Fun

Report: Blockchain Price Oracle Manipulation Produces Millions in Losses, Shows No Signs of Slowing

News Feed - 2020-11-12 12:11:24

Report: Blockchain Price Oracle Manipulation Produces Millions in Losses, Shows No Signs of Slowing


On November 9, a writer from the website samczsun.com published a report that shows a number of issues with price oracle manipulation stemming from a few blockchain applications. The researcher notes that price oracle manipulation has resulted in “over $30 [million] in losses so far.”


According to the researcher from samczsun.com there’s been a substantial amount of price oracle manipulation in 2020. On Monday, he tweeted: “Price oracle manipulation has resulted in over 30MM of losses so far and it shows no signs of slowing.” The tweet was also retweeted by the ethereum.org Twitter handle’s 500k followers. The tweet from @samczsun also leads to a blog post written on the researcher’s web portal called: “So you want to use a price oracle.”


In the article, he explains that during the end of 2019 he published a post called “Taking undercollateralized loans for fun and for profit” and the post explained how he could attack ETH-based decentralized applications (dapps). The dapps he wrote about specifically rely on price oracle data for a number of crypto assets.


“It’s currently late 2020 and unfortunately numerous projects have since made very similar mistakes,” samczsun.com’s post stresses. “With the most recent example being the Harvest Finance hack which resulted in a collective loss of 33MM USD for protocol users.”


Basically an oracle is a protocol that can record both onchain and off-chain data and submits the data into a blockchain like Ethereum. These oracles are used in smart contracts, automated market makers (AMM), trading platforms, and one of the popular ETH-based oracles is Chainlink. The report on vulnerabilities says that developers are aware of some of the issues tethered to oracles but “price oracle manipulation is clearly not something that is often considered.”


The blog post adds: Conversely, exploits based on reentrancy have fallen over the years while exploits based on price oracle manipulation are now on the rise.


The blog post however isn’t just criticisms and samczsun.com’s editorial features an introduction to oracles, oracle manipulation, and how to mitigate against exploitation. Further, the post discusses six vulnerabilities that have taken place in the past.


For example, the post mentions undercollateralized loans, the Synthetix sKRW oracle malfunction, the yVault bug, Synthetix MKR manipulation, the Harvest Finance hack, and the Bzx hack as well. An illustration of the Synthetix MKR manipulation. Photo via Samczsun.com.


Samczsun.com’s research also summarizes the Harvest Finance issues that took place on October 26, 2020.


“The attacker deflated the price of USDC in the Curve pool by performing a trade, entered the Harvest pool at the reduced price,” the findings state. “[The attacker] restored the price by reversing the earlier trade, and exited the Harvest pool at a higher price. This resulted in over 33MM USD of losses.”


The report concludes that “price oracles are a critical, but often overlooked, component of defi security.” The article highlights that there are plenty of ways that dapps can shoot themselves in the foot if they overlook some of these problems. “Reading price information during the middle of a transaction may be unsafe and could result in catastrophic financial damage,” the research post says.


What do you think about the millions lost from blockchain-based price oracles so far? Let us know what you think in the comments section below. Ethereum User Spends $9,500 in Fees Sending Just $120 in an Error to Forget ALTCOINS | 4 days ago ETH 2.0 Scheduled for December, Vitalik Deposits $1.4M Worth of Ether Into Phase 0 Contract ALTCOINS | 5 days ago Tags in this story $30 Million, Altcoins, crypto assets, Cryptocurrency, DeFi, Defi Apps, ETH-based apps, Ethereum, Hack, Harvest Finance hack, Losses, manipulation, MKR, price oracle, price oracle manipulation, Prices, samczsun.com, Synthetix sKRW oracle malfunction, yVault bug


Image Credits: Shutterstock, Pixabay, Wiki Commons, samczsun.com, Use Bitcoin and Bitcoin Cash to play online casino games here. Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Bitcoin Demand Holds Strong Despite Price Drop: Accumulation Trend Remains Intact
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
‘Metaverse’ Term Creator Neal Stephenson Not Bullish About Massive Adoption of Virtual Worlds
"Metaverse" Term Creator Neal Stephenson Not Bullish About Massive Adoption of Virtual Worlds Neal Stephenson, ostensibly the first to coin the term “metaverse,” issued
DueDEX is Paving the Way, Launching Fee-Free LINK/USDT Futures Trading
DueDEX is Paving the Way, Launching Fee-Free LINK/USDT Futures Trading1th October 2020, Belize City, Belize:With new exchanges cropping up, trading becoming ever-more popular, and t
Atari Announces IEO Collaboration and Listing of the Atari Token with Bitcoin.com Exchange
Atari Announces IEO Collaboration and Listing of the Atari Token with Bitcoin.com ExchangeAtari announces IEO collaboration on Bitcoin.com Exchange via its multi-asset trading platform.Public sale slated for November, de
Dogecoin Price Marks Local Bottom, Can Price Run 100% From Here Again?
Este artículo también está disponible en español. Crypto analyst Trader Tardigradehas revealed that the Dogecoin price has marked a local bottom. He further provided insi
Brazilian Crypto Investment Platform Bluebenx Stops Withdrawals Under Hack Allegations
Brazilian Crypto Investment Platform Bluebenx Stops Withdrawals Under Hack Allegations Bluebenx, a Brazil-based cryptocurrency investment platform, suspended withdrawals last week
2 Days After the Bitcoin Halving: Network ‘Remains Strong,’ Higher Fees, Bullish Sentiment
2 Days After the Bitcoin Halving: Network "Remains Strong," Higher Fees, Bullish SentimentOn May 11, 2020, the Bitcoin network completed it’s third block reward halving and th
WhatsApp and Signal survive EU chat control bill — For now
Robert D. Knight10 hours agoWhatsApp and Signal survive EU chat control bill — For nowEU legislators have dropped plans to scan messaging apps, but privacy advocates can’t celebrate just yet.1518 Total views8 Total s
Web3 ad service Everyworld reaches 225K users within a month of launching beta
Tristan Greene4 hours agoWeb3 ad service Everyworld reaches 225K users within a month of launching betaThe service is currently available in beta for select markets.7864 Total views14 Total sharesListen to article 0:00Ne
Bitcoin’s Hashrate Hits Record High 130 EH/s, as BTC Price Faces Resistance at $12,000
Bitcoin"s Hashrate Hits Record High 130 EH/s, as BTC Price Faces Resistance at $12,000Bitcoin’s seven-day average hashrate has reached a new all-time high of 130 exahash per s
Biggest Movers: LTC Hits 9-Day High, While MATIC Snaps Recent Losses
Biggest Movers: LTC Hits 9-Day High, While MATIC Snaps Recent Losses Litecoin surged to a nine-day high to start the month, breaking out of a recent resistance point in the process
Bitcoin Bull Run Isn’t Over: Cathie Wood Predicts $1.5 Million
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu