Fun

Report: Blockchain Price Oracle Manipulation Produces Millions in Losses, Shows No Signs of Slowing

News Feed - 2020-11-12 12:11:24

Report: Blockchain Price Oracle Manipulation Produces Millions in Losses, Shows No Signs of Slowing


On November 9, a writer from the website samczsun.com published a report that shows a number of issues with price oracle manipulation stemming from a few blockchain applications. The researcher notes that price oracle manipulation has resulted in “over $30 [million] in losses so far.”


According to the researcher from samczsun.com there’s been a substantial amount of price oracle manipulation in 2020. On Monday, he tweeted: “Price oracle manipulation has resulted in over 30MM of losses so far and it shows no signs of slowing.” The tweet was also retweeted by the ethereum.org Twitter handle’s 500k followers. The tweet from @samczsun also leads to a blog post written on the researcher’s web portal called: “So you want to use a price oracle.”


In the article, he explains that during the end of 2019 he published a post called “Taking undercollateralized loans for fun and for profit” and the post explained how he could attack ETH-based decentralized applications (dapps). The dapps he wrote about specifically rely on price oracle data for a number of crypto assets.


“It’s currently late 2020 and unfortunately numerous projects have since made very similar mistakes,” samczsun.com’s post stresses. “With the most recent example being the Harvest Finance hack which resulted in a collective loss of 33MM USD for protocol users.”


Basically an oracle is a protocol that can record both onchain and off-chain data and submits the data into a blockchain like Ethereum. These oracles are used in smart contracts, automated market makers (AMM), trading platforms, and one of the popular ETH-based oracles is Chainlink. The report on vulnerabilities says that developers are aware of some of the issues tethered to oracles but “price oracle manipulation is clearly not something that is often considered.”


The blog post adds: Conversely, exploits based on reentrancy have fallen over the years while exploits based on price oracle manipulation are now on the rise.


The blog post however isn’t just criticisms and samczsun.com’s editorial features an introduction to oracles, oracle manipulation, and how to mitigate against exploitation. Further, the post discusses six vulnerabilities that have taken place in the past.


For example, the post mentions undercollateralized loans, the Synthetix sKRW oracle malfunction, the yVault bug, Synthetix MKR manipulation, the Harvest Finance hack, and the Bzx hack as well. An illustration of the Synthetix MKR manipulation. Photo via Samczsun.com.


Samczsun.com’s research also summarizes the Harvest Finance issues that took place on October 26, 2020.


“The attacker deflated the price of USDC in the Curve pool by performing a trade, entered the Harvest pool at the reduced price,” the findings state. “[The attacker] restored the price by reversing the earlier trade, and exited the Harvest pool at a higher price. This resulted in over 33MM USD of losses.”


The report concludes that “price oracles are a critical, but often overlooked, component of defi security.” The article highlights that there are plenty of ways that dapps can shoot themselves in the foot if they overlook some of these problems. “Reading price information during the middle of a transaction may be unsafe and could result in catastrophic financial damage,” the research post says.


What do you think about the millions lost from blockchain-based price oracles so far? Let us know what you think in the comments section below. Ethereum User Spends $9,500 in Fees Sending Just $120 in an Error to Forget ALTCOINS | 4 days ago ETH 2.0 Scheduled for December, Vitalik Deposits $1.4M Worth of Ether Into Phase 0 Contract ALTCOINS | 5 days ago Tags in this story $30 Million, Altcoins, crypto assets, Cryptocurrency, DeFi, Defi Apps, ETH-based apps, Ethereum, Hack, Harvest Finance hack, Losses, manipulation, MKR, price oracle, price oracle manipulation, Prices, samczsun.com, Synthetix sKRW oracle malfunction, yVault bug


Image Credits: Shutterstock, Pixabay, Wiki Commons, samczsun.com, Use Bitcoin and Bitcoin Cash to play online casino games here. Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Travala Scores 33% Revenue Growth With 60% of Bookings Paid With Crypto
Travala Scores 33% Revenue Growth With 60% of Bookings Paid With Crypto Travala, the online platform that allows crypto users to book hotel rooms in thousands of destinations aro
ETH Price Strains Defi Collateral Loans as ‘Black Swan’ Event Strikes Makerdao
ETH Price Strains Defi Collateral Loans as "Black Swan" Event Strikes Makerdao The price of ethereum dropping double digits on March 12 sent shockwaves through the decentralized
Indonesian Government Sets Crypto Tax at 0.1% to Be Levied Starting in May
Indonesian Government Sets Crypto Tax at 0.1% to Be Levied Starting in May The Indonesian government has decided to tax capital gains income from crypto investmentsat 0.1% starting
William Suberg20 hours agoBitcoin UTXOs echoing March 2020 ‘black swan’ crash — New researchBTC price performance may be weathering a storm not seen since COVID-19 sparked a 60% drawdown three-and-a-half years ago.
Biggest Movers: XRP Rebounds on Tuesday, as AVAX Hits 1-Week High
Biggest Movers: XRP Rebounds on Tuesday, as AVAX Hits 1-Week High Xrp rose for a second consecutive session on Wednesday, as the token continued to move away from a recent price fl
Andreessen Horowitz Launches A16z Crypto Research Lab
Andreessen Horowitz Launches A16z Crypto Research Lab A16z, also known as Andreessen Horowitz, the venture capital (VC) company that has invested millions in crypto-related project
Circle to Issue Weekly USDC Reserve Reports — Tether Publishes May 2022 Assurance Report
Circle to Issue Weekly USDC Reserve Reports — Tether Publishes May 2022 Assurance Report The co-founder and CEO of Circle, Jeremy Allaire, has announced the cryptocurrency firm t
Toncoin (TON) gains 10% after Binance Launchpool platform addition
Nancy Lubale1 hour agoToncoin (TON) gains 10% after Binance Launchpool platform additionGrowth in its DeFi ecosystem and the upcoming Binance Launchpool addition have put wind in Toncoin’s sails.145 Total views1 Total
Turkish crypto bill: 5 things to know before it’s introduced
Helen Partz11 hours agoTurkish crypto bill: 5 things to know before it’s introducedTurkey was expected to introduce crypto legislation in early 2024, but the local parliament is yet to report on the process.1463 Total
Dollar to Play Lesser Role Due to Its Weaponization, Digital Currencies, Economist Jeffrey Sachs Says
Dollar to Play Lesser Role Due to Its Weaponization, Digital Currencies, Economist Jeffrey Sachs Says Within the next decade, the U.S. dollar will play a much less dominant role th
Brandt Says DOGE Bear Market Is Over, Kiyosaki Advises Buying BTC ‘Before Fed Pivot,’ Bitcoin.com Backed Ramírez Challenges for WBA Boxing World Title — Week in Review
Brandt Says DOGE Bear Market Is Over, Kiyosaki Advises Buying BTC "Before Fed Pivot," Bitcoin.com Backed Ramírez Challenges for WBA Boxing World Title — Week in Review In this w
Poland’s Central Bank Says It Will Add 100 Tons of Gold to Existing Holdings in 2022
Poland"s Central Bank Says It Will Add 100 Tons of Gold to Existing Holdings in 2022 The Polish central bank, the National Bank of Poland (NBP), is reportedly planning to raise its