How $150m in Ethereum & DAI was used to steal $7m from a Yearn.finance competitor

How $150m in Ethereum & DAI was used to steal $7m from a Yearn.finance competitor
фото показано с : cryptoslate.com

2020-11-16 18:30

It may seem like a broken record at this point but yet another decentralized finance (DeFi) protocol was recently exploited.

And, once again, the exploit took place on a competitor of Yearn.finance (YFI).

Here’s more about what happened, and what DeFi users can do to prevent their funds from being attacked moving forward.

Yearn.finance fork ValueDeFi hacked for $7 million

In August and September, forking Yearn.finance was all the rage. Yearn.finance had rapidly become the crypto industry’s darling, with $1 billion in deposits and its native token YFI sporting a matching $1 billion market capitalization.

Forks upon forks were released.

One fork that gained traction was YF Value (YFV), which, like Yearn.finance, was marketed as a place for users to deposit cryptocurrencies and earn a steady and safe return. While extremely similar in concept to Yearn.finance, the marketing strategy worked: at its peak in early September, YFV had a market capitalization just shy of $150 million.

Unfortunately, YFV isn’t as safe as first thought.

On Saturday morning, users began to take notice of a large Ethereum transaction that involved Aave, Curve, Uniswap, and YF Value (now known as Value DeFi).

In that transaction, a user had withdrawn 80,000 ETH from Aave in a flash loan, along with another $116 million in DAI from Uniswap.

Those funds were subsequently traded to manipulate the price of stablecoins on Curve. This manipulation meant that the attacker was able to obtain Value deposit tokens worth more than the actual value of the stablecoins that underlie those tokens.

In total, $7.5 million worth of DAI was drained from Value, though $2 million was returned to the protocol by the pseudonymous attacker.

Although unfortunate for depositors, literal hours before the attack, Value called itself the “most secured and advanced piece of technology in the DeFi space,” claiming its developers accounted for well-known flaws in Ethereum smart contracts.

13 Hours Ago:
– Value DeFi calls itself “the most secured and advanced piece of technology in the DeFi space”

10 Hours Later:
– Flash loan attacked for $7 million pic.twitter.com/yYbWuYBX03

— Spencer Noon (@spencernoon) November 14, 2020

The exploit of Value comes after similar attacks took place with Akropolis and with Harvest Finance.

Avoiding protocols with bad oracle integration

At the core of many of these exploits and potential attack vectors are the lack of proper oracle integrations. An oracle is software that supplies data outside a system to that system; in DeFi, oracles are most often used by protocols that need to know the price of a cryptocurrency.

“Honest” oracles use a variety of metrics, such as using an index or taking a snapshot, to mitigate the risk of price manipulation attacks.

The protocols that were exploited by flash loan attacks did not use properly integrate oracles, allowing the inter-block prices of stablecoins to be manipulated to the advantage of exploiters.

The post How $150m in Ethereum & DAI was used to steal $7m from a Yearn.finance competitor appeared first on CryptoSlate.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Multi collateral Dai (DAI) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $1.0002
Капитализация $0 Rank 99999
Цена в час новости $ 1.0012 (-100%)

finance yearn steal competitor dai 150m used

finance yearn → Результатов: 126


Цена yEarn Finance резко снизилась на фоне ухода основателя проекта Андре Кронье из индустрии

Старший архитектор решений Fantom Foundation Антон Нелл и ведущий DeFi-разработчик экосистемы, а по совместительству основатель yEarn Finance Андре Кронье решили покинуть криптовалютную индустрию. По его словам, они перестанут сотрудничать по 25 проектам, включая yEarn Finance, Multichain и недавно запущенную Solidly Exchange.

2022-3-8 11:22


Застрахованные пользователи yEarn.Finance получат возмещение убытков

Основатель DeFi-проекта yEarn. Finance Андре Кронье пообещал вернуть утраченные в результате хакерской атаки средства тем, кто приобрел страховой полис у партнеров Nexus Mutual и Cover Protocol. Для остальных пользователей вопрос пока остается открытым.

2021-2-9 17:36


Фото:

yEarn.Finance вслед за Pickle Finance поглотит Cream Finance

Основатель DeFi-проекта yEarn. Finance Андре Кронье представил детали интеграции с лендинговым протоколом Cream, работающим по модели проектов Compound и Aave. Об этом он заявил спустя два дня после объединения yEarn.

2020-11-26 17:26


Yearn Finance Consumes Pickle Without Governance Vote

The move follows a hack over the weekend that resulted in the loss of $20 million in stablecoins, however, the community had no say in the decision. Yearn Finance has partnered, or rather absorbed, Pickle Finance in an effort to increase rewards for stakers and reimburse some of the victims of the flash loan attack … Continued The post Yearn Finance Consumes Pickle Without Governance Vote appeared first on BeInCrypto.

2020-11-26 17:13


Фото:

Pickle Finance объединится с yEarn.Finance после потери $20 млн

Разработчики протокола децентрализованных финансов Pickle Finance объявили о слиянии с DeFi-проектом yEarn. Finance Андре Кронье. 🤝Yearn @iearnfinance & Pickle INTEGRATION🤝 Read more in this post from @AndreCronjeTech https://t.

2020-11-25 12:04


Фото:

Yearn.Finance и Pickle Finance объявили о слиянии

Руководство проекта децентрализованного финансирования Yearn.Finance решило протянуть руку помощи недавно взломанному Pickle Finance и объединиться. Это поможет компенсировать потери пользователям.

2020-11-25 10:57


Предложение Ethereum на рынке может упасть после запуска ETH-пула в yearn.finance

Аналитики ожидают, что запуск пула yETH популярным DeFi-проектом yearn. finance окажет положительное воздействие на рынок Ethereum. Инструмент поможет держателям эфира использовать свои монеты для автоматического вложения в наиболее доходные возможности, предоставляемые DeFi-проектами с поддержкой заработка токенов при помощи предоставления ликвидности.

2020-9-1 13:04