Fun

News Feed - 2023-07-11 05:07:57

Tom Blackstone3 hours agoArcadia Finance hacker used reentrancy exploit, team demands return of fundsIn a post-mortem report, Arcadia Finance developers said an attacker stole funds by liquidating a vault before it could perform a health check, interrupting the app’s normal flow of operations.988 Total viewsListen to article 0:00NewsJoin us on social networksThe Arcadia Finance attacker used a reentrancy exploit to drain $455,000 from the decentralized finance (DeFi) protocol, according to a July 10 post-mortem report issued by the app’s development team. A “reentrancy exploit” is a bug that allows an attacker to “reenter” a contract or interrupt it during a multi-step process, preventing the process from being completed correctly.


The team has sent a message to the attacker demanding the return of funds within 24 hours and threatening police action if the hacker fails to comply.Post Mortem of ongoing situation, providing a technical overview and sharing more information on next steps.https://t.co/NPNbbSzKBQ— Arcadia Finance (@ArcadiaFi) July 10, 2023


Arcadia Finance was exploited on the morning of July 10 and drained of $455,000 worth of crypto. A preliminary report from blockchain security firm PeckShield stated that the attacker had used a “lack of untrusted input validation” in the app’s contracts to drain the funds. The Arcadia team had denied this, stating that PeckShield’s analysis was mistaken. However, the team did not explain what it thought the cause was at the time.


The new Arcadia report stated that the app’s “liquidateVault()” function did not contain a reentrancy check. This allowed the attacker to call the function before a health check had been completed but after the attacker had withdrawn funds. As a result, the attacker could borrow funds and not pay them back, draining them from the protocol.


The team has now paused the contracts and is working on a patch to close the loophole.


The attacker first took a flash loan from Aave for $20,672 worth of USD Coin (USDC) and deposited it into an Arcadia vault. Next, the hacker used this vault collateral to borrow $103,210 USDC from an Arcadia liquidity pool. This was accomplished through a “doActionWithLeverage()” function that allows users to borrow funds only if their account can remain healthy by the end of the block.


The attacker deposited the $103,210 into the vault, bringing the total funds to $123,882. The hacker then withdrew all funds, leaving the vault with no assets and $103,210 in debt.


Theoretically, this should have caused all actions to revert, as withdrawing the funds should have caused the account to fail a health check. However, the attacker used a malicious contract to call liquidateVault() before the health check could commence. The vault was liquidated, eliminating all of its debts. As a result, it was left with zero assets and zero liabilities, allowing it to pass the health check.


Since the account passed the health check after all transactions were concluded, none of the transactions reverted, and the pool was drained of $103,210. The attacker paid back the loan from Aave within the same block. The hacker repeated this exploit multiple times, draining a total of $455,000 from pools on Optimism and Ethereum.


In its report, Arcadia’s team pushed back against claims that the exploit was caused by untrusted input, stating that this alleged vulnerability was not “the core issue” in the attack.


Related:Circle, Tether freezes over $65M in assets transferred from Multichain


The Arcadia team posted a message to the attacker using the input data field of an Optimism transaction, stating:“We understand you are involved with Arcadia Finance’s exploit. We’re actively working with security experts and law enforcement. Your TC deposits and withdrawals on BNB were a bit too fast, it’s hard to hide your identity online these days. We will escalate this with law enforcement in absence of any funds being returned within the next 24 hours.”


In its report, Arcadia claimed it had found some promising leads for tracking down the attacker. “Besides obtaining addresses linked to centralized exchanges, we also uncovered links to previous exploits of other protocols,” the report said. “The team is investigating both on-chain and off-chain data to the fullest extent and has multiple leads.”


Exploits and scams have been a continuing problem in the DeFi space in 2023. A July 5 report from CertiK stated that over $300 million was lost due to exploits in the second quarter of the year.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.# Ethereum# Hackers# Lending# Hacks# DeFiAdd reactionAdd reactionRelated NewsCan memecoins be used as real currency?Chibi Finance $1M alleged rug pull: How it happenedAccount abstraction will drive a billion users from Asia to Web3: ConsenSys execOver $204M lost to DeFi hacks and scams in Q2: Finance RedefinedCrypto hacks and exploits snatch over $300M in Q2 2023: ReportMultichain MPC bridge sees $100M+ outflows, sparking fears of exploit

News Feed

XRP Price To Rally To $6: Partially Completed Wave 5 Says There’s Still Room To Run
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
BUSD Stablecoin Drops from Top 10 Crypto Assets Amid Significant Decrease in Dominance
BUSD Stablecoin Drops from Top 10 Crypto Assets Amid Significant Decrease in Dominance After Paxos announced that it would no longer mint the stablecoin BUSD, 4.98 billion BUSD sta
Softbank lost 99% when the dotcom bubble burst, now it’s all-in on AI
Tristan Greene3 hours agoSoftbank lost 99% when the dotcom bubble burst, now it’s all-in on AISoftbank Group stocks reached an all-time-high on a market capitalization of $97.2 billion.764 Total views1 Total sharesList
Optimism Raises $150 Million in Series B Funding Round Led by Paradigm and A16z
Optimism Raises $150 Million in Series B Funding Round Led by Paradigm and A16z Optimism, an L2 (Layer 2) rollup solution for Ethereum, has raised $150 million in its Series B fund
David Attlee14 hours agoFrance, Singapore and Switzerland test cross-border CBDCsProject Mariana was developed under the aegis of the Bank for International Settlements.3549 Total views33 Total sharesListen to article 0:
Ethereum price soars on spot ETF rumor — How are ETH options markets positioned?
Marcel Pechman9 minutes agoEthereum price soars on spot ETF rumor — How are ETH options markets positioned?Ethereum price soared to a 2-month high at $3,700 today as analysts significantly boosted their expectation tha
Business Advisory Firm Expects Criminal Cryptocurrency Transactions to Fall by 30% by 2024
Business Advisory Firm Expects Criminal Cryptocurrency Transactions to Fall by 30% by 2024 Gartner, an advisory firm, has predicted that criminal cryptocurrency transactions or tra
Prashant Jha12 hours agoChina court declares virtual assets legal properties protected by law: ReportDespite a blanket ban on cryptocurrencies imposed by Beijing in 2021, many Chinese courts over the years have establish
Yashu Gola11 hours agoWhy is Dogecoin price up today?Dogecoin price hits a two-month high amid speculations that Twitter’s rebrand to X would add a DOGE payment option.7163 Total views46 Total sharesListen to article 0
William Suberg12 hours agoBitcoin enters make-or-break zone after BTC price snaps back to $38KBitcoin returns to 18-month highs as whipsaw BTC price action manages to avoid another open interest blowout.4473 Total views3
Year-End Gold and Bitcoin Price Predictions from Regular Everyday People
Year-End Gold and Bitcoin Price Predictions from Regular Everyday PeopleJust recently, news.Bitcoin.com talked to a number of individuals and asked them to let us know what they thi
Biggest Movers: SOL Hits 6-Week High, Following US Inflation Data
Biggest Movers: SOL Hits 6-Week High, Following US Inflation Data Solana moved to a six-week high on Wednesday, as markets reacted to the latest inflation figures from the United S