Fun

Hacker mints 1B tokens in $16M Curio smart contract exploit

News Feed - 2024-03-26 08:03:19

Ezra Reguerra12 hours agoHacker mints 1B tokens in $16M Curio smart contract exploitCurio said it will conduct a fund compensation program for affected liquidity providers, which could potentially take up to one year to complete.1055 Total views13 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksReal-world asset (RWA) liquidity firm Curio suffered a smart contract exploit involving a critical vulnerability related to voting power privileges, allowing the attacker to steal $16 million in digital assets.


Curio alerted its community of the exploit and highlighted that they are addressing the situation. The company said that a MakerDAO-based smart contract used within Curio was breached.


However, the company assured its users that the exploit only affected the Ethereum side and that all Polkadot and the Curio Chain contracts remained secure.


Web3 security firm Cyvers estimated that the losses from the exploit are about $16 million. The security firm said the exploit involved a “permission access logic vulnerability.”Source: Cyvers Alerts


On March 25, Curio published a post-mortem of the exploit and a compensation plan for affected users. Within the report, Curio highlighted that the problem was a flaw in the voting power privilege access control.


With this, the attacker acquired a small number of Curio Governance (CGT) tokens, allowing them to gain access and elevate their voting power in the project’s smart contract.


With the elevated voting power, the attacker performed a series of steps that ultimately allowed the execution of arbitrary actions within the Curio DAO contract. This led to the unauthorized minting of 1 billion CGT.


In the report, Curio said all the funds affected in the exploit will be returned. The team said it would release a new token called CGT 2.0. With the new token, the team promised to restore 100% of the funds for CGT holders.


Related:Hacker moves $10M from 2023 phishing incident to Tornado Cash


For liquidity providers, Curio said that it will conduct a fund compensation program. The team said it will be paid in four stages, with each stage lasting 90 days. This could mean that full payment could potentially take one year. They wrote:“The compensation program will consist of 4 consecutive stages, each lasting for 90 days. During each stage: compensation will be paid in USDC/USDT, amounting to 25% of the losses incurred by the second token in the liquidity pools.”


The company also said that it would reward white hat hackers who can help in recovering the lost funds. The team said that hackers could receive a reward equivalent to 10% of funds recovered in the initial recovery phase.


Magazine:‘Am I sorry? No’ — 3AC founder. $6B BTC laundered for fast food worker: Asia Express# Blockchain# Security# Hackers# Cybersecurity# HacksAdd reactionAdd reactionRead moreCrypto game ‘Munchables’ on Blast exploited for $63MMastercard sees partnerships as key to blockchain remittances in Latam‘Ripple is well-positioned to pay a significant civil penalty,‘ says SEC

News Feed

Joe Biden drops out of United States presidential race
Ciaran Lyons5 hours agoJoe Biden drops out of United States presidential raceUnited States President Joe Biden has announced he will bow out of the 2024 presidential election.8550 Total views8 Total sharesListen to artic
E-Commerce Giant Ebay Now Allows NFT Sales Citing ‘Massive Wave of Attention’
E-Commerce Giant Ebay Now Allows NFT Sales Citing ‘Massive Wave of Attention’ Ebay, which has 187 million buyers on its platform, is now allowing the sale of
Brazilian Brokerage Platform Rico to Offer Cryptocurrency Services Next Year
Brazilian Brokerage Platform Rico to Offer Cryptocurrency Services Next Year Rico, a Brazilian brokerage platform part of XP Inc., has announced it plans to enter the cryptocurrenc
Marcel Pechman8 hours agoBitcoin at $25K: Discount or disaster?This week, The Market Report discusses Bitcoin’s recent dip below $25,000 and what it means for the near future. Was it a discount or a disaster?2986 Total
NYC Mayor Undeterred by Falling Bitcoin Price, Says Buying the Dip Could Yield ‘Good Profit’
NYC Mayor Undeterred by Falling Bitcoin Price, Says Buying the Dip Could Yield "Good Profit" The mayor of New York City, Eric Adams, is not deterred by bitcoin’s volatility,
Elisha Owusu Akyaw11 hours agoHashing It Out podcast: What does the future hold for BNB Chain?Arno Bauer, the senior solution architect at BNB Chain, denies the “Ethereum killer” tag in a discussion highlighting new
Quik․com Offers Registry of ․metaverse ․web3 and 8 Other NFT Domain TLDs
Quik․com Offers Registry of ․metaverse ․web3 and 8 Other NFT Domain TLDs sponsored Did you know?Due to the decentralized nature of NFT domains, users can host decentralized we
DOJ Tells FBI and Others: ‘Stop Signing Appreciation Notes for Binance’
DOJ Tells FBI and Others: "Stop Signing Appreciation Notes for Binance" The U.S. Department of Justice (DOJ) has requested federal agencies stop signing apprecia
Shiba Inu Price Rebounds Toward $0.00003, Taking 69% Of All Holders Back Into The Green
Este artículo también está disponible en español. The Shiba Inu price has rebounded towards $0.00003, which has put most of the SHIB holdersback in the green. This is sig
William Suberg12 hours agoBitcoin shorts keep burning as BTC price seeks to hold $27KBitcoin stubbornly refuses to give up its latest gains as BTC price seeks to flip $27,000 to support into September’s last Wall Stree
Top 100 Apecoin Holders Control Over 51% of the Supply, APE Lost 81% in 2 Months
Top 100 Apecoin Holders Control Over 51% of the Supply, APE Lost 81% in 2 Months Back in mid-March 2022, Bored Ape Yacht Club’s (BAYC) Apecoin DAO launched and airdropped mi
France’s Le Maire Attacks Facebook’s ‘Political’ Ambitions With Libra
France’s economic and finance minister says Libra is “unacceptable,” calling it an intrusion into the state’s political sovereignty. Writing in a Financi