Fun

Decentralized lending platform Seneca exploited for $6.4M

News Feed - 2024-02-29 10:02:24

Christopher Roark10 hours agoDecentralized lending platform Seneca exploited for $6.4MThe Seneca lending protocol was exploited through its ‘performOperations’ function, and over $6M of collateral was drained from it.1161 Total views7 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksDecentralized finance (DeFi) lending platform and stablecoin issuer Seneca Protocol has been exploited, according to a Feb. 28 statement on the protcol’s official X account. In a report seen by Cointelegraph, blockchain analytics firm CertiK estimated the losses at $6.4 million so far. The Seneca team urged users to revoke approvals for the affected contracts. Its staff are “currently working with security specialists to investigate the bug,” they stated.We are actively working with security specialists to investigate the approval bug found today.

In the meantime, REVOKE approvals for the following addresses:#Ethereum

PT-ezETH 0x529eBB6D157dFE5AE2AA7199a6f9E0e9830E6Dc1

apxETH 0xD837321Fc7fabA9af2f37EFFA08d4973A9BaCe34…— Seneca (@SenecaUSD) February 28, 2024


Seneca Protocol is a DeFi lending app that allows users to deposit a variety of cryptocurrencies as collateral, which then can be used to mint and borrow the protocol’s native stablecoin, SenecaUSD.


Blockchain data shows that an account ending in 42DC was able to transfer approximately 1,385.23 Pendleton Kelp restaked Ether (PT Kelp rsETH) from a Seneca collateral pool, which it did by calling the “performOperations” function. The account subsequently swapped these tokens for approximately $4 million worth of Ether (ETH) over the course of three transactions. After these swaps, the account transferred an additional 717.04 ETH derivative tokens from various collateral pools and swapped them for ETH.Seneca attack transactions. Source: Etherscan.


In its report, CertiK claimed that these transfers were malicious. They were made possible because the protocol contains a flaw in its “performOperations” function, the report stated. The bug allows any account to call the function while specifying OPERATION_CALL as the action to be performed. This allows the attacker to “perform external calls to any address as the callee and callData are fully controlled by the attacker.” As a result, the attacker was able to drain funds from the collateral pool that it didn’t own, CertiK claims.


Blockchain investigator Spreek also warned users about the exploit on X, stating that it represented a “critical vulnerability.” Spreek suggested that users should revoke approvals of the addresses used in the exploit.


Related:Serenity Shield’s token falls nearly 99% after MetaMask wallet breach


According to security researcher ddimitrov22, Seneca is suffering from an additional vulnerability that prevents developers from pausing the Seneca contracts, as the pause and unpause functions in them contain the keyword “internal,” which means “there is no way to call them.”The Seneca protocol is hacked and it cannot be paused even though it inherits the Pausable library.

This is because the `_pause` and `_unpause` functions are internal and there is no way to call them. pic.twitter.com/en0qIsayMX— ddimitrov22 (@ddimitrovv22) February 28, 2024


In its post acknowledging the attack, the development team stated that they are conducting an investigation and will post an update “shortly.”


Hacks and exploits continue to threaten Web3 users in 2024. On Feb, 23, Axie Infinity co-founder Jeff “Jihoz” Zirlin lost $9.7 million from a hack of his personal wallets. On the same day, DeFi protocol Blueberry was exploited for 457 ETH.# Blockchain# Ethereum# Hackers# Cybersecurity# Hacks# DeFiAdd reactionAdd reactionRead more

News Feed

South Korean police catch $4.1M crypto scam duo
Arijit Sarkar13 hours agoSouth Korean police catch $4.1M crypto scam duoScammers falsely guaranteed 70% profits on an investment of 1 billion South Korean won within a month and stole 5.5 billion won in six different tra
Ethereum As The Default Crypto Backbone: The Real Reason Behind Tom Lee’s Pick
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Microsoft Layoffs Reportedly Hit Key VR and Metaverse Teams
Microsoft Layoffs Reportedly Hit Key VR and Metaverse Teams The latest round of layoffs at Microsoft, which announced it will cut 10,000 jobs this year, has hit key teams for its V
Amaka Nwaokocha13 hours agoCoinbase user agreement dispute reaches US Supreme CourtThe Supreme Court’s choice to take up this case represents a pivotal development for firms utilizing arbitration clauses.10197 Total vi
Bitcoin drops 9% from its ATH as the market shows signs of being ‘overheated’
Nancy Lubale6 hours agoBitcoin drops 9% from its ATH as the market shows signs of being ‘overheated’After a monstrous rally, the BTC price is showing signs of cooling off, with altcoins quickly following suit.2442 To
Skybridge Estimates Bitcoin’s Fair Market Value at $40K and Ethereum’s at $2,800
Skybridge Estimates Bitcoin"s Fair Market Value at $40K and Ethereum"s at $2,800 Skybridge Capital’s founder says bitcoin’s fair market value is about $40,000 based o
African Union greenlights AI adoption across member states
Amaka Nwaokocha1 hour agoAfrican Union greenlights AI adoption across member statesThe strategy aims to fast-track AI development and adoption in Africa, driving innovation and growth in the continent.340 Total views1 To
BitMEX co-founder must face suit over ‘God Access’ trading desk, judge rules
Jesse Coghlan2 hours agoBitMEX co-founder must face suit over ‘God Access’ trading desk, judge rulesDistrict Judge Andrew Carter said Benjamin Delo “was central” to an alleged scheme to use customer information t
War Spurs Crypto Activity in Russia and Ukraine, Chainalysis Reports
War Spurs Crypto Activity in Russia and Ukraine, Chainalysis Reports The deadly conflict that started with Russia’s assault on Ukraine has increased crypto-related activity in bo
ETH Compatible BCH Sidechain Smartbch Successfully Launches Three Nodes
ETH Compatible BCH Sidechain Smartbch Successfully Launches Three Nodes The day before the fourth Bitcoin Cash anniversary, the Smart Bitcoin Cash team (Smartbch
‘100x Lower Than L1 Fees’ — Alchemy Integrates Ethereum L2 Product Starknet to Increase Web3 Scalability
"100x Lower Than L1 Fees" — Alchemy Integrates Ethereum L2 Product Starknet to Increase Web3 Scalability According to the startup Starkware, the team’s Ethereum layer two
Crypto Asset Aptos Soars to All-Time High, Increasing 391% in 30 Days
Crypto Asset Aptos Soars to All-Time High, Increasing 391% in 30 Days During the past 30 days, the layer one blockchain asset aptos (APT) has risen 391.8% against the U.S. dollar.