Fun

Old Dolomite exchange contract suffers $1.8M loss from approval exploit

News Feed - 2024-03-21 06:03:25

Christopher Roark2 hours agoOld Dolomite exchange contract suffers $1.8M loss from approval exploitThe Ethereum version of Dolomite suffered a $1.8 million exploit, and the team is warning users to revoke approvals for this old address.1076 Total viewsListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAn old contract previously used by the Dolomite crypto exchange has been exploited for approximately $1.8 million, according to a March 20 report from blockchain security platform CertiK and seen by Cointelegraph. The exploit affected users who previously authorized approvals to the contract, and the development team recommended revoking approvals to the Ethereum Dolomite address that begins with 0xe2466. 


The development team claimed that users who have only interacted with the current version on Arbitrum should not be affected. They have also disabled the faulty contract, which should protect users who have not yet become victims of the attack. Even so, the team argued that users should revoke approvals to this contract.Source: Dolomite


Dolomite is a decentralized exchange and money market protocol that currently runs on Arbitrum and Polygon zkEVM. It originally launched on Ethereum in 2019. The team migrated it to the Arbitrum network in 2022 and gradually phased out support for the Ethereum version. Because of the immutable nature of smart contracts, users can still interact with its Ethereum version using developer tools.


According to the CertiK report, the attacker exploited a function named “callFunction” that allows a user to make any arbitrary calls. This function is guarded by a “noEntry” modifier, which under normal circumstances, should prevent any reentrancy attacks. However, this guard can be bypassed by the TradeManager contract located at 0xe2466, which contains a “call” function that has no reentrancy guard. Thus, the attacker was able to use this contract to drain funds from users, CertiK claimed.


The attacker transferred all of the stolen funds to address 0x5eAA7DadA44d59549A6c58008b2bd3C7F81d2502 and then deposited them into Tornado cash, Certik stated.


Related:ParaSwap evades hack targeting Augustus v6 contract vulnerability


This exploit is one of several that have occurred in March. On March 11, the Unizen protocol on Ethereum lost over $2.1 million due to an approval exploit. In that case, the development team promised to reimburse users as soon as possible. On March 15, Mozaic Finance lost over $2.4 million due to a private key compromise.# Ethereum# Hackers# Cryptocurrency Exchange# Hacks# Decentralized Exchange# DeFi# ArbitrumAdd reactionAdd reactionRead morePrice analysis 3/20: BTC, ETH, BNB, SOL, XRP, ADA, DOGE, AVAX, SHIB, TONSEC pushes deadline on VanEck spot Ether ETF applicationParaSwap evades hack targeting Augustus v6 contract vulnerability

News Feed

Turner Wright3 hours agoSam Bankman-Fried denies knowledge of moving FTX deposits to North Dimension: ReportAssistant U.S. Attorney Danielle Sassoon grilled the former FTX CEO in court on his knowledge of FTX user deposi
Kraken considers dropping USDT in Europe ahead of new regulations
Ana Paula Pereira6 hours agoKraken considers dropping USDT in Europe ahead of new regulationsWith new regulations in Europe set to enforce strict limits on transactions and reserve requirements, Kraken is assessing its s
Securities Numbering Body Launches Task Force to Standardize Digital Assets
The Association of National Numbering Agencies (ANNA) has launched a task force to address digital asset labelings across financial markets. Announced Wednesday, the new task force
Indonesia Will Not Ban Cryptocurrencies Like China, Minister Says as Crypto Trade Soars
Indonesia Will Not Ban Cryptocurrencies Like China, Minister Says as Crypto Trade Soars Authorities in Indonesia do not intend to follow China’s example of imposing an outri
MicroStrategy’s Q2 earnings reveals Bitcoin stockpile now $14.7B
Tom Mitchelhill8 hours agoMicroStrategy’s Q2 earnings reveals Bitcoin stockpile now $14.7BMicroStrategy shares jumped just 1% in after-hours trading, with the company posting a net loss of $123 million in the second qu
Wharton Professor Urges the Fed to ‘Bite the Bullet’ and Defend the US Dollar — Warns About Bitcoin Taking Over
Wharton Professor Urges the Fed to "Bite the Bullet" and Defend the US Dollar — Warns About Bitcoin Taking Over A finance professor at the Wharton School of the University of Pen
Argentine Digital Peso Proposal: Eliminate Tax Evasion by Digitizing the Full Fiat Currency Supply
Argentine Digital Peso Proposal: Eliminate Tax Evasion by Digitizing the Full Fiat Currency Supply A proposal to eliminate the physical representation of the Argentine Peso, in ord
Binance class-action lawsuit dismissal reversed by appeals court
Ciaran Lyons7 hours agoBinance class-action lawsuit dismissal reversed by appeals courtThe United States appeals court declared that the rationale given by the district court for dismissing the lawsuit against crypto exc
South African University to Commence Blockchain and Digital Currency Education in November
South African University to Commence Blockchain and Digital Currency Education in November A South African university, the University of Cape Town (UCT) has revealed it will commen
Crypto ETF Race Heats Up in 2021- Valkyrie Bitcoin Trust Files to List Shares on NYSE
Crypto ETF Race Heats Up in 2021- Valkyrie Bitcoin Trust Files to List Shares on NYSE 2021 has been an explosive year for bitcoin as the crypto asset has touched
Solana Price Faces Slowdown: Support And Resistance Levels To Keep An Eye On
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
MiCA laws come into effect in Europe — Here’s what you need to know
Savannah Fortis10 hours agoMiCA laws come into effect in Europe — Here’s what you need to knowThe EU’s Markets in Crypto-Assets Regulation introduces new rules for the cryptocurrency industry, which will affect sta