Cream Finance Offers the Attacker 10% of Stolen Fund as Bug Bounty on Return of Funds

2021-11-1 20:22

In its post mortem of the third hack of this year, this time of $130 million, Cream Finance shared that they are working with the authorities to trace the attacker.

In the hack, only the Ethereum v1 markets were impacted, and all the other v1 markets and the Iron Bank were safe, it added. The vulnerability has now also been patched.

As for what happened, the decentralized finance (DeFi) project Cream Finance noted that it was a mix of economic and oracle exploits.

The attacker flash borrowed DAI from lending protocol MakerDAO to create a large amount of yUSD tokens while simultaneously exploiting the price oracle calculation for yUSD price through the manipulation of the multi-asset liquidity pool that contained yDAI, yUSDC,yUSDT, and yTUSD on which the price oracle relied — all in a single transaction.

By increasing the increasing yUSD price per share, the attacker’s yUSD position was artificially increased, creating sufficient borrow limit to remove the vast majority of the liquidity from C.R.E.A.M. Ethereum v1 markets, explained the team.

In response, all the interactions with Cream’s Ethereum v1 markets have been suspended, and crTokens on them locked making them non-transferable.

“The key vulnerability lies in the price calculation of a wrappable token. We have stopped all supply/borrow of wrappable tokens, including all PancakeSwap LP tokens,” said the team.

The Yearn Finance team meanwhile successfully salvaged 9.42 mln which the attacker donated to the yUSD vault as part of the attack. The funds will soon be returned to the Cream multisig.

The team is currently working on a plan to restore funds lost, starting with a partial payment, which the details will be shared in the coming days.

Cream Finance also announced a bug bounty under which the attacker is encouraged to reach out to the team and return users’ funds in exchange for keeping 10% of the funds.

“They are impacting everyday users of DeFi, and we would like them to do the right thing,” said Cream Finance.

As a result of the attack, the total value locked (TVL) in the project had dropped by $370 million to $1.32 bln last week but hasn’t recovered as the TVL currently sits at $1.44 bln.

Much like the funds, the price of the CREAM token hasn’t pared its losses either. Currently trading at $101.11, the price is near the $98.41 low it dropped to last week and is down 73% from its all-time high of $374 hit in February.

The post Cream Finance Offers the Attacker 10% of Stolen Fund as Bug Bounty on Return of Funds first appeared on BitcoinExchangeGuide.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Wish Finance (WSH) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 WSH

hack markets cream attacker finance working authorities

hack markets → Результатов: 62


Kucoin’s Hackers Identified With ‘Substantial Proof’ in $280M Theft, Law Enforcement Involved

Kucoin announced through its CEO Johnny Lyu that they have found the hackers who compromised close to $280 million of the exchange’s funds in last week’s hack. Lyu tweeted this update over the weekend as crypto markets struggled in the red zone following the Kucoin hack, BitMEX indictments, and the news of President Trump contracting […] The post Kucoin's Hackers Identified With 'Substantial Proof' in 0M Theft, Law Enforcement Involved first appeared on BitcoinExchangeGuide.

2020-10-5 16:16


Фото:

Here’s Why Bitcoin Hasn’t Nuked Lower Despite Barrage of Bearish News

Many analysts and investors have been quite surprised at how stable Bitcoin’s price has been despite a plethora of bear-favoring developments within the markets From a macro perspective, President Trump’s recent viral diagnosis has rocked the traditional markets, which has had a trickle-down effect on crypto Within the crypto market, the recent $150m KuCoin hack, as well as the government’s charges against the BitMEX founders, have both spooked investors Despite all these factors placing pressure […]

2020-10-4 00:00


Bitcoin Gold (BTG) Gets Delisted By Bittrex Crypto Exchange Due To $18 Million Hack

Bittrex Exchange Removes Bitcoin Gold From Their Exchange Among cryptocurrency startup companies, the risk of theft, extortion, or major attack is very significant. The cryptocurrency community has always been especially susceptible to crime, because of the prevalence of technology-minded hackers in the markets, as well as the anonymous nature of cryptocurrencies in general. For these […]

2018-9-4 13:37