Hackers steal $8 million worth of cryptocurrencies from DeFi Protocol bZx

Hackers steal $8 million worth of cryptocurrencies from DeFi Protocol bZx
фото показано с : invezz.com

2020-9-14 14:30

Hackers were able to infiltrate the DeFi lending protocol bZx and stole more than $8 million worth of cryptocurrencies. This is not the first time the DeFi protocol has been attacked this year.

This time, the hackers were 8 times more potent than the previous attack on the margin and leverage-based trading and lending platform. The hackers leveraged a duplication vulnerability that gave them access to siphon USDC, USDT, ETH, and LINK, with a combined worth of over $8 million.

Anton Bukov, a team member of the bZx group shared a thread on Twitter to admit that the firm was hit by another attack. He also said the hacking was initiated due to the fault in the line of code for a smart contract. The hacking was successful after the hackers initiated the iToken transactions to siphon ETH.

We realized that initial source code works incorrectly when "_from" equals to "_to" and leads to funds duplication. We found 9 exploiting transactions on $iETH lending token with 101778 $iETH tokens duplicated (worth ~4.7K $ETH) // @DuneAnalytics pic.twitter.com/IWodBkGaEq

— Anton Bukov | k06a.eth (@k06a) September 13, 2020 How the attack occurred

When researchers delved deeper to find out how the hackers were able to infiltrate the DeFi protocol again, the report showed that there was a vulnerability in the “transferfrom0 protocol”, which allowed the successful transfer of ERC20 between protocols.

This made it easier to initiate the function when creating and transferring the iToken, giving the hackers the avenue to increase their balance. The hackers were able to initiate a transfer function using the same form & to address of the main function. Immediately after that, they used an InternalTransferFrom function with a single argument, allowing the lines to code faulty.

Subsequently, the hackers were able to increase the balance of –balancesTo while reducing the –balancesFrom, based on the report. After stealing $8 million from the DeFi protocol, the bZx hackers immediately patched the faulty code. After code coding companies Peckshield and Certik approved, the DeFi lending protocol decided to patch the code.

This is not the first time bZx has been attacked

With this recent spate of attacks, it seems bZx is facing a hard time this year. Based on an earlier report, a hacker successfully stole $1 million worth of ETH from the portal in two successful attempts in February.

In the first attack that occurred on February 14, the hacker made use of different methods in the attacks. First, the hacker took 10,000 ETH from dYdX and took a 112 wBTC loan on compound using 5,500 ETH.

In the second attack, which occurred four days later, the attacker drained the system off $600,000 by leveraging ‘oracle manipulation’ to cheat the system.

The post Hackers steal $8 million worth of cryptocurrencies from DeFi Protocol bZx appeared first on Invezz.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Defi (DEFI) на Currencies.ru

$ 0.0182135 (-17.70%)
Объем 24H $1.165k
Изменеия 24h: 74.29 %, 7d: -97.27 %
Cегодня L: $0.0182135 - H: $0.0182135
Капитализация $0 Rank 3233
Цена в час новости $ 1.0065 (-98.19%)

defi protocol hackers time lending worth million

defi protocol → Результатов: 126


Фото:

Hashstack Finance Announces The Public Testnet Launch Of Its Open Protocol

Decentralized finance (DeFi) platform Hashstack Finance has announced the public testnet launch of its Open Protocol to disrupt the DeFi lending market. As per the announcement, the Open Protocol will allow DeFi users to access expert first tips on how to get the utmost worth out of their collateral when borrowing. Hashstack hopes this launch […]

2022-5-3 23:45


Фото:

PARSIQ’s IQ Protocol Ranks 1st Among Binance Smart Chain’s Top DeFi Projects Under 100M Market Cap

IQ Protocol (PRQ) has revealed that its innovative decentralized finance (DeFi) solutions have been gaining massive interest and adoption globally since its official launch barely five months ago. With 60 strategic partnerships and a 50x surge in its TVL, IQ Protocol is now the number one DeFi project under a 100 million market cap onRead More

2021-11-17 18:00


Фото:

The DeFi Yield Protocol (DYP) Looks Poised to take DeFi to Next Level

Within the rapidly budding cryptocurrency industry, 2020 has undoubtedly been the year of decentralized finance (DeFi) and the DeFi Yield Protocol is committed to take DeFi new heights.  What Is the DeFi Yield Protocol? The DeFi Yield Protocol (DYP) is developing a cutting-edge unique platform that enables anyone to provide liquidity and be rewarded forRead More

2020-12-24 13:43


Фото:

Altcoin Explorer: Kyber Network, the On-Chain Liquidity Protocol Leading the DeFi Sector

Kyber Network is an on-chain liquidity protocol that powers decentralized applications, from exchanges and funds to lending protocols and payments wallets. In recent months Kyber has experienced tremendous growth due to the development of decentralized finance and has managed to establish itself as one of the reference protocols for this new sector.

2020-2-13 12:00


TTC blockchain DApp ecosystem project Tigris Protocol now open-source

TTC, a decentralized token-incentivized protocol for social network services and online communities, announced today it has made the decision to open-source the Tigris Protocol project. Tigris Protocol is a set of decentralized finance (DeFi) solutions operating on a TTC blockchain that offers a range of services, such as staking, collateralized debt, and Tigris Rewards Programs.

2020-1-31 14:16