Popular DeFi platform Sturdy Finance hacked losing $800,000

TL;DR Breakdown

  • Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000.
  • The attack began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols.
  • BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system.

Sturdy Finance, a decentralized lending protocol, experienced a significant security breach today, resulting in a loss of 442 ether, equivalent to approximately $800,000. The attack was carried out by an unknown individual who exploited a reentrancy vulnerability within the system, enabling them to manipulate a faulty price oracle and siphon off funds.

In decentralized finance (DeFi) applications like Sturdy Finance, price oracles play a crucial role by providing real-world price data. However, they can also serve as a prime target for hackers seeking to exploit vulnerabilities and compromise the security of the platform.

The attack on Sturdy Finance began with a reentrancy attack, a method commonly employed to fraudulently withdraw funds from DeFi protocols. This type of attack takes advantage of the ability to call a function repeatedly within a single transaction before the original function call is completed. By leveraging this loophole, the attacker was able to withdraw more funds than they were legitimately entitled to.

Sturdy Finance security breach

Once the attacker gained control over the function calls, they proceeded to exploit the price oracle. Sturdy Finance relied on a separate “read-only” smart contract to derive its price oracle, which was responsible for accurately determining the market value of assets in a liquidity pool managed by the protocol on the Balancer decentralized exchange. However, the attacker successfully manipulated the oracle, allowing them to drain funds from Sturdy Finance.

BlockSec, a security firm, identified the root cause of the breach as the typical reentrancy vulnerability in Balancer’s system, combined with the manipulation of the price of B-stETH-STABLE.

In response to the attack, Sturdy Finance took immediate action by suspending all of its markets to prevent further potential losses. The team assured users that no additional funds were at risk and that no immediate action was required from the users. They pledged to provide more information as soon as it became available.

Following the attack, on-chain data revealed that the attacker utilized the Tornado Cash mixer to obfuscate their activities. This mixer is a tool used to enhance privacy and make it difficult to trace transactions on the blockchain.

The incident highlights the ongoing challenges and risks associated with decentralized finance and the importance of robust security measures. Sturdy Finance’s swift response in suspending the markets demonstrates its commitment to protecting user funds and mitigating potential losses. As the investigation unfolds, it is hoped that further insights will be gained to prevent similar attacks in the future and strengthen the overall security of decentralized lending protocols.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Popular DeFi platform Sturdy Finance hacked losing $800,000

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月14日 15:11
Next 2023年6月14日 16:10

Related articles

  • Kenyan court declares Meta as the primary employer in its lawsuit

    TL;DR Breakdown A Kenyan court has ruled that Meta is the primary employer in a lawsuit. Analysts discuss the implications of the case on Meta and Sama. A recent ruling by a Kenyan court has declared that Meta, the parent company of Facebook, is the primary employer of content moderators involved in a lawsuit against the social media giant and its content review partner in Africa, Sama. The lawsuit, filed in March of this year by 184 moderators, alleged unlawful dismissal and claimed that Meta’s new content review partner on the continent, Majorel, had blacklisted them based on Meta’s instruction. The Kenyan court said the moderators were contracted to Meta Justice Byram Ongaya of Kenya’s employment and labor relations court watered down Meta’s attempt to distance itself from the case. The court determined that the moderators performed work for Meta using its technology, adhered to its performance and accuracy metrics and that Sama was merely an agent or manager acting on behalf of Meta. Sama, on the other hand, disputed this claim, stating that it is a client of Sama’s…

    Article 2023年6月8日
  • Tether hits $3.3B in excess reserves, holds $72.5B worth of U.S. Treasury bills

    TL;DR Breakdown Tether has released its assurance opinion for Q2 of 2023, highlighting a $850 million rise in excess reserves to reach $3.3 billion. Tether’s operational profitability was $1 billion from April to June 2023, with a 30% rise over Q1 2023. USDT’s market cap hit a new high in July, approaching $84 million. Description Tether Holdings Limited published its assurance opinion for Q2 of 2023, highlighting a $850 million rise in excess reserves to reach $3.3 billion. The report shows that Tether has been adding on its treasury reserved holding for USDT tokens. The report is the first time the company has disclosed its indirect exposure to United States … Read more Tether Holdings Limited published its assurance opinion for Q2 of 2023, highlighting a $850 million rise in excess reserves to reach $3.3 billion. The report shows that Tether has been adding on its treasury reserved holding for USDT tokens. The report is the first time the company has disclosed its indirect exposure to United States Treasury bills held by money market funds, where it holds about $72.5…

    Article 2023年8月1日
  • Ripple’s legal team and SEC engage in war of words over lawsuit tactics

