Fun

ParaSwap evades hack targeting Augustus v6 contract vulnerability

News Feed - 2024-03-20 05:03:34

Arijit Sarkar34 minutes agoParaSwap evades hack targeting Augustus v6 contract vulnerabilityParaSwap paused the V6 API soon after discovering the vulnerability and secured the potential victims’ funds through a white hack. Plans to reimburse potential victims are underway.175 Total views10 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksDecentralized finance (DeFi) aggregator ParaSwap discovered a vulnerability in its newly launched Augustus V6 contract and prevented a colossal loss of funds through timely white hat intervention.


On March 18, the ParaSwap Augustus v6 went live, promising greater efficiency in swapping gas fees than all its preceding contracts. The contract contained a critical vulnerability that would allow hackers to drain funds when approved.


Soon after discovering the vulnerability, on March 20, ParaSwap paused the v6 application prog interface (API) and secured the potential victims’ funds through a white hack.Source: ParaSwap


ParaSwap advised all users to revoke permissions to the Augustus v6 contract to avoid further loss of funds until the vulnerability is neutralized.


Despite ParaSwap’s proactive effort to roll back the vulnerable v6 contract and inform users to take necessary steps as well, the hacker managed to cash out funds worth roughly $24,000 from four different addresses.


In total, ParaSwap revealed that 386 addresses were affected by the vulnerability. The protocol also asked users to report any loss of funds that may have gone unidentified during the preliminary investigation.ParaSwap identified 386 wallet addresses being affected by the Augustus Vv contract vulnerability. Source: paraswap.notion.site


In addition, ParaSwap also deactivated the support for the vulnerable v6 contract on its recently updated user interface (UI) and reverted to using v5. “We have successfully recovered funds for all addresses, and more details about the refund process will be shared soon,” the company added.


ParaSwap did not immediately respond to Cointelegraph’s request for comment.


Affected users remain at risk as long as they haven’t revoked their approvals, so ParaSwap recommends individuals use exploit checker services like Revoke to confirm their safety. Check out Cointelegraph’s guide on how to identify and mitigate smart contract vulnerabilities.


Related:Old Trust Wallet iOS vulnerability from 2018 may still affect some accounts


Generative artificial intelligence (AI) tools like the ChatGPT-4 are good at generating and parsing codes. However, the tools fail to perform as a fully reliable security auditor.


According to a recently published research paper from a pair of researchers from Salus Security, a blockchain security company with offices in North America, Europe and Asia:“GPT-4 can be a useful tool in assisting with smart contract auditing, especially in code parsing and providing vulnerability hints. However, given its limitations in vulnerability detection, it cannot fully replace professional auditing tools and experienced auditors at this time.”


According to their findings, ChatGPT is good at detecting true positives — actual vulnerabilities that, outside of a testing environment, would be worth investigating. It reached greater than 80% precision in testing.


Magazine:South Africa’s digital-nomad crypto hub: Cape Town, Crypto City Guide# Blockchain# Smart Contracts# Hackers# CODE# Hacks# DeFiAdd reactionAdd reactionRead moreTrezor X account shills fake presale tokens in suspected hackSygnum bank to tokenize $50M of Matter Labs’ reserves for transparencySquare Enix invests in Web3 and NFT gaming platform HyperPlay

News Feed

German Cannabis Firm Hedges Bitcoin to Protect from Massive Currency Devaluation
German Cannabis Firm Hedges Bitcoin to Protect from Massive Currency Devaluation On Tuesday, the cannabis firm Synbiotic SE, a publicly-traded company in Germany
Kraken-CertiK saga turns murky as part of exploited funds go ‘missing’
Prashant Jha5 hours agoKraken-CertiK saga turns murky as part of exploited funds go ‘missing’Kraken is planning to take legal action against security firm CertiK as the “white hat” operation by the security firm
Tristan Greene3 hours agoOxford scientists develop GPU-accelerated limit order book sim to teach AI how to tradeThe first-of-its-kind architecture gives up to a 7x speedup over traditional training methods.1940 Total vie
David Attlee12 hours agoThere could be 24 CBDCs live by 2030: BIS survey93% of central banks are already conducting research on central bank digital currencies.3000 Total views2 Total sharesListen to article 0:00NewsJoin
SEC Slaps Former Coinbase Manager With Insider Trading Charges — Identifies 9 Crypto Tokens as Securities
SEC Slaps Former Coinbase Manager With Insider Trading Charges — Identifies 9 Crypto Tokens as Securities The U.S. Securities and Exchange Commission (SEC) has announced insider
A Look at ‘Individual X’ and the Seized Stash of Silk Road Bitcoins Worth $1 Billion
A Look at "Individual X" and the Seized Stash of Silk Road Bitcoins Worth $1 Billion On November 3, 2020, the cryptocurrency community noticed that one of the la
Ezra Reguerra12 hours agoXbox to enhance game dialogues with generative AI through new partnershipThe company will provide an AI toolset for game developers to improve scripts, dialogue trees and quests inside games.1696
Leading Japanese Firms Partner on Security Token Research
Mitsubishi UFJ Financial Group – Japan’s largest financial group and the fifth largest bank in the world by assets – is leading a 22-member research consortium to develop standards around security token man
Sega Hints at the Inclusion of NFT and Metaverse Elements in Its ‘Super Game’ Proposal
Sega Hints at the Inclusion of NFT and Metaverse Elements in Its "Super Game" Proposal Sega, the renowned game development company based in Japan, has hinted at the use of NFT (non
Mt. Gox just moved $3B in Bitcoin — Here’s why the price barely blipped
Ciaran Lyons2 hours agoMt. Gox just moved $3B in Bitcoin — Here’s why the price barely blippedCrypto analysts say Mt. Gox holders are more likely committed to hodling, and the market thinks so, too.1969 Total views1
Meet the First BCH Dex Built on Smartbch — Benswap.cash Presents High-Yield Liquidity Pools, Noncustodial Swaps
Meet the First BCH Dex Built on Smartbch — Benswap.cash Presents High-Yield Liquidity Pools, Noncustodial Swaps Decentralized finance (defi) has set a trend during the latter hal
LBank: DafriBank Aims for Making DBA Africa’s Number 1 Cryptocurrency
LBank: DafriBank Aims for Making DBA Africa’s Number 1 Cryptocurrency press release PRESS RELEASE. Since blockchain technology and crypto have become the power of the next industr