Fun

Hacker mints 1B tokens in $16M Curio smart contract exploit

News Feed - 2024-03-26 08:03:19

Ezra Reguerra12 hours agoHacker mints 1B tokens in $16M Curio smart contract exploitCurio said it will conduct a fund compensation program for affected liquidity providers, which could potentially take up to one year to complete.1055 Total views13 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksReal-world asset (RWA) liquidity firm Curio suffered a smart contract exploit involving a critical vulnerability related to voting power privileges, allowing the attacker to steal $16 million in digital assets.


Curio alerted its community of the exploit and highlighted that they are addressing the situation. The company said that a MakerDAO-based smart contract used within Curio was breached.


However, the company assured its users that the exploit only affected the Ethereum side and that all Polkadot and the Curio Chain contracts remained secure.


Web3 security firm Cyvers estimated that the losses from the exploit are about $16 million. The security firm said the exploit involved a “permission access logic vulnerability.”Source: Cyvers Alerts


On March 25, Curio published a post-mortem of the exploit and a compensation plan for affected users. Within the report, Curio highlighted that the problem was a flaw in the voting power privilege access control.


With this, the attacker acquired a small number of Curio Governance (CGT) tokens, allowing them to gain access and elevate their voting power in the project’s smart contract.


With the elevated voting power, the attacker performed a series of steps that ultimately allowed the execution of arbitrary actions within the Curio DAO contract. This led to the unauthorized minting of 1 billion CGT.


In the report, Curio said all the funds affected in the exploit will be returned. The team said it would release a new token called CGT 2.0. With the new token, the team promised to restore 100% of the funds for CGT holders.


Related:Hacker moves $10M from 2023 phishing incident to Tornado Cash


For liquidity providers, Curio said that it will conduct a fund compensation program. The team said it will be paid in four stages, with each stage lasting 90 days. This could mean that full payment could potentially take one year. They wrote:“The compensation program will consist of 4 consecutive stages, each lasting for 90 days. During each stage: compensation will be paid in USDC/USDT, amounting to 25% of the losses incurred by the second token in the liquidity pools.”


The company also said that it would reward white hat hackers who can help in recovering the lost funds. The team said that hackers could receive a reward equivalent to 10% of funds recovered in the initial recovery phase.


Magazine:‘Am I sorry? No’ — 3AC founder. $6B BTC laundered for fast food worker: Asia Express# Blockchain# Security# Hackers# Cybersecurity# HacksAdd reactionAdd reactionRead moreCrypto game ‘Munchables’ on Blast exploited for $63MMastercard sees partnerships as key to blockchain remittances in Latam‘Ripple is well-positioned to pay a significant civil penalty,‘ says SEC

News Feed

US House may vote to overturn Biden's SAB 121 veto next week
Brayden Lindrea7 hours agoUS House may vote to overturn Biden"s SAB 121 veto next weekWhile the House and Senate already voted to overturn SAB 121, it will need a two-thirds majority vote from both chambers to invalidate
Bitcoin Just Did It — New Record High Above $125,000 This ‘Uptober’
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
How STACKD Finance Services Make DeFi Safer for Everyone
How STACKD Finance Services Make DeFi Safer for Everyone sponsored Decentralized Finance (DeFi)represents the financial, blockchain-based world of tomorrow. Future generations will
South Korean PC Gaming Rooms Rely on Crypto Mining to Profit During the Coronavirus Pandemic
South Korean PC Gaming Rooms Rely on Crypto Mining to Profit During the Coronavirus Pandemic The coronavirus pandemic has significantly hit several entertainment
FBI Issues Alert Concerning Malicious State-Sponsored North Korean Hackers Targeting Crypto Firms
FBI Issues Alert Concerning Malicious State-Sponsored North Korean Hackers Targeting Crypto Firms On April 18, the Federal Bureau of Investigation (FBI), the U.S. Treasury Departme
4 tips that’ll keep your crypto safe from hackers this bull market
Jesse Coghlan1 hour ago4 tips that’ll keep your crypto safe from hackers this bull marketFrom choosing a secure exchange to setting up DeFi protocols security, security sages have shared their top tips so you can keep
Shiba Inu Falls Below $0.00002631 As Bears Dominate The Market, Time To Buy?
Este artículo también está disponible en español. Shiba Inu (SHIB) has seen intense bearish pressure as its price slips below the critical $0.00002631 level. This downwar
Checkout.com Reveals Merchants Can Accept and Make Payments in USDC
Checkout.com Reveals Merchants Can Accept and Make Payments in USDC On Tuesday, the financial technology company Checkout.com announced that it will allow merchant settlements usin
Swiss Government Rejects $103 Million Bailout for Crypto Companies Battered by Coronavirus
Swiss Government Rejects $103 Million Bailout for Crypto Companies Battered by CoronavirusSwitzerland’s government has rejected a 100 million franc ($103 million) bailout for
Solana memecoin hits a whopping $328T market cap — for all the wrong reasons
Brayden Lindrea3 hours agoSolana memecoin hits a whopping $328T market cap — for all the wrong reasonsCrypto users have continued to send funds to the apparent honeypot scam, even with many warnings they won’t be abl
XRP Price Range-Bound: Can It Break Out or Stay Stuck?
Este artículo también está disponible en español. XRP price is moving higher from the $0.5250 support. The price could gain bullish momentum if it clears the $0.5450 and
CrowdStrike stock falls another 13% on Monday, days after global IT outage
Martin Young4 hours agoCrowdStrike stock falls another 13% on Monday, days after global IT outage“We are likely to experience similar incidents,” said Binance CSO Jimmy Su in the wake of the global computer outage.11