Fun

Onyx protocol exploited a second time for $3.8M via known bug

News Feed - 2024-09-27 11:09:45

Christopher Roark10 hours agoOnyx protocol exploited a second time for $3.8M via known bugThe decentralized finance app lost nearly $4 million thanks to an interaction between an old bug and a new input validation vulnerability.746 Total views12 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onDecentralized finance (DeFi) protocol Onyx was exploited for $3.8 million on Sept. 26, according to a report from blockchain security platform PeckShield. The exploit used a known bug in the Compound Finance v2 codebase — one that had already been used to exploit Onyx previously on Nov. 1. A vulnerability in the non-fungible token (NFT) liquidation contract also contributed to the exploit, the report stated.


In a Sept. 27 X post, the Onyx team claimed that the faulty NFT contract was the root cause of the exploit.


According to the PeckShield report, 4.1 million virtual USD (VUSD), 7.35 million Onyxcoin (XCN), 0.23 Wrapped Bitcoin (WBTC), $5,000 worth of the Dai (DAI) stablecoin and $50,000 worth of the USDt (USDT) stablecoin were drained from the protocol, for a total of over $3.8 million in losses.Source:PeckShield


The known vulnerability exists in version 2 of Compound Finance, which is a codebase often forked and used by decentralized finance protocols. It led to an exploit against Hundred Finance in April 2023. In

October 2023, the vulnerability was used against Onyx for the first time.


Related:Onyx Protocol suffers $2.1M Hundred Finance copycat attack


The flaw can only be exploited when an “empty market,” or a market with no liquidity, exists, which generally only happens when a new market is launched.


The Onyx team acknowledged the exploit in an X post. “Onyx Protocol was subject to a security incident where a nefarious actor exploited the protocol to drain VUSD from the protocol,” it stated. However, it claimed that the known flaw was not its primary cause. “The primary issue wasn’t an empty market but the NFTLiquidation Contract,” it stated in a thread.


Peck Shield agreed that the NFT contract was “[a]nother issue that facilitates the hack.” The faulty contract allowed the attacker to “inflate the self-liquidation reward amount” because it didn’t “properly validate (untrusted) user input.”Onyx NFT contract vulnerability. Source: PeckShield


DeFi exploits are a common source of losses for Web3 users. On Sept. 27, liquid staking protocol Bedrock lost over $2 million due to a vulnerability in its uniBTC contract. On Sept. 23, Bankroll Network was drained of $230,000 when an attacker made multiple self-transfers, exploiting a faulty “buyFor” function to inflate their profits.# Ethereum# Hackers# Cybersecurity# DeFiAdd reaction

News Feed

‘Black Thursday’ Liquidations Sparks $28M Lawsuit Against Maker Foundation
"Black Thursday" Liquidations Sparks $28M Lawsuit Against Maker FoundationThe Maker Foundation is being sued in a class-action lawsuit for $28 million over the March 12 event that c
US Lawmakers Probe SEC, Treasury, Federal Reserve Over Revolving Door With Crypto Industry
US Lawmakers Probe SEC, Treasury, Federal Reserve Over Revolving Door With Crypto Industry U.S. lawmakers have raised concerns about the revolving door between financial regulators
Gareth Jenkinson1 minute agoHut8 relocates 6,400 rigs, sees growth in AI & high performance computingBitcoin mining firm Hut8 continues to relocate miners from idle North Bay site as demand for AI and high power comp
Remitano Makes Cross-Border Money Transfer Much Easier With New “Cash-Out” Feature
Remitano Makes Cross-Border Money Transfer Much Easier With New “Cash-Out” Feature PRESS RELEASE. To simplify banking and meet its users’ Remittance ne
Gareth Jenkinson11 hours agoFTX​ releases restructuring plan, hints at rebooted offshore exchangeReams of dockets from FTX have been filed alongside a proposed reorganization plan that could see it resurrected as an of
Morgan Stanley CEO Says Bitcoin Is Not a Fad, Crypto Is Not Going Away
Morgan Stanley CEO Says Bitcoin Is Not a Fad, Crypto Is Not Going Away The chief executive officer of global investment bank Morgan Stanley says that cryptocurrency, including bitc
‘Persistent inflation’ will be key in Bitcoin’s run to $200K — Crypto fund manager
Ivan Zhelev5 hours ago‘Persistent inflation’ will be key in Bitcoin’s run to $200K — Crypto fund manager“Unsustainable budget deficits” and “persistent inflation” have HashKey Capital analysts predicting
SEC custody rule made crypto regulation a ‘political football’ — Rep. Nickel
Brayden Lindrea7 hours agoSEC custody rule made crypto regulation a ‘political football’ — Rep. NickelThe SEC’s proposed crypto custody rule and its “hostility” to the industry isn’t in Joe Biden’s “bes
William Suberg9 hours agoBitcoin ‘overreacting’ as SEC returns ETF filings, BTC price dives 6%Bitcoin ETF applications need refiling, the SEC says, but as BTC price dips to $29,500, markets instantly fear that the fi
Ethereum median gas price hits 5-year low
Jesse Coghlan3 hours agoEthereum median gas price hits 5-year lowThe median price to send an Ethereum transaction hit 1.9 gwei over the weekend, with low-priority transactions priced even lower.1196 Total views1 Total sh
Why is Solana's Dogwifhat (WIF) memecoin crashing?
Yashu Gola7 hours agoWhy is Solana"s Dogwifhat (WIF) memecoin crashing?WIF price risks declining by another 48% due to the formation of a classic bearish reversal setup.1636 Total views29 Total sharesListen to article 0:
Martin Young4 hours agoBen Armstrong charges revealed: Could face fines or prison if convictedCrypto influencer Ben “BitBoy” Armstrong was released on bail around eight hours after being booked by Gwinnett County pol