Harvest Finance Releases Attack Postmortem After Losing $24 Million

Harvest Finance Releases Attack Postmortem After Losing $24 Million
фото показано с : beincrypto.com

2020-10-27 10:04

The latest Harvest Finance DeFi incursion has generated overwhelming denigration from crypto pundits on social media. However, it would be more constructive to break the situation down to find out exactly what happened in order to mitigate future attacks.

On Oct 26, the DeFi farming Harvest Finance protocol was drained of at least $24 million in liquidity through a flash loan attack as reported by BeInCrypto at the time.

The protocol has taken responsibility for what it called an ‘economic attack’ and ‘engineering error’ and has made a remediation plan for affected users its top priority.

“We take responsibility for this engineering error and are ensuring such incidents are mitigated in the future.”

Harvest Finance Postmortem

In a postmortem blog post, Harvest Finance breaks down the events that led to the draining of millions of dollars of crypto funds from its liquidity pools.

The report explained that the attacker exploited arbitrage and impermanent loss features that influenced the value of individual assets inside the Y pool of Curve Finance, where the vault funds resided.

Around 18 million USDT and 50 million USDC were sourced from Uniswap and deployed into the attacking contract. The smart contract converted the USDT via a swap inside the Y pool, creating a higher value of USDC inside the pool as the other assets incurred an impermanent loss.

The attacker also deposited the USDC into Harvest’s USDC vault, receiving a total of 51.4 million fUSDC at 0.97 USDC per share, decreasing the value of the shares by approximately 1%. The USDC was converted back into USDT via the Y pool to obtain the original lower value of USDC due to the reverting of the impermanent loss effect.

The DeFi pirate then withdrew from Harvest’s USDC vault trading all fUSDC shares back for a slightly higher share price as the value of USDC inside the Y pool decreased. The USDC was paid entirely by the buffer of the Harvest USDC vault, not interacting with Y pool at all, to net a profit of around 620k in USDC.

Flash Loan Kung Fu

This process was then executed 30 times in seven minutes, netting the attacker a tidy sum of around $24 million in USDT and USDC. The share prices of both stablecoin vaults plummeted, making the overall loss even greater.

“The value lost is about $33.8 million, which corresponded to approximately 3.2% of the total value locked in the protocol at the time before the attack.”

This was a very sophisticated arbitrage attack — it was not a hack and no smart contract code was compromised. Flash loans are not easy to master, a notion that was expanded on in one summary of the events;

“Mastering flash loans is like turning up to a 12th century jousting tournament on a Harley Davidson dual-wielding AK47’s; nobody expects it, plebs get rekt.”

Harvest Finance is working on mitigating future flash loan exploits but the damage has already been done. Around $600 million in total value locked has fled the protocol over the past 24 hours according to DeFi Pulse and FARM tokens have dumped 58% in the same period.

The post Harvest Finance Releases Attack Postmortem After Losing $24 Million appeared first on BeInCrypto.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Harvest Masternode Coin (HC) на Currencies.ru

$ 0.0050211 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0.0050211 - H: $0.0050211
Капитализация $21.91k Rank 99999
Доступно / Всего 4.364m HC / 10m HC

harvest finance situation break constructive down out

harvest finance → Результатов: 25


Объем торгов Uniswap достиг рекордного максимума в $2,12 млрд

Объемы торгов децентрализованных бирж Curve и Uniswap превысили $2 млрд в этот понедельник, после того как DeFi-протокол Harvest Finance подвергся атаке. Оборот Uniswap вырос почти на 1 300% до рекордного максимума в $2,12 млрд.

2020-10-26 18:54


Фото:

Хакеры украли криптоактивы на$25 млн из протокола DeFi Harvest Finance

Хакеры атаковали протокол децентрализованных финансов Harvest Finance и смогли вывести криптоактивы на $25 млн. После атаки курс токена FARM рухнул на 65% всего за час.

2020-10-26 13:30


Хакер похитил $25 млн из DeFi-протокола Harvest Finance — токен обвалился на 50%

Разработчики заявили, что располагают значительным объемом информации о преступнике. По их словам, это хакер, который хорошо известен в криптосообществе.

2020-10-26 13:04


Фото:

DeFi project Harvest Finance loses $24 million to hackers

By now, everyone knows that the DeFi sector has been the center of the attention of the crypto industry in 2020. The sector has grown by billions and billions of dollars in only a few months. However, just like it started attracting new users and investors, as well as their money — it also started attracting hackers interested in stealing that money.

2020-10-26 12:15


Фото:

Хакер вывел $19,8 млн с платформы Harvest Finance. Курс FARM упал на 50%

Неизвестный злоумышленник использовал $24 млн в стейблкоинах из пулов DeFi-протокола Harvest Finance, чтобы вывести с платформы $19,8 млн в renBTC. Нативный токен проекта FARM отреагировал падением более чем на 50%.

2020-10-26 11:57


Цена токена DeFi-проекта Harvest Finance за час обвалилась на 65%

Уязвимость в протоколе децентрализованных финансов (DeFi) Harvest Finance привела к падению токена платформы FARM на 65% менее чем за час, пишет Coindesk. Из пулов Harvest Finance неизвестным злоумышленником было выведено более $25 млн.

2020-10-26 11:49


Фото:

Стоимость заблокированных активов в протоколе DeFi Harvest Finance достигла $700 млн

На децентрализованной платформе Harvest Finance для «доходного фермерства», которая позволяет получать прибыль на других проектах DeFi, заблокированы активы, эквивалентные более чем $700 млн.

2020-10-22 12:59