Fun

Hacker mints 1B tokens in $16M Curio smart contract exploit

News Feed - 2024-03-26 08:03:19

Ezra Reguerra12 hours agoHacker mints 1B tokens in $16M Curio smart contract exploitCurio said it will conduct a fund compensation program for affected liquidity providers, which could potentially take up to one year to complete.1055 Total views13 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksReal-world asset (RWA) liquidity firm Curio suffered a smart contract exploit involving a critical vulnerability related to voting power privileges, allowing the attacker to steal $16 million in digital assets.


Curio alerted its community of the exploit and highlighted that they are addressing the situation. The company said that a MakerDAO-based smart contract used within Curio was breached.


However, the company assured its users that the exploit only affected the Ethereum side and that all Polkadot and the Curio Chain contracts remained secure.


Web3 security firm Cyvers estimated that the losses from the exploit are about $16 million. The security firm said the exploit involved a “permission access logic vulnerability.”Source: Cyvers Alerts


On March 25, Curio published a post-mortem of the exploit and a compensation plan for affected users. Within the report, Curio highlighted that the problem was a flaw in the voting power privilege access control.


With this, the attacker acquired a small number of Curio Governance (CGT) tokens, allowing them to gain access and elevate their voting power in the project’s smart contract.


With the elevated voting power, the attacker performed a series of steps that ultimately allowed the execution of arbitrary actions within the Curio DAO contract. This led to the unauthorized minting of 1 billion CGT.


In the report, Curio said all the funds affected in the exploit will be returned. The team said it would release a new token called CGT 2.0. With the new token, the team promised to restore 100% of the funds for CGT holders.


Related:Hacker moves $10M from 2023 phishing incident to Tornado Cash


For liquidity providers, Curio said that it will conduct a fund compensation program. The team said it will be paid in four stages, with each stage lasting 90 days. This could mean that full payment could potentially take one year. They wrote:“The compensation program will consist of 4 consecutive stages, each lasting for 90 days. During each stage: compensation will be paid in USDC/USDT, amounting to 25% of the losses incurred by the second token in the liquidity pools.”


The company also said that it would reward white hat hackers who can help in recovering the lost funds. The team said that hackers could receive a reward equivalent to 10% of funds recovered in the initial recovery phase.


Magazine:‘Am I sorry? No’ — 3AC founder. $6B BTC laundered for fast food worker: Asia Express# Blockchain# Security# Hackers# Cybersecurity# HacksAdd reactionAdd reactionRead moreCrypto game ‘Munchables’ on Blast exploited for $63MMastercard sees partnerships as key to blockchain remittances in Latam‘Ripple is well-positioned to pay a significant civil penalty,‘ says SEC

News Feed

Robert Kiyosaki: I’m Still Bullish on Bitcoin — Crypto Cannot Be Blamed for FTX Collapse
Robert Kiyosaki: I"m Still Bullish on Bitcoin — Crypto Cannot Be Blamed for FTX Collapse The famous author of the best-selling book Rich Dad Poor Dad, Robert Kiyosaki, is still b
Ana Paula Pereira2 hours agoFederal Reserve of San Francisco hiring crypto architect for CBDC projectSan Francisco"s Federal Reserve Bank is seeking a crypto architect for a central bank digital currency (CBDC).890 Total
Digital Real Pilot to Run on Ethereum-Compatible, Permissioned Blockchain
Digital Real Pilot to Run on Ethereum-Compatible, Permissioned Blockchain According to the Central Bank of Brazil, the digital real pilot project will use an Ethereum-compatible, p
China’s Research Institute Updates Crypto Ranking — Review Affected by Pandemic
China"s Research Institute Updates Crypto Ranking — Review Affected by PandemicChina’s Center for Information and Industry Development has published its latest crypto projec
Former US solicitor general claims regulators want to ‘debank’ crypto
Turner Wright2 hours agoFormer US solicitor general claims regulators want to ‘debank’ cryptoSeveral parties have filed amicus briefs with the appellate court in support of Custodia Bank receiving approval for a mast
Dogecoin Price Prediction: Here’s What The 91-Day Pattern Says Could Happen Next
Este artículo también está disponible en español. Crypto analyst Master Kenobihas again alluded to the 91-day pattern to provide insights into where the Dogecoin price co
Gareth Jenkinson11 hours agoCoinEx to resume service with new wallet system following $70M hackCoinEx has rebuilt its wallet system following a $70 million hack and is set to resume deposits and withdrawals for select cr
Police in Kazakhstan Arrest Gang Forcing IT Specialists to Run Crypto Farms
Police in Kazakhstan Arrest Gang Forcing IT Specialists to Run Crypto Farms Law enforcement in Kazakhstan detained members of a crime group suspected of forcing IT experts into ope
Binance Enters Popular Venezuelan Dollar Indexes as Currency Plunges 10% in One Week
Binance Enters Popular Venezuelan Dollar Indexes as Currency Plunges 10% in One Week Binance, the leading P2P exchange in Venezuela, is now present in several po
Bitcoin drops below $60K as analyst says zero spot Bitcoin ETF inflows ‘very normal’
Nancy Lubale7 hours agoBitcoin drops below $60K as analyst says zero spot Bitcoin ETF inflows ‘very normal’Bitcoin price losses crucial support at $60,000 as inflows to the spot Bitcoin ETFs stagnate.6607 Total views
Investment Strategist Discusses Bitcoin ‘Entering Unstoppable Maturation Stage’ — Says Price Should Continue to Rise
Investment Strategist Discusses Bitcoin "Entering Unstoppable Maturation Stage" — Says Price Should Continue to Rise Bloomberg Intelligence’s senior commodity strategist sa
Robinhood Q1 crypto trading surges 224% — SEC action ‘disappointing’
Brayden Lindrea8 hours agoRobinhood Q1 crypto trading surges 224% — SEC action ‘disappointing’Robinhood’s crypto services contributed to nearly 40% of the firm’s transaction-based revenue and helped the firm pr