Fun

Old Dolomite exchange contract suffers $1.8M loss from approval exploit

News Feed - 2024-03-21 06:03:25

Christopher Roark2 hours agoOld Dolomite exchange contract suffers $1.8M loss from approval exploitThe Ethereum version of Dolomite suffered a $1.8 million exploit, and the team is warning users to revoke approvals for this old address.1076 Total viewsListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAn old contract previously used by the Dolomite crypto exchange has been exploited for approximately $1.8 million, according to a March 20 report from blockchain security platform CertiK and seen by Cointelegraph. The exploit affected users who previously authorized approvals to the contract, and the development team recommended revoking approvals to the Ethereum Dolomite address that begins with 0xe2466. 


The development team claimed that users who have only interacted with the current version on Arbitrum should not be affected. They have also disabled the faulty contract, which should protect users who have not yet become victims of the attack. Even so, the team argued that users should revoke approvals to this contract.Source: Dolomite


Dolomite is a decentralized exchange and money market protocol that currently runs on Arbitrum and Polygon zkEVM. It originally launched on Ethereum in 2019. The team migrated it to the Arbitrum network in 2022 and gradually phased out support for the Ethereum version. Because of the immutable nature of smart contracts, users can still interact with its Ethereum version using developer tools.


According to the CertiK report, the attacker exploited a function named “callFunction” that allows a user to make any arbitrary calls. This function is guarded by a “noEntry” modifier, which under normal circumstances, should prevent any reentrancy attacks. However, this guard can be bypassed by the TradeManager contract located at 0xe2466, which contains a “call” function that has no reentrancy guard. Thus, the attacker was able to use this contract to drain funds from users, CertiK claimed.


The attacker transferred all of the stolen funds to address 0x5eAA7DadA44d59549A6c58008b2bd3C7F81d2502 and then deposited them into Tornado cash, Certik stated.


Related:ParaSwap evades hack targeting Augustus v6 contract vulnerability


This exploit is one of several that have occurred in March. On March 11, the Unizen protocol on Ethereum lost over $2.1 million due to an approval exploit. In that case, the development team promised to reimburse users as soon as possible. On March 15, Mozaic Finance lost over $2.4 million due to a private key compromise.# Ethereum# Hackers# Cryptocurrency Exchange# Hacks# Decentralized Exchange# DeFi# ArbitrumAdd reactionAdd reactionRead morePrice analysis 3/20: BTC, ETH, BNB, SOL, XRP, ADA, DOGE, AVAX, SHIB, TONSEC pushes deadline on VanEck spot Ether ETF applicationParaSwap evades hack targeting Augustus v6 contract vulnerability

News Feed

Zhiyuan Sun8 hours agoHTX to restore services ‘within 24 hours’ after $13.6M hack”Huobi HTX has now properly handled this attack,” the crypto exchange stated.9919 Total views8 Total sharesListen to article 0:00Ne
Helen Partz10 hours agoTelegram Wallet avoided self-custody to ease crypto onboarding, COO saysAs Telegram prepares to roll out Wallet as a native setting on the messenger in November, it’s important to understand why
Blockchain ID project Humanity Protocol hits unicorn status with $30M raise
Brayden Lindrea4 hours agoBlockchain ID project Humanity Protocol hits unicorn status with $30M raiseOver half a million people are already on the waitlist for Humanity Protocol’s public testnet launch, expected to tak
Nigeria Central Bank Governor Says CBDC Launch Just ‘a Couple of Days’ Away
Nigeria Central Bank Governor Says CBDC Launch Just "a Couple of Days" Away The governor of the Central Bank of Nigeria (CBN), Godwin Emefiele, has confirmed the country’s u
Neither Joe Biden nor Donald Trump are crypto champions
Nicholas Anthony1 hour agoNeither Joe Biden nor Donald Trump are crypto championsPresident Joe Biden hasn"t taken a particularly friendly stance toward cryptocurrency. On the contrary, he"s been a lot like his predecesso
US Government Seizes Trezor Wallet With $6.3 Million in Bitcoin From Gift Card Fraud Case
US Government Seizes Trezor Wallet With $6.3 Million in Bitcoin From Gift Card Fraud Case On September 22, 2021, a U.S. district judge from San Antonio, Texas, granted a summary ju
ZK International Subsidiary xSigma Introduces New Defi Project
ZK International Subsidiary xSigma Introduces New Defi Project PRESS RELEASE. xSigma Corporation, a wholly owned subsidiary of ZK International Group (NASDAQ:ZKI
Bitcoin Set To Hit $140,000 Target In December – Here’s Why
Este artículo también está disponible en español. Bitcoin (BTC) experienced a rather turbulent end to November, reaching a local bottom of $90,796 on Tuesday. Notably, th
Most Retail Crypto Investors Lost Money Over the Last 7 Years, According to BIS Analysis
Most Retail Crypto Investors Lost Money Over the Last 7 Years, According to BIS Analysis According to data from the Bank for International Settlements (BIS), published in the lates
Cardano Breaks Out Of Triangle—27% Surge Incoming?
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
How Penguin Karts Will Drive The Blockchain Gaming Scene Forward
How Penguin Karts Will Drive The Blockchain Gaming Scene Forward sponsored A lot has happened since the idea of Penguin Karts was first conceived. Who would have thought that a nost
Biggest Movers: ATOM Hits 2-Month High, as XRP Extends Recent Gains
Biggest Movers: ATOM Hits 2-Month High, as XRP Extends Recent Gains Cosmos rallied to a two-month high on Thursday, as cryptocurrency prices rebounded following Wednesday’s