Fun

Old Dolomite exchange contract suffers $1.8M loss from approval exploit

News Feed - 2024-03-21 06:03:25

Christopher Roark2 hours agoOld Dolomite exchange contract suffers $1.8M loss from approval exploitThe Ethereum version of Dolomite suffered a $1.8 million exploit, and the team is warning users to revoke approvals for this old address.1076 Total viewsListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAn old contract previously used by the Dolomite crypto exchange has been exploited for approximately $1.8 million, according to a March 20 report from blockchain security platform CertiK and seen by Cointelegraph. The exploit affected users who previously authorized approvals to the contract, and the development team recommended revoking approvals to the Ethereum Dolomite address that begins with 0xe2466. 


The development team claimed that users who have only interacted with the current version on Arbitrum should not be affected. They have also disabled the faulty contract, which should protect users who have not yet become victims of the attack. Even so, the team argued that users should revoke approvals to this contract.Source: Dolomite


Dolomite is a decentralized exchange and money market protocol that currently runs on Arbitrum and Polygon zkEVM. It originally launched on Ethereum in 2019. The team migrated it to the Arbitrum network in 2022 and gradually phased out support for the Ethereum version. Because of the immutable nature of smart contracts, users can still interact with its Ethereum version using developer tools.


According to the CertiK report, the attacker exploited a function named “callFunction” that allows a user to make any arbitrary calls. This function is guarded by a “noEntry” modifier, which under normal circumstances, should prevent any reentrancy attacks. However, this guard can be bypassed by the TradeManager contract located at 0xe2466, which contains a “call” function that has no reentrancy guard. Thus, the attacker was able to use this contract to drain funds from users, CertiK claimed.


The attacker transferred all of the stolen funds to address 0x5eAA7DadA44d59549A6c58008b2bd3C7F81d2502 and then deposited them into Tornado cash, Certik stated.


Related:ParaSwap evades hack targeting Augustus v6 contract vulnerability


This exploit is one of several that have occurred in March. On March 11, the Unizen protocol on Ethereum lost over $2.1 million due to an approval exploit. In that case, the development team promised to reimburse users as soon as possible. On March 15, Mozaic Finance lost over $2.4 million due to a private key compromise.# Ethereum# Hackers# Cryptocurrency Exchange# Hacks# Decentralized Exchange# DeFi# ArbitrumAdd reactionAdd reactionRead morePrice analysis 3/20: BTC, ETH, BNB, SOL, XRP, ADA, DOGE, AVAX, SHIB, TONSEC pushes deadline on VanEck spot Ether ETF applicationParaSwap evades hack targeting Augustus v6 contract vulnerability

News Feed

Grayscale’s GBTC stops bleeding: First inflow since launch
Ciaran Lyons4 hours agoGrayscale’s GBTC stops bleeding: First inflow since launchGrayscale Investments" GBTC has seen its first day of inflows, following over $17.5 billion in outflows since the launch of Bitcoin ETFs
Best AI Agent Coins to Buy as Investor Hype Remains Steady on AI Industry
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
London’s ‘Joe Rogan’ and crypto advocate Brian Rose makes bid for mayor
Robert D. Knight10 hours agoLondon’s ‘Joe Rogan’ and crypto advocate Brian Rose makes bid for mayorThe former Wall Street and City of London banker is making his second bid to become mayor of London.4369 Total view
CoinEx Looks Forward to Celebrating RLWC2021’s Finalists
CoinEx Looks Forward to Celebrating RLWC2021’s Finalists press release PRESS RELEASE.As the exclusive cryptocurrency trading platform partner of the Rugby League World Cup 2021 (R
Technical Analysis: Terra Luna Drops 20%, While Symbol Token Climbs on Friday
Technical Analysis: Terra Luna Drops 20%, While Symbol Token Climbs on Friday Terra (Luna) was one of this week’s biggest crypto losers, falling by as much as 20% during Fri
Bitcoin, Ethereum Technical Analysis: BTC, ETH Consolidate as Markets Prepare for Christmas Break
Bitcoin, Ethereum Technical Analysis: BTC, ETH Consolidate as Markets Prepare for Christmas Break Bitcoin continued to consolidate to start the week, as market volatility remained
Youth Fashion Retail Chain Pacsun Now Accepts 11 Cryptocurrencies
Youth Fashion Retail Chain Pacsun Now Accepts 11 Cryptocurrencies On October 5, the youth fashion and retail brand Pacsun announced the company is now accepting cryptocurrencies vi
Top New Crypto to HODL as BitGo Launches OTC Trading Services amid 2025 IPO Rumors
BitGo, a popular crypto custody service firm, has now introduced over-the-counter (OTC) trading for digital assets. This will allow traders to trade in derivatives of more than 250 digital assets. BitGo will also offer y
BIS Economists Recommend 3 Crypto Policies for Regulators Worldwide to Adopt
BIS Economists Recommend 3 Crypto Policies for Regulators Worldwide to Adopt Economists at the Bank of International Settlements (BIS) have recommended three policies regulators wo
Derek Andersen5 hours agoFed governor Bowman doubles down on CBDC skepticism, likes stablecoin no betterMichelle Bowman told a university audience that financial innovation should be justified by need and be properly reg
Tron (TRX) Leads The Crypto Market With 100% Rally To New ATH, $0.5 Next?
Este artículo también está disponible en español. Tron (TRX) joined the crypto market’s rally by jumping over 100% in 24 hours to a new all-time high (ATH). Its surge i
Best Crypto to Buy as OpenAI and Musk’s Battle Escalates & OpenAI Tests New AI Agent
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu