Popular DeFi platform Sturdy Finance hacked losing $800,000

TL;DR Breakdown

  • Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000.
  • The attack began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols.
  • BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system.

Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000. The attack was carried out by an unknown individual who exploited a reentrancy vulnerability within the system, enabling them to manipulate a faulty price oracle and siphon off funds.

In decentralized finance (DeFi) applications like Sturdy Finance, price oracles play a crucial role by providing real-world price data. However, they can also serve as a prime target for hackers seeking to exploit vulnerabilities and compromise the security of the platform.

The attack on Sturdy Finance began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols. This type of attack takes advantage of the ability to call a function repeatedly within a single transaction before the original function call is completed. By leveraging this loophole, the attacker was able to withdraw more funds than they were legitimately entitled to.

Sturdy Finance security breach

Once the attacker gained control over the function calls, they proceeded to exploit the price oracle. Sturdy Finance relied on a separate “read-only” smart contract to derive its price oracle, which was responsible for accurately determining the market value of assets in a liquidity pool managed by the protocol on the Balancer decentralized exchange. However, the attacker successfully manipulated the oracle, allowing them to drain funds from Sturdy Finance.

BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system, combined with the manipulation of the price of B-stETH-STABLE.

In response to the attack, Sturdy Finance took immediate action by suspending all of its markets to prevent further potential losses. The team assured users that no additional funds were at risk and that no immediate action was required from the users. They pledged to provide more information as soon as it became available.

Following the attack, on-chain data revealed that the attacker utilized the Tornado Cash mixer to obfuscate their activities. This mixer is a tool used to enhance privacy and make it difficult to trace transactions on the blockchain.

The incident highlights the ongoing challenges and risks associated with decentralized finance and the importance of robust security measures. Sturdy Finance’s swift response in suspending the markets demonstrates its commitment to protecting user funds and mitigating potential losses. As the investigation unfolds, it is hoped that further insights will be gained to prevent similar attacks in the future and strengthen the overall security of decentralized lending protocols.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Popular DeFi platform Sturdy Finance hacked losing $800,000

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月14日 15:11
Next 2023年6月14日 16:10

Related articles

  • Crypto traders bet on Asia as the US crackdown the market

    TL;DR Breakdown Asia is fast becoming the new center of gravity for crypto markets as the United States SEC moves to dismantle the DeFi market in the country.  Asian crypto markets shine despite the sanctions put by China and India – two countries with the largest populations in the region. The pivot toward Asia was underway even before the SEC under Chair Gary Gensler launched a wide-reaching clampdown in 2023. Description Amidst a backdrop of mounting regulatory scrutiny and a recent crackdown on crypto in the United States, Asia has emerged as a thriving hub for crypto traders seeking a haven for their digital assets. As the global crypto landscape undergoes significant shifts, regulatory clarity and growing adoption of digital currencies in countries across Asia have … Read more Amidst a backdrop of mounting regulatory scrutiny and a recent crackdown on crypto in the United States, Asia has emerged as a thriving hub for crypto traders seeking a haven for their digital assets. As the global crypto landscape undergoes significant shifts, regulatory clarity and growing adoption of digital currencies in…

    Article 2023年6月26日
  • Gasparino’s fiery encounter with XRP ‘cult’ leaves Ripple community divided

    TL;DR Breakdown Gasparino engages in a heated dispute with the XRP community, labeling them a “cult.” Ripple faces potential penalties of up to $1 billion in its legal battle with the SEC. Gasparino questions Ripple’s ability to handle the financial blow and suggests potential strategies. Description In a clash of titans, Fox Business’ Charles Gasparino finds himself embroiled in a fiery dispute with members of the XRP community, whom he has boldly labeled a “cult.” The ongoing legal struggle between Ripple and the SEC provides the backdrop for Gasparino’s encounters with the passionate XRP backers, resulting in frustration and professional exhilaration … Read more In a clash of titans, Fox Business’ Charles Gasparino finds himself embroiled in a fiery dispute with members of the XRP community, whom he has boldly labeled a “cult.” The ongoing legal struggle between Ripple and the SEC provides the backdrop for Gasparino’s encounters with the passionate XRP backers, resulting in frustration and professional exhilaration for the Fox anchor. Gasparino, known for his outspoken nature, took to Twitter to recount his tumultuous interactions with the XRP…

