Fun

ParaSwap evades hack targeting Augustus v6 contract vulnerability

News Feed - 2024-03-20 05:03:34

Arijit Sarkar34 minutes agoParaSwap evades hack targeting Augustus v6 contract vulnerabilityParaSwap paused the V6 API soon after discovering the vulnerability and secured the potential victims’ funds through a white hack. Plans to reimburse potential victims are underway.175 Total views10 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksDecentralized finance (DeFi) aggregator ParaSwap discovered a vulnerability in its newly launched Augustus V6 contract and prevented a colossal loss of funds through timely white hat intervention.


On March 18, the ParaSwap Augustus v6 went live, promising greater efficiency in swapping gas fees than all its preceding contracts. The contract contained a critical vulnerability that would allow hackers to drain funds when approved.


Soon after discovering the vulnerability, on March 20, ParaSwap paused the v6 application prog interface (API) and secured the potential victims’ funds through a white hack.Source: ParaSwap


ParaSwap advised all users to revoke permissions to the Augustus v6 contract to avoid further loss of funds until the vulnerability is neutralized.


Despite ParaSwap’s proactive effort to roll back the vulnerable v6 contract and inform users to take necessary steps as well, the hacker managed to cash out funds worth roughly $24,000 from four different addresses.


In total, ParaSwap revealed that 386 addresses were affected by the vulnerability. The protocol also asked users to report any loss of funds that may have gone unidentified during the preliminary investigation.ParaSwap identified 386 wallet addresses being affected by the Augustus Vv contract vulnerability. Source: paraswap.notion.site


In addition, ParaSwap also deactivated the support for the vulnerable v6 contract on its recently updated user interface (UI) and reverted to using v5. “We have successfully recovered funds for all addresses, and more details about the refund process will be shared soon,” the company added.


ParaSwap did not immediately respond to Cointelegraph’s request for comment.


Affected users remain at risk as long as they haven’t revoked their approvals, so ParaSwap recommends individuals use exploit checker services like Revoke to confirm their safety. Check out Cointelegraph’s guide on how to identify and mitigate smart contract vulnerabilities.


Related:Old Trust Wallet iOS vulnerability from 2018 may still affect some accounts


Generative artificial intelligence (AI) tools like the ChatGPT-4 are good at generating and parsing codes. However, the tools fail to perform as a fully reliable security auditor.


According to a recently published research paper from a pair of researchers from Salus Security, a blockchain security company with offices in North America, Europe and Asia:“GPT-4 can be a useful tool in assisting with smart contract auditing, especially in code parsing and providing vulnerability hints. However, given its limitations in vulnerability detection, it cannot fully replace professional auditing tools and experienced auditors at this time.”


According to their findings, ChatGPT is good at detecting true positives — actual vulnerabilities that, outside of a testing environment, would be worth investigating. It reached greater than 80% precision in testing.


Magazine:South Africa’s digital-nomad crypto hub: Cape Town, Crypto City Guide# Blockchain# Smart Contracts# Hackers# CODE# Hacks# DeFiAdd reactionAdd reactionRead moreTrezor X account shills fake presale tokens in suspected hackSygnum bank to tokenize $50M of Matter Labs’ reserves for transparencySquare Enix invests in Web3 and NFT gaming platform HyperPlay

News Feed

Who is ‘Mr. 100’? Mysterious Bitcoin whale becomes 14th-biggest BTC holder
Zoltan Vardai8 hours agoWho is ‘Mr. 100’? Mysterious Bitcoin whale becomes 14th-biggest BTC holderThe Bitcoin wallet has added 100 BTC tranches regularly since at least November 2022, when FTX collapsed.3833 Total vi
Artists sue SEC over NFT status, DraftKings kills NFT business: Nifty Newsletter
Ezra Reguerra5 hours agoArtists sue SEC over NFT status, DraftKings kills NFT business: Nifty NewsletterTwo artists have taken legal action to demand clarification from the SEC over the status of NFTs.1064 Total views2 T
Samsung secures $6.4B grant to expand Texas chip manufacturing: Report
Zoltan Vardai13 hours agoSamsung secures $6.4B grant to expand Texas chip manufacturing: ReportThe South Korean manufacturing conglomerate also plans to invest up to $45 billion in expanding its Texas facility by the end
Welcome to the United Kingdom — Please hand over your crypto
Syed Rahman6 hours agoWelcome to the United Kingdom — Please hand over your cryptoAn April change to United Kingdom law will allow authorities to treat crypto like other assets by seizing it without accusing suspects o
Russia Not Ready for Bitcoin as Legal Tender, Putin’s Spokesman Peskov Says
Russia Not Ready for Bitcoin as Legal Tender, Putin’s Spokesman Peskov Says Russia has no reason to recognize bitcoin, President Putin’s press secretary has noted after El
US senators oppose Joe Biden’s CBDC plans
Arijit Sarkar1 hour agoUS senators oppose Joe Biden’s CBDC plansThe Federal Reserve’s plan for digital dollar issuance in the United States was met with a roadblock after five senators filed legislation demanding a b
DMEX: No-KYC Derivatives DEX With up To 100x Leverage
DMEX: No-KYC Derivatives DEX With up To 100x Leverage DMEX is a decentralized anonymous margin trading exchange that doesn’t require KYC checks, simply gen
Turner Wright1 hour agoCrypto ATM firm Bitcoin Depot will go public on Nasdaq starting July 3The special purpose acquisition company deal, first reported in August 2022, cost $885 million and is expected to allow investo
Martin Young4 hours agoTerraform Labs contends Citadel Securities had a hand in its stablecoin collapseTerraform Labs has urged the judge to grant its motion to compel trading data from Citadel Securities, which it says
Bugs in Gains Network fork let traders profit 900% on every trade: Report
Christopher Roark3 hours agoBugs in Gains Network fork let traders profit 900% on every trade: ReportAn attacker could have placed a limit buy order with an arbitrarily high open price to automatically win every trade, t
Luxury Retailer Tiffany & Co. Announces Jeweled Cryptopunk Pendants Tied to NFTs
Luxury Retailer Tiffany & Co. Announces Jeweled Cryptopunk Pendants Tied to NFTs The luxury jewelry and specialty retailer Tiffany & Co. announced the firm is planning to sell 250
Oil Producers and Bitcoin Miners Meet in Texas to Discuss Cooperative Mining Possibilities
Oil Producers and Bitcoin Miners Meet in Texas to Discuss Cooperative Mining Possibilities A meetup in a vehicle warehouse in Houston served as an encounter point for oil producers