Visor Finance Releases $500,000 DeFi Heist Post Mortem Report

2021-6-21 08:19

The latest decentralized finance (DeFi) protocol to suffer at the hands of bad actors is vault management platform Visor Finance.

In an incident report on June 20, the DeFi protocol revealed that an attacker had obtained access to an account that managed some of its admin functions.

DeFi exploits abound

The malicious actor was able to withdraw funds from deposits that were yet to be placed into the liquidity provider positions, it added.  

Visor reported that the amount stolen equated to around 16.7% of its total value locked of $3 million, or around $500,000. It confirmed that the hacker was not a member of the team and therefore lacked a full understanding of its emergency withdrawal safeguards,

“Stolen funds were thus limited to un-positioned assets and thus the $500k number was not arbitrary.”

Visor Finance confirmed that it used its treasury stash to replace what had been stolen before detailing how it happened.

Admin account compromised

Visor Protocol offers something called a Smart Vault which is a non-fungible token (NFT) vault for users to mint and deposit assets into. This is then used to interact with a “Hypervisor” – a smart contract that connects assets in the vault to external DeFi protocols.

It was the Hypervisor that was compromised during the incursion and the team has admitted that it was at fault for having single admin access and not a multi-signature account.

“But with that said, our mistake was not using a multisig account for all admin functions of the Hypervisor. This has since been corrected.”

Visor stated that it was initially designed this way as it was not practical to have multiple signatures for managing frequent rebalancing on multiple pairs every time a rebalance was needed. An emergency withdraw function was implemented to test the Hypervisors pending a protocol audit as a safeguard in case funds needed to be rescued, it added.

The DeFi protocol confirmed that the smart contracts themselves were not exploited and industry standard practices will be employed going forward.

“We realize the importance of permission management and will only adopt industry standards and best practices now and going forward. We recognize this is a particularly complex design space since it is dealing with both active management and safety of funds.”

Last week, DeFi protocol Iron Finance suffered heavy losses due to what it described as a ‘crypto bank run’.

VISR token price tanks

The protocol’s native token tanked 64% at the time of the incident on June 19, plunging from $0.95 to $0.34 according to CoinGecko.

At the time of writing, VISR was trading at $0.51, down 55% on the week and 87% since its May 5 all-time high of $4.11. The total value locked is around $1.2 million according to DeFi Llama, a slump of 66% from its all-time high of $3.5 million on June 17.

The post Visor Finance Releases $500,000 DeFi Heist Post Mortem Report appeared first on BeInCrypto.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Wish Finance (WSH) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 WSH

finance defi visor mortem report releases heist

finance defi → Результатов: 126


Фото:

Provide Fearless Concentrated Liquidity With Kamino Finance

Decentralized finance (DeFi) is a sector of finance that’s less than a decade old, and it’s picking up speed. Within the last two years, DeFi has erupted with growth and innovation from all over the ecosystem, and improvements are constantly being made to how decentralized applications (dApps) provide better and more capital-efficient services. However, innovations […]

2022-9-12 19:11


Фото:

DeFi tokens that will get you into the world of decentralized finance

Coin98 C98/USD, UMA UMA/USD, and Wanchain WAN/USD are all solid decentralized finance (DeFi) tokens that you can pick from as of June 17, 2022. On June 16, 2022, Coin98 announced that the cryptocurrency was added to dYdX’s official list of wallets which boosted all user access to a robust as well as professional exchange for […] The post DeFi tokens that will get you into the world of decentralized finance appeared first on Invezz.

2022-6-18 14:02


DeFi Protocol Visor Finance Restores Full User Position Value After $500k Exploit

Decentralized finance (DeFi) protocol for liquidity management that is building on popular DEX Uniswap V3, Visor Finance was exploited over the weekend for $500,000. Last month, Visor began active liquidity management on Uniswap v3 after releasing its NFT Smart Vault that allows DeFi participants to deposit assets and permission them for use on various protocols.

2021-6-22 15:59


Какие DeFi-проекты смогли пережить взломы?

Рассказываем о пяти проектах DeFi, которые восстановились после взлома и продолжили работать. Сообщество DeFi снова поставило под сомнение подход «тестирования в деле» после того, как проекты Alpha Finance Labs и CREAM Finance потеряли 37,5 млн долларов в результате хакерской атаки.

2021-2-28 20:54


Фото:

DeFi-проект LV Finance оказался экзит-скамом

LV Finance пополнил череду проектов, воспользовавшихся ажиотажем вокруг сферы децентрализованных финансов (DeFi), чтобы обманным путем присвоить деньги пользователей.

2020-9-21 11:00