Fun

‘Sophisticated’ Hacker Plunders $450,000 From Defi Protocol Balancer

News Feed - 2020-06-30 02:06:54

"Sophisticated" Hacker Plunders $450,000 From Defi Protocol Balancer


Decentralized finance (Defi) protocol ​Balancer was on Sunday hacked for more than $450,000 worth of cryptocurrency.


In two separate transactions, an attacker targeted two pools containing Ethereum-based tokens with transfer fees – or so-called deflationary tokens.


Pools with Sta and Stonk tokens were affected by this exploit, Balancer, an automated market marker protocol, said on June 29.


The hacker made off with around 601 ether, 11 wrapped bitcoin (WBTC), 22,600 chainlink (LINK), and 61,000 synthetix (SNX) – altogether totaling more than $451,000.


According to an analysis by Dex aggregator 1inch.exchange, the attacker used a smart contract to automate multiple actions in a single transaction. First, the hacker obtained a flash loan of $23 million worth of ethereum from the crypto-lending platform Dydx.


The money was used to swap Weth to Statera (Sta), a so-called deflationary token, back and forth 24 times until the Sta balance was totally drained. With Sta, at least one percent of the token is programmed to burn with every transaction.


However, the Balancer pool apparently failed to account for this mechanism. So, the Sta balance declined by one percent every time the attacker made their 24 swaps. After this, the hacker exchanged 1 weiSta, or the equivalent of a billionth of a token, to Weth several times.


Due to Sta token transfer fee implementation, the pool never received statera, but still proceeded to release the wrapped ether regardless, said 1inch. The same step was repeated to drain WBTC, SNX, and link token balances from the pool, it added.


Finally, the attacker repaid the $23 million Dydx loan. Later, they converted the Sta tokens to Balancer pool tokens and eventually into ethereum via Uniswap, which was then cashed out.


1inch noted that the attack was carried out by a “sophisticated smart contract engineer” who is deeply knowledgeable about decentralized finance and its protocols.


Balancer claimed that “we were not aware this specific type of attack was possible, [but] we have consistently…warned about the unintended effects ERC20s with transfer fees could have in the protocol.”


To prevent future attacks, the platform said that it will start to add ‘transfer fee tokens to the UI blacklist similarly to what we have done for no bool transfer tokens.”


“We will be adding more documentation around the risks of how these pools work and how broken or maliciously designed tokens can potentially drain assets from a pool,” it added.


A number of Defi platforms have been hacked this year.​ In February, Bzx protocol was attacked twice while Maker lost around $8.3 million in March. Uniswap and Dforce were drained of $300,000 and $25 million, respectively, although this later amount was returned by the hacker in April.


What do you think about the Balancer pool hack? Let us know in the comments section below.Skeptics Concerned Plustoken Scammers Plan to Dump $187M Worth of EthereumALTCOINS | 1 day agoYield Farming Pool Concept May Solidify Ethereum"s Role as BTC"s Main SidechainALTCOINS | 3 days agoTags in this story1inch, Balancer pool hack, decentralized finance, Dforce, ERC20 Tokens, hacked, Maker, uniswap


Image Credits: Shutterstock, Pixabay, Wiki CommonsSpot-markets for Bitcoin, Bitcoin Cash, Ripple, Litecoin and more. Start your trading here.Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.Read disclaimer Show comments

News Feed

Bank of America Market Strategist Says ‘Summer Rally Is Over’ as Crypto and Stocks Slide Ahead of Fed Rate Hike This Week
Bank of America Market Strategist Says ‘Summer Rally Is Over’ as Crypto and Stocks Slide Ahead of Fed Rate Hike This Week Digital currency markets, precious metals, and stocks
Vitalik Buterin says OpenAI’s GPT-4 has passed the Turing test
Tristan Greene6 hours agoVitalik Buterin says OpenAI’s GPT-4 has passed the Turing testButerin’s comments reference new research indicating most humans can no longer tell when they’re talking to a machine.3736 Tota
Is the Bitcoin halving the right time to invest in BTC?
Zoltan Vardai4 hours agoIs the Bitcoin halving the right time to invest in BTC?While Bitcoin’s pre-halving rallies are historically profitable for investors, analysts expect the biggest gains to come after the halving,
Coinbase refutes accusation it violated campaign finance laws
Tom Mitchelhill5 hours agoCoinbase refutes accusation it violated campaign finance lawsDescribing the allegations as “misinformation” — Coinbase chief legal officer Paul Grewal said Coinbase was exempt from certain
Spot Ethereum ETF launch delayed by SEC comments
Amaka Nwaokocha12 hours agoSpot Ethereum ETF launch delayed by SEC commentsThe SEC commented on the S-1 forms and requested resubmissions by July 8, potentially delaying the launch of spot Ether ETFs until mid-to-late Ju
Crypto execs on DeFi domain hacks: Don’t interact with crypto for now
Ezra Reguerra46 minutes agoCrypto execs on DeFi domain hacks: Don’t interact with crypto for nowCoinGecko founder Bobby Ong explained that after Google sold its domain business to Squarespace, two-factor authentication
Bitcoin price closes in on all-time high as political and TradFi tone and tenor shift
Marcel Pechman2 hours agoBitcoin price closes in on all-time high as political and TradFi tone and tenor shiftBTC price rallied as an improved regulatory outlook in the US and a series of improvements in the Bitcoin ecos
Roaring Kitty’s gamification of GameStop is a menace to the market
Lucas Kiely1 hour agoRoaring Kitty’s gamification of GameStop is a menace to the marketKeith Gill — also known as "Roaring Kitty" — has become a hero of the people, but he is also a menace to stable marke
Whale Alert: 200 Million Dogecoin Bought—Is A Price Rally On The Horizon?
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
PEPE Whales Increased Their Holdings By $1.4 Billion Yesterday – Details
Este artículo también está disponible en español. PEPE has made headlines again, reaching a new all-time high of $0.000027 just a few hours ago. This milestone comes amid
As Bitcoin Rises, Why is Ethereum Struggling To Catch Up? Analyst Explains
Este artículo también está disponible en español. While Bitcoin has faced strong bullish momentum in recent weeks, achieving new all-time highs consistently for days, Eth
Bitcoin Realized Price Moves Further Away From Market Value – Bearish Signal Or Not?
Este artículo también está disponible en español. Bitcoin declined by 1.83% in the past week pushing its market price to below $97,000. Despite this loss, market sentimen