Fun

Old Dolomite exchange contract suffers $1.8M loss from approval exploit

News Feed - 2024-03-21 06:03:25

Christopher Roark2 hours agoOld Dolomite exchange contract suffers $1.8M loss from approval exploitThe Ethereum version of Dolomite suffered a $1.8 million exploit, and the team is warning users to revoke approvals for this old address.1076 Total viewsListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAn old contract previously used by the Dolomite crypto exchange has been exploited for approximately $1.8 million, according to a March 20 report from blockchain security platform CertiK and seen by Cointelegraph. The exploit affected users who previously authorized approvals to the contract, and the development team recommended revoking approvals to the Ethereum Dolomite address that begins with 0xe2466. 


The development team claimed that users who have only interacted with the current version on Arbitrum should not be affected. They have also disabled the faulty contract, which should protect users who have not yet become victims of the attack. Even so, the team argued that users should revoke approvals to this contract.Source: Dolomite


Dolomite is a decentralized exchange and money market protocol that currently runs on Arbitrum and Polygon zkEVM. It originally launched on Ethereum in 2019. The team migrated it to the Arbitrum network in 2022 and gradually phased out support for the Ethereum version. Because of the immutable nature of smart contracts, users can still interact with its Ethereum version using developer tools.


According to the CertiK report, the attacker exploited a function named “callFunction” that allows a user to make any arbitrary calls. This function is guarded by a “noEntry” modifier, which under normal circumstances, should prevent any reentrancy attacks. However, this guard can be bypassed by the TradeManager contract located at 0xe2466, which contains a “call” function that has no reentrancy guard. Thus, the attacker was able to use this contract to drain funds from users, CertiK claimed.


The attacker transferred all of the stolen funds to address 0x5eAA7DadA44d59549A6c58008b2bd3C7F81d2502 and then deposited them into Tornado cash, Certik stated.


Related:ParaSwap evades hack targeting Augustus v6 contract vulnerability


This exploit is one of several that have occurred in March. On March 11, the Unizen protocol on Ethereum lost over $2.1 million due to an approval exploit. In that case, the development team promised to reimburse users as soon as possible. On March 15, Mozaic Finance lost over $2.4 million due to a private key compromise.# Ethereum# Hackers# Cryptocurrency Exchange# Hacks# Decentralized Exchange# DeFi# ArbitrumAdd reactionAdd reactionRead morePrice analysis 3/20: BTC, ETH, BNB, SOL, XRP, ADA, DOGE, AVAX, SHIB, TONSEC pushes deadline on VanEck spot Ether ETF applicationParaSwap evades hack targeting Augustus v6 contract vulnerability

News Feed

Turner Wright2 hours agoNevada court approves regulator’s petition to place Prime Trust into receivership, pending hearingPrime Trust will have the opportunity to show why a petition from the Nevada Financial Instituti
Weiss Ratings Report Claims Crypto-Backed Home Loans Spell Trouble
Weiss Ratings Report Claims Crypto-Backed Home Loans Spell Trouble A report published on May 2 by the rating agency Weiss Ratings warns that crypto-backed mortgages “spell r
Hong Kong launches Project Ensemble to support tokenization with wCBDC
Derek Andersen5 hours agoHong Kong launches Project Ensemble to support tokenization with wCBDCThe HKMA’s latest CBDC project will look at tokenized deposits in tokenized asset transactions.529 Total views1 Total share
Bitcoin Price Spikes Over 9% as the Crypto Asset’s Value Nears $15K
Bitcoin Price Spikes Over 9% as the Crypto Asset"s Value Nears $15K The crypto economy has jumped over the $400 billion mark and is now hovering around $414 bill
Real Estate Platform Pacaso Accepts Crypto Assets for Payments, CEO Says ‘Mass Crypto Adoption Well Underway’
Real Estate Platform Pacaso Accepts Crypto Assets for Payments, CEO Says "Mass Crypto Adoption Well Underway" On October 20, the day bitcoin smashed a new all-time price high, the
Flight Radar Report Shows FTX Co-Founder’s Private Jet Flew to Argentina, SBF Says He’s Still in the Bahamas
Flight Radar Report Shows FTX Co-Founder"s Private Jet Flew to Argentina, SBF Says He"s Still in the Bahamas According to Flightradar24’s official Twitter account, the most track
Israeli Police Arrest Beitar Jerusalem Owner and 7 Suspects in Multimillion-Dollar Crypto Fraud
Israeli Police Arrest Beitar Jerusalem Owner and 7 Suspects in Multimillion-Dollar Crypto Fraud Israeli police have arrested eight suspects in connection with a cryptocurrency frau
Ana Paula Pereira4 hours agoFTX advisers sharing customers’ data with FBI: ReportFTX advisers have complied with subpoenas from multiple FBI field offices in recent months, providing law enforcement with records of som
Charges of Fraudulent Pretense: US Court Unseals Onecoin Cofounder’s Indictment
Charges of Fraudulent Pretense: US Court Unseals Onecoin Cofounder"s IndictmentManhattan prosecutors from the New York Southern District Court (NYSD) have unsealed indictment charge
Solving the blockchain trilemma with decentralized scalability
Cointelegraph14 hours agoSolving the blockchain trilemma with decentralized scalabilityThis podcast is produced in collaboration with the Metis network and explores the role of layer-2 solutions in providing fast, secure
Opium‌ ‌Protocol Allows Traders to Hedge or Bet Against the Stablecoin Tether’s Solvency
Opium‌ ‌Protocol Allows Traders to Hedge or Bet Against the Stablecoin Tether"s SolvencyCryptocurrency traders can now protect their tether tokens or bet against the solvency of
Tron’s Steemit Acquisition Exposes Delegated-Proof-of-Stake Centralization
Tron"s Steemit Acquisition Exposes Delegated-Proof-of-Stake Centralization The Steemit community is mired in controversy over the recent Tron takeover that managed to change the