Fun

Hacker mints 1B tokens in $16M Curio smart contract exploit

News Feed - 2024-03-26 08:03:19

Ezra Reguerra12 hours agoHacker mints 1B tokens in $16M Curio smart contract exploitCurio said it will conduct a fund compensation program for affected liquidity providers, which could potentially take up to one year to complete.1055 Total views13 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksReal-world asset (RWA) liquidity firm Curio suffered a smart contract exploit involving a critical vulnerability related to voting power privileges, allowing the attacker to steal $16 million in digital assets.


Curio alerted its community of the exploit and highlighted that they are addressing the situation. The company said that a MakerDAO-based smart contract used within Curio was breached.


However, the company assured its users that the exploit only affected the Ethereum side and that all Polkadot and the Curio Chain contracts remained secure.


Web3 security firm Cyvers estimated that the losses from the exploit are about $16 million. The security firm said the exploit involved a “permission access logic vulnerability.”Source: Cyvers Alerts


On March 25, Curio published a post-mortem of the exploit and a compensation plan for affected users. Within the report, Curio highlighted that the problem was a flaw in the voting power privilege access control.


With this, the attacker acquired a small number of Curio Governance (CGT) tokens, allowing them to gain access and elevate their voting power in the project’s smart contract.


With the elevated voting power, the attacker performed a series of steps that ultimately allowed the execution of arbitrary actions within the Curio DAO contract. This led to the unauthorized minting of 1 billion CGT.


In the report, Curio said all the funds affected in the exploit will be returned. The team said it would release a new token called CGT 2.0. With the new token, the team promised to restore 100% of the funds for CGT holders.


Related:Hacker moves $10M from 2023 phishing incident to Tornado Cash


For liquidity providers, Curio said that it will conduct a fund compensation program. The team said it will be paid in four stages, with each stage lasting 90 days. This could mean that full payment could potentially take one year. They wrote:“The compensation program will consist of 4 consecutive stages, each lasting for 90 days. During each stage: compensation will be paid in USDC/USDT, amounting to 25% of the losses incurred by the second token in the liquidity pools.”


The company also said that it would reward white hat hackers who can help in recovering the lost funds. The team said that hackers could receive a reward equivalent to 10% of funds recovered in the initial recovery phase.


Magazine:‘Am I sorry? No’ — 3AC founder. $6B BTC laundered for fast food worker: Asia Express# Blockchain# Security# Hackers# Cybersecurity# HacksAdd reactionAdd reactionRead moreCrypto game ‘Munchables’ on Blast exploited for $63MMastercard sees partnerships as key to blockchain remittances in Latam‘Ripple is well-positioned to pay a significant civil penalty,‘ says SEC

News Feed

Jesse Coghlan1 hour agoAre Bitcoin ETFs good for adoption or ‘watered-down crypto’? Debate ragesAs hype builds for spot Bitcoin ETFs in the U.S., some are concerned the industry is moving away from the “core promis
Unreported Transactions Linked to Disgraced FTX Co-Founder Revealed by Onchain Investigation
Unreported Transactions Linked to Disgraced FTX Co-Founder Revealed by Onchain Investigation According to onchain research, wallets connected to Sam Bankman-Fried, the disgraced co
Derek Andersen2 hours agoAPEC finance ministers to share perspectives on crypto at meeting in San FranciscoU.S. Treasury Secretary Janet Yellen said she is looking forward to hearing from the finance ministers of some of
Tom Blackstone10 hours agoWeb3 game project allegedly hired actors to pose as executives in $1.6M exit scamCertiK says Standard Cross Finance hired actors to pose as executives, then dumped tokens on investors, draining
Bitcoin, Ethereum Technical Analysis: ETH Surges Above $1,200 to Start the Weekend
Bitcoin, Ethereum Technical Analysis: ETH Surges Above $1,200 to Start the Weekend Ethereum was back above $1,200 on Saturday, as bullish sentiment returned to cryptocurrency marke
5 Takeaways on Ethereum 2.0 From Vitalik’s ‘Beast Mode’ Blog Posts
The Takeaway: Moving ETH from the Ethereum 2.0 blockchain to the old ethereum blockchain may be possible in the early months (or years) after launch, new research suggests. Due to changes in data storage structure, recal
Bitcoin Slips in Latest Crypto Ranking by Chinese Government-Backed Center
Bitcoin Slips in Latest Crypto Ranking by Chinese Government-Backed CenterChina’s Center for Information and Industry Development has revised its rankings of 37 crypto project
Square’s Cash App Generates $1.8 Billion in Bitcoin Revenue, BTC Profit up 29% in Q3
Square’s Cash App Generates $1.8 Billion in Bitcoin Revenue, BTC Profit up 29% in Q3 Square Inc. has reported bitcoin revenue of $1.82 billion in the third quarter, an 11% increa
LBank and Adanian Labs Kickstarts a ‘Crypto Accelerator Program’ in Kenya
LBank and Adanian Labs Kickstarts a ‘Crypto Accelerator Program’ in Kenya press release PRESS RELEASE.The blockchain ecosystem is growing exponentially. It has brought prosperit
Vitalik Buterin donates over $500K in animal-themed coins to charity
Ezra Reguerra10 hours agoVitalik Buterin donates over $500K in animal-themed coins to charityVitalik Buterin urged the community to send the memecoin token funds they want to send him directly to charities.8362 Total vie
Bitcoin CME Gap Close About To Happen With Push Toward $83,000 – What Happens Next?
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Twitch Director Shaan Puri Moves 25% of Net Worth Into Bitcoin to ‘Front Run Wave of Institutional Capital’
Twitch Director Shaan Puri Moves 25% of Net Worth Into Bitcoin to "Front Run Wave of Institutional Capital" Twitch director and former CEO of Bebo Shaan Puri ann