    TL;DR Breakdown Ripple’s Chief Legal Officer, Stuart Alderoty, criticized the SEC’s latest court filing as a “hypocritical pivot,” accusing the regulatory body of inconsistencies in its stance on cryptocurrency regulations. The SEC’s recent filing accuses Ripple Labs of intentionally prolonging the lawsuit to maintain public sales of XRP, a claim that has sparked outrage and allegations of hypocrisy from the Ripple community. Prominent defense lawyer James Filan and other legal experts have questioned the SEC’s sincerity in wanting to conserve judicial resources, pointing out that the SEC itself has been known for employing delay tactics in the case. Description Stuart Alderoty, Ripple’s Chief Legal Officer, has labeled the U.S. Securities and Exchange Commission’s (SEC) latest court filing as a “hypocritical pivot,” escalating tensions in the ongoing legal battle between the two entities. Alderoty took to social media to criticize the SEC’s recent submission, which aimed to reinforce its interlocutory appeal.  He pointed out what … Read more Stuart Alderoty, Ripple’s Chief Legal Officer, has labeled the U.S. Securities and Exchange Commission’s (SEC) latest court filing as a “hypocritical pivot,” escalating…

    Article 2023年9月10日
  • Best crypto memes of the day – August 31st

    Description Hodling #Bitcoin: pic.twitter.com/8t0SrIjhVe — naiive (@naiivememe) August 31, 2023 #Bitcoin pic.twitter.com/C4joHXmbSc — naiive (@naiivememe) August 31, 2023 #Bitcoin @TheKiffness pic.twitter.com/3o0eJIhP4S — naiive (@naiivememe) August 31, 2023 When you’re holding your memecoin for too long, and price dumps. pic.twitter.com/hf1ythvDj8 — Whale (@WhaleChart) August 31, 2023 #Bitcoin pic.twitter.com/DAqWetPnBH — naiive (@naiivememe) August 30, 2023 GM pic.twitter.com/yIHiMjVswM — Devchart 👨🏻‍💻 (@devchart) August 31, 2023 #Bitcoin 🔥🤓📈 pic.twitter.com/GlCEP5XV8z — Kevin Svenson (@KevinSvenson_) August 30, 2023 When every altcoin is mooning but yours pic.twitter.com/VBw4zHOYU4 — Altcoin Sherpa (@AltcoinSherpa) August 29, 2023 #Bitcoin pic.twitter.com/qjcPX5birK — naiive (@naiivememe) August 30, 2023 Do your research then buy the DIP#Cryptomeme #Memes #NFT #ETH #Dogecoin #Crypto #NFTmeme #RespectMeme #Memes #cryptomemes #cryptocurrency #CryptoTwitter #Ethereum #CryptoCommunity #BTCETF #memecoins pic.twitter.com/8rwxh4mGiO — Crypto Memes (@MemesMoneyco) August 31, 2023 Don’t Stop just Buy Bitcoin#Cryptomeme #Memes #NFT #ETH #Dogecoin #Crypto #NFTmeme #RespectMeme #Memes #cryptomemes #cryptocurrency #CryptoTwitter #Ethereum #CryptoCommunity #BTCETF #memecoins pic.twitter.com/Gs4Md03AVh — Veronika_Geraimovich (@Veronika_Crypto) August 31, 2023 #crypto #CryptoMeme #memecoins #Memes #bullrun pic.twitter.com/oqBGnA18Yl — LOL Crypto Club (@LOLCryptoClub) August 31, 2023 Always deposit and never withdraw 😁👍#CryptoNews #CryptoMeme #binance #CYBER pic.twitter.com/0aSQQ2U7nJ — CRYPTO REKT MEMES…

    Article 2023年9月1日
  • How inflation is pushing the Fed’s buttons

    TL;DR Breakdown U.S. faces unexpected inflation rise, challenging its control over it. University of Michigan’s survey reveals a year-ahead inflation outlook of 3.1%, the lowest since March 2021. Consumer behavior aligns with inflation expectations, potentially influencing market outcomes. Description A recent uptick in inflation, challenging the U.S.’s supposed grip over it, is certainly causing some sleepless nights for economists and policymakers alike. As the current trend hovers above expected numbers, questions arise: How will the Federal Reserve respond, and what are consumers genuinely feeling about this economic turbulence? Public Perception vs. Hard Data Dive … Read more A recent uptick in inflation, challenging the U.S.’s supposed grip over it, is certainly causing some sleepless nights for economists and policymakers alike. As the current trend hovers above expected numbers, questions arise: How will the Federal Reserve respond, and what are consumers genuinely feeling about this economic turbulence? Public Perception vs. Hard Data Dive into the recent survey results from the University of Michigan, and you’ll spot a notable trend. Their preliminary data from September revealed that the year-ahead inflation outlook stood…

    Article 2023年9月20日
TOP