DeFi Project Bancor Hacks Own Protocol to Save Funds at Risk from Security Vulnerability

2020-6-18 19:33

Yet another DeFi project faces security risk. On June 17, around 12:00 am GMT, the on-chain liquidity protocol Bancor Network was vulnerable to fund loss.

San Francisco-based Hex Capital reported that “User funds being drained due to unauthenticated safeTransferFrom() function on their new BancorNetwork contract.” Bancor then tried to “white-hat” drain user funds but were too late.

However, as per Bancor’s official response on the security incident all funds are safe as they were successful in the white-hat attack and migrated $455,349 of funds at risk to a safe wallet.

The team discovered the vulnerability in the new version of BancorNetwork v0.6 contract, which was deployed the day before the attack.

The contracts mistakenly made a safeTransferFrom function in the Bancor Network contract public, which use allowance to interact with user wallets, a common practice used by most Dapps.

In this particular case, a private function was made public when it should have been restricted to the contract alone, allowing anyone to transfer tokens which were approved only for the contract to transfer, explained the team.

After the successful white-hat attack, Bancor pushed a new network contract and removed the infinite approval.

However, two arbitrage bots detected the income transactions and made a profit of $135, 229 by front-running the transactions. Bancor is currently in contact with the bots’ owners to “return the amounts to the rightful owners in exchange for a bug bounty.”

Bancor also awarded a bug bounty to DEX Aggregator 1inch team for helping with the situation.

Trading is now back to normal on the system.

The incident however pushed Bancor (BNT) token prices down by 6.64% to $0.778 while other DeFI tokens are enjoying substantial greens. BNT is still up 227% YTD.

Security research manager Tal Be’ery, co-founder or ZenGo said he warned about the risks of the approval exploit three months ago.

#BaDAPProve: 3 months ago we @ZenGo warned about it. Today it happened @Bancor.https://t.co/j52C0DFg9y
"if the DApp is vulnerable to a security issue attackers can abuse these highly excessive privileges to steal ALL of the DApp’s users holdings" https://t.co/nvyLbbZkS5 pic.twitter.com/5FFnRzsqI6

— Tal Be'ery (@TalBeerySec) June 18, 2020

This is not the first time a DeFi project has been at security risk. In 2020, there have been several cases where millions have been lost calling for the projects in the DeFi space to better their security standards.

Meanwhile, Melody He, co-founder of The Spartan Group, a crypto hedge fund which is an active investor in Defi maintains,

“Defi will become source of new revenue and inspiration. Whoever understands the power of Defi, will have a higher chance of keeping their competitive edge.”

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

World Trade Funds (XWT) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 XWT

funds user bancor new safetransferfrom due unauthenticated

funds user → Результатов: 126


Betform ICO

Betform is a decentralized social betting platform that brings funs, privacy, and safety for funds to players. Our key operations are regulated by smart contracts. At Betform, we strive to offer the user access to as large as possible a range of blockchain games at a maximum degree of convenience, while adhering to the highest security standards in the ecosystem.

2018-10-22 17:05


Фото:

Chinese Startup Cobo Builds Ultra-Secure Self-Destructing Bitcoin Hardware Wallet

China-based cryptocurrency company Cobo has developed a new hardware wallet which provides innovative new security features to ensure that user funds are kept secure. The Cobo Vault Cobo refers to its Cobo Vault as “the world’s first all-around secure, military-grade cryptocurrency hardware wallet,” and this description seems to be justified.

2018-10-19 20:00


Фото:

How Monero Are Improving Human Rights With XMR

 Listen Here – https://soundcloud. com/cryptodaily/how-monero-are-improving-human-rights-with-xmr Monero is considered to be the privacy coin, the currency of choice for absolute privacy. Now, privacy doesn’t necessarily mean security and we should remember that 2018 has seen a tonne of ‘Monero mining’ hacks, calling into question some of the projects integrity.

2018-10-12 17:00


Фото:

Stackr: The Dawn of a Digital Asset Savings Solution - [BTC Media Sponsor]

Financial savings have long been the foundation of wealth and asset building. However, we are now in a time when the growing obsolescence of financial institutions has forced certain technologies out of date, created high fees, revealed structural inefficiencies and, ultimately, meant that some standard investment solutions now fail to place consumer needs first.

2018-10-6 16:37


Чанпен Чжао: Binance запустит децентрализованную биржу к началу 2019 года

Глава крупнейшей криптобиржи Binance Чанпен Чжао сообщил, что его компания планирует в начале следующего года представить публичную бета-версию децентрализованной торговой площадки. Just had a productive meeting for #Binance #DEX (decentralized exchange), where $BNB will be native gas, and the exchange don’t control user funds.

2018-10-1 15:53


Фото:

Japan Reports Crypto Thefts up Three-Fold in 2018, Worth Half a Billion in Stolen Funds

Cryptocurrency–The National Police Agency of Japan has released troubling news on the state of cryptocurrency-related thievery. Despite growing adoption and awareness for the industry throughout 2018, thereby leading to an improvement in security for user funds, the Japanese organization reports crypto-related thefts have cost users more than half a billion dollars.

2018-9-21 04:42


NEO Finance ICO

NEO Finance offers an international platform in which participants have the opportunity to instantly receive a money loan with fiat money on bail of volatile crypto assets such as: Bitcoin Ethereum Ripple BitcoinCash Receipt of credit funds can be carried out in the following ways: In your wallet NEO Finance With the help of a payment card NEO Finance, with the possibility of cashing in any ATM Using the user's bank card.

2018-8-14 15:13