerns over scams and frauds. The exchange is focused on restoring its banking ties and reintroducing fiat ramp services for its Australian users. Description In the midst of turbulence in the crypto sector, a silver lining emerges from Down Under. Ben Rose, the General Manager of Binance Australia, displays an unwavering optimism regarding Australia’s impending regulations on digital assets. While the crypto world has faced challenges from both the financial and regulatory sectors, Rose remains steadfast in his belief … Read more In the midst of turbulence in the crypto sector, a silver lining emerges from Down Under. Ben Rose, the General Manager of Binance Australia, displays an unwavering optimism regarding Australia’s impending regulations on digital assets. While the crypto world has faced challenges from both the financial and regulatory sectors, Rose remains steadfast in his belief that the tides will turn in favor of the crypto…

    Article 2023年9月2日
  • Changpeng Zhao applauds Schiff’s unexpected crypto conversion

    TL;DR Breakdown Peter Schiff surprised many by announcing his involvement in a project centered around NFT art on the Bitcoin blockchain. The project involves collaborating with Market Price, an artist, to create a collection of digital assets called Ordinals. The Taproot upgrade allows users to inscribe various forms of content on individual satoshis, the smallest unit of Bitcoin. In a recent lighthearted tweet, CZ, the well-known figure in the cryptocurrency industry, expressed his delight at Peter Schiff’s unexpected conversion. Schiff, who has long been a vocal critic of Bitcoin and cryptocurrencies, surprised many by announcing his involvement in a new project centered around NFT art on the Bitcoin blockchain. The project involves collaborating with Market Price, one of Schiff’s favorite artists, to create a collection of digital assets called Ordinals, akin to NFTs. This collection will feature the highly anticipated original painting titled “Golden Triumph,” as well as a series of prints and Ordinals inscribed on the Bitcoin blockchain. Although Schiff maintains that he has yet to embrace the crypto world fully, his venture into NFTs demonstrates a growing recognition…

    Article 2023年5月31日
  • US Treasury yields fall as investors await inflation data and Fed’s decision

    TL;DR Breakdown US Treasury yields experienced a slight decline, with the 10-year yield dropping just over one basis point to 4.2742%. Investors are closely watching upcoming inflation data, as it will provide crucial insights into the Federal Reserve’s stance on interest rates. Gold prices have been strongly affected by the movement of the US dollar and US Treasuries, which are linked to US interest rates. Description On Tuesday, US Treasury yields experienced a slight decline as investors evaluated the economic outlook, focusing on inflation and its potential implications for Federal Reserve monetary policy. The yield on the 10-year Treasury decreased by just over one basis point to 4.2742%, while the 2-year Treasury yield saw little change and was last trading at … Read more On Tuesday, US Treasury yields experienced a slight decline as investors evaluated the economic outlook, focusing on inflation and its potential implications for Federal Reserve monetary policy. The yield on the 10-year Treasury decreased by just over one basis point to 4.2742%, while the 2-year Treasury yield saw little change and was last trading at just…

    Article 2023年9月13日
  • Injective unveils inEVM, bridging the gap between Solana, Cosmos, and Ethereum

    TL;DR Breakdown Injective introduces inEVM, the first-ever Ethereum Virtual Machine (EVM) capable of achieving composability across Cosmos and Solana. The new platform promises Ethereum developers unmatched access to Injective’s global network, ultra-fast transaction speeds, and a smoother development experience. Description In an era where blockchain integration is more than a luxury—it’s a necessity, Injective steps up to the plate with a groundbreaking innovation. The company has recently unleashed its inEVM platform, designed as a masterstroke to bridge the once disparate worlds of Solana, Cosmos, and Ethereum. This ambitious endeavor is more than just a technical … Read more In an era where blockchain integration is more than a luxury—it’s a necessity, Injective steps up to the plate with a groundbreaking innovation. The company has recently unleashed its inEVM platform, designed as a masterstroke to bridge the once disparate worlds of Solana, Cosmos, and Ethereum. This ambitious endeavor is more than just a technical feat; it signifies a paradigm shift in how blockchains can interact, collaborate, and expand their horizons. As the lines between distinct blockchain networks blur, Injective inEVM emerges…

    Article 2023年9月20日
  • Cryptic Invitation to Shibarium Mainnet: Elon Musk’s Mystery Connection Unveiled

    TL;DR Breakdown Shiba Inu’s lead developer invites Elon Musk to the Shibarium launch at the Blockchain Futuristic Conference in Toronto. Shibarium, a Layer-2 scaling protocol, aims to improve Ethereum’s scalability and empower developers to build decentralized applications. Musk’s recent mention of Shiba Inu adds to the buzz, and the beta test, Puppynet, has already achieved significant milestones. Description Renowned billionaire investor and ardent Dogecoin supporter, Elon Musk, has been cryptically invited to attend the highly anticipated launch of Shibarium, Shiba Inu’s Layer-2 scaling protocol. The invitation was extended by none other than Shytoshi Kusama, the lead developer of Shiba Inu, via a subtle tweet. The event is scheduled to take place during the … Read more Renowned billionaire investor and ardent Dogecoin supporter, Elon Musk, has been cryptically invited to attend the highly anticipated launch of Shibarium, Shiba Inu’s Layer-2 scaling protocol. The invitation was extended by none other than Shytoshi Kusama, the lead developer of Shiba Inu, via a subtle tweet. The event is scheduled to take place during the Blockchain Futuristic Conference, set to be held between August…

    Article 2023年8月1日
TOP