    Article 2023年7月17日
  • PayPal PYUSD Stablecoin is 100% Backed – Reports

    TL;DR Breakdown The report affirms that PYUSD is fully collateralized with assets. In addition to Treasury-backed assets, Paxos disclosed that it held $1,500,146 in fiat currency within insured depository institutions as cash deposits. This transparency report comes on the heels of Paxos and PayPal’s joint launch of PYUSD. Description Paxos, the stablecoin issuer, has taken a significant step in enhancing transparency within the cryptocurrency industry by releasing the inaugural transparency report for its Ethereum-based stablecoin, PayPal USD (PYUSD). This report affirms that PYUSD is fully collateralized with assets, underlining its commitment to maintaining the stability and integrity of this digital currency. The transparency report, … Read more Paxos, the stablecoin issuer, has taken a significant step in enhancing transparency within the cryptocurrency industry by releasing the inaugural transparency report for its Ethereum-based stablecoin, PayPal USD (PYUSD). This report affirms that PYUSD is fully collateralized with assets, underlining its commitment to maintaining the stability and integrity of this digital currency. The transparency report, which covers data up to August 31, 2023, provides a comprehensive overview of the assets backing PYUSD and…

    Article 2023年9月14日
  • Is Worldcoin’s identity verification safe? data protection authorities on high alert

    TL;DR Breakdown The Bavarian State Office for Data Protection Supervision (BayLDA) has initiated an investigation into the human identity verification project known as Worldcoin, citing concerns over the handling of biometric data. The project’s data collection methods also came under criticism from the French National Commission on Informatics and Liberty, who questioned their legality and ethics.  Description The Bavarian State Office for Data Protection Supervision (BayLDA) has initiated an investigation into the human identity verification project known as Worldcoin, citing concerns over the handling of biometric data. According to a report from Reuters on July 31, this investigation was launched in November 2022. Worldcoin’s primary objective was to differentiate real individuals from … Read more The Bavarian State Office for Data Protection Supervision (BayLDA) has initiated an investigation into the human identity verification project known as Worldcoin, citing concerns over the handling of biometric data. According to a report from Reuters on July 31, this investigation was launched in November 2022. Worldcoin’s primary objective was to differentiate real individuals from bots by utilizing retinal scans for identity verification, and the…

    Article 2023年8月1日
  • Cryptocurrency exchange Crypto.com battles user over mistaken $50,000 deposit

    TL;DR Breakdown Crypto.com seeks court confirmation of an arbitration award after mistakenly depositing $50,000 into a user’s account. The user promptly transferred the money to an offshore bank account and refused to return it. The arbitrator ruled in favour of Crypto.com and awarded them $76,391.46 but lacked the authority to compel the user to pay. Description Crypto.com, the leading cryptocurrency exchange, has taken legal action to secure confirmation of an arbitration award in its favour after a user’s account was wrongly credited with $50,000. According to court documents filed on July 6, Crypto.com claimed the funds were mistakenly deposited into James Deutero McJunkins’ account in June 2022. McJunkins swiftly transferred the … Read more Crypto.com, the leading cryptocurrency exchange, has taken legal action to secure confirmation of an arbitration award in its favour after a user’s account was wrongly credited with $50,000. According to court documents filed on July 6, Crypto.com claimed the funds were mistakenly deposited into James Deutero McJunkins’ account in June 2022. McJunkins swiftly transferred the money to an offshore bank account, evading Crypto.com’s attempts to recover…

    Article 2023年7月9日
TOP