Fun

‘Sophisticated’ Hacker Plunders $450,000 From Defi Protocol Balancer

News Feed - 2020-06-30 02:06:54

"Sophisticated" Hacker Plunders $450,000 From Defi Protocol Balancer


Decentralized finance (Defi) protocol ​Balancer was on Sunday hacked for more than $450,000 worth of cryptocurrency.


In two separate transactions, an attacker targeted two pools containing Ethereum-based tokens with transfer fees – or so-called deflationary tokens.


Pools with Sta and Stonk tokens were affected by this exploit, Balancer, an automated market marker protocol, said on June 29.


The hacker made off with around 601 ether, 11 wrapped bitcoin (WBTC), 22,600 chainlink (LINK), and 61,000 synthetix (SNX) – altogether totaling more than $451,000.


According to an analysis by Dex aggregator 1inch.exchange, the attacker used a smart contract to automate multiple actions in a single transaction. First, the hacker obtained a flash loan of $23 million worth of ethereum from the crypto-lending platform Dydx.


The money was used to swap Weth to Statera (Sta), a so-called deflationary token, back and forth 24 times until the Sta balance was totally drained. With Sta, at least one percent of the token is programmed to burn with every transaction.


However, the Balancer pool apparently failed to account for this mechanism. So, the Sta balance declined by one percent every time the attacker made their 24 swaps. After this, the hacker exchanged 1 weiSta, or the equivalent of a billionth of a token, to Weth several times.


Due to Sta token transfer fee implementation, the pool never received statera, but still proceeded to release the wrapped ether regardless, said 1inch. The same step was repeated to drain WBTC, SNX, and link token balances from the pool, it added.


Finally, the attacker repaid the $23 million Dydx loan. Later, they converted the Sta tokens to Balancer pool tokens and eventually into ethereum via Uniswap, which was then cashed out.


1inch noted that the attack was carried out by a “sophisticated smart contract engineer” who is deeply knowledgeable about decentralized finance and its protocols.


Balancer claimed that “we were not aware this specific type of attack was possible, [but] we have consistently…warned about the unintended effects ERC20s with transfer fees could have in the protocol.”


To prevent future attacks, the platform said that it will start to add ‘transfer fee tokens to the UI blacklist similarly to what we have done for no bool transfer tokens.”


“We will be adding more documentation around the risks of how these pools work and how broken or maliciously designed tokens can potentially drain assets from a pool,” it added.


A number of Defi platforms have been hacked this year.​ In February, Bzx protocol was attacked twice while Maker lost around $8.3 million in March. Uniswap and Dforce were drained of $300,000 and $25 million, respectively, although this later amount was returned by the hacker in April.


What do you think about the Balancer pool hack? Let us know in the comments section below.Skeptics Concerned Plustoken Scammers Plan to Dump $187M Worth of EthereumALTCOINS | 1 day agoYield Farming Pool Concept May Solidify Ethereum"s Role as BTC"s Main SidechainALTCOINS | 3 days agoTags in this story1inch, Balancer pool hack, decentralized finance, Dforce, ERC20 Tokens, hacked, Maker, uniswap


Image Credits: Shutterstock, Pixabay, Wiki CommonsSpot-markets for Bitcoin, Bitcoin Cash, Ripple, Litecoin and more. Start your trading here.Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.Read disclaimer Show comments

News Feed

Former BAYC creative director Jeff Nicholas joins Meta’s Reality Labs
Tristan Greene5 hours agoFormer BAYC creative director Jeff Nicholas joins Meta’s Reality LabsNicholas joins Meta as an executive mixed reality producer for entertainment experiences.809 Total views1 Total sharesListen
Biggest Movers: WAVES Drops 17% as NEAR, SOL, and AVAX Also Take Double-Digit Hits on Friday
Biggest Movers: WAVES Drops 17% as NEAR, SOL, and AVAX Also Take Double-Digit Hits on Friday WAVES dropped by as much as 17% in today’s session, as crypto markets as a whole
Bitcoin, Ethereum Technical Analysis: ETH Nears $3,000 to Start the Weekend 
Bitcoin, Ethereum Technical Analysis: ETH Nears $3,000 to Start the Weekend  Ethereum rallied on Saturday, as the world’s second-largest cryptocurrency moved closer to the
Onkar Singh13 minutes agoHow to host an event in the metaverseFrom pre-event planning to virtual execution, discover the steps to create an immersive and engaging digital experience that captivates the audience.45 Total
Demand for Crypto Soars: Bitcoin Funds Break Records, Goldman Sachs Wants In
Demand for Crypto Soars: Bitcoin Funds Break Records, Goldman Sachs Wants In Investors are increasingly seeking exposure to bitcoin following the recent months-l
Virtual Assets Unleashes Retail Cash Reload Innovation for Purchasing Cryptocurrency
Virtual Assets Unleashes Retail Cash Reload Innovation for Purchasing CryptocurrencyInstantly add cash to your Crypto Dispensers account with Green Dot @ the Register
Vitalik registers ‘defensive accelerationism’ (d/acc) ENS domain — but what is it?
Martin Young3 hours agoVitalik registers ‘defensive accelerationism’ (d/acc) ENS domain — but what is it?Ethereum co-founder Vitalik Buterin has just paid around $500 to register a new Ethereum Name Service domain
William Suberg9 hours agoBTC price dips 3.5% as ‘overheated’ Bitcoin derivatives spark angstBitcoin eats away at upside that followed the Federal Reserve interest rate announcement, with BTC price action over $1,000
Bitcoin miner profits get squeezed as hash price drops to lowest since October 2023
Ana Paula Pereira6 hours agoBitcoin miner profits get squeezed as hash price drops to lowest since October 2023After enjoying record profits during Bitcoin’s recent halving, miners now face a sharp decline in hash pric
Tristan Greene6 hours agoChatGPT can now speak, listen and see imagesOpenAI collaborated with professional voice actors to train the models to speak.3748 Total views11 Total sharesListen to article 0:00NewsJoin us on soc
South Africa eyes stablecoins and blockchain for digital payments
Arijit Sarkar18 minutes agoSouth Africa eyes stablecoins and blockchain for digital paymentsSouth Africa’s 2024 budget review highlighted the need for structural reforms and a focus on improving public financial manage
Yellen Says US Could Back All Deposits at Smaller Banks if Needed to Prevent Contagion
Yellen Says US Could Back All Deposits at Smaller Banks if Needed to Prevent Contagion U.S. Treasury Secretary Janet Yellen says the federal government could guarantee all deposits