DeFi protocol CremaFinance exploited for $8.7 million

2022-7-4 16:36

CremaFinance, a liquidity protocol on Solana, was exploited for over $8.7 million this weekend, the platform confirmed on Monday.

The hack follows an exploit in the decentralized finance platform’s tick account, Crema said in an update.

Once they managed to create the fake account, the attacker was able to “circumvent” a routine security check, leading to the withdrawal of millions of dollars in crypto.

6) In CLMM, the calculation of transaction fees mainly relies on the data in tick account. As a result, the authentic transaction fee data was replaced by the faked data so the hacker completed the stealing by claiming a huge fee amount out from the pool.

— CremaFinance (@Crema_Finance) July 3, 2022

The Solana-based protocol announced a temporary pause to its service, noting it had initiated an investigation into the exploit with the help of industry’s leading security services.

“The hacker swapped the stolen fund into 69422.9SOL and 6,497,738 USDCet via Jupiter. The USDCet was then bridged to the Ethereum network via Wormhole and swapped to 6064ETH via Uniswap after that,” Crema said in a tweet.

The attack on Crema is one among several DeFi attacks in 2022, with blockchain security analytics platform Chainalysis reporting that about 97% of crypto attacks within Q1 were connected to DeFi.

Among the billions stolen year-to-date from protocols are high profile losses like the $615 million on Axie Inifinity’s Ronin bridge; the $320 million heist from Wormhole; the $181 million Beanstalk flash loan attack and the $30 million hack on Optimism.

Tracking site REKT Database shows over $3.6 billion has been lost to hackers over the past year, with just over $1.1 billion returned.

The post DeFi protocol CremaFinance exploited for $8.7 million appeared first on CoinJournal.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

BlockMason Credit Protocol (BCPT) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.04 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Цена в час новости $ 0.0195725 (-100%)

million exploited cremafinance protocol defi coinjournal liquidity

million exploited → Результатов: 91


Фото:

‘Save Yourself’ sextortion campaign targets 27 million victims in their inboxes

A well-established botnet and malware agent is now engaged in a new large-scale sextortion campaign by acting as a spambot to target innocent recipients. According to Check Point Research, the creators of the Phorpiex (aka Trik) botnet added this revenue generation ability to trick victims into transferring more than 11BTC (~$89,370) to the threat actors’ wallets over the course of five months.

2019-10-16 16:00


Фото:

A bug in Indian local search app exposed over 156 million accounts

A major flaw in an Indian local search app, Justdial, allowed hackers to log in to any of its 156 million users accounts. Apart from accessing user information such as names, phone numbers, and email addresses, the vulnerability allowed them to peek into financial details including balance and transactions of an account through JustDial Pay, the company’s payment service.

2019-10-10 08:44