Fun

Defi Protocol That Bragged About Having Flash Loan Attack Prevention Hacked for $6 Million

News Feed - 2020-11-17 07:11:49

Defi Protocol That Bragged About Having Flash Loan Attack Prevention Hacked for $6 Million


A decentralized finance (defi) protocol that bragged about having flash loan attack prevention has been exploited for $6 million in DAI, in a flash loan attack.


Value Defi, a yield aggregating protocol, boasted of having the “highest security” in a Nov. 13 tweet that now appears to have been deleted. The protocol claimed that its technology was capable of preventing flash loan attacks.


Hardly a day later, hackers plundered Value Defi’s multi-stablecoin vault of a total of $8 million of the stablecoin DAI. The attacker returned $2 million to the protocol and pocketed $6 million — and with it left one audacious message stating, “do you really know flashloan?”


Value Defi said it suffered a “complex attack that resulted in a net loss of $6 million.”


The hacker took out a loan of 80,000 ether from the defi lending platform Aave and also borrowed an additional $116 million in DAI from Uniswap. According to Value Defi’s postmortem of the incident, the attacker swapped the ETH loan for stablecoins and deposited part of the flash-loaned DAI into the protocol’s vault.


He then made a series of stablecoin swaps involving USDT, USDC, and DAI — a technique that eventually exploits Value Defi’s vault withdrawal method. Aave developer Emiliano Bonassi exclaimed: This is the complex exploit I’ve ever seen. It used two flashloans.


Flash loans allow users to borrow money without collateral because the lender expects the funds to be returned within one transaction block, almost immediately. Hackers have used this loophole in defi to steal millions of dollars.




In its postmortem, Value Defi said it was looking at ways to compensate affected users. It stated that users can claim 20% in DAI from the $2 million that was returned by the hackers. The protocol is also hiking transaction fees to generate income for compensation.


“We will create a compensation fund which will be funded by a combination of the dev fund, insurance fund and a portion of the fees that are currently generated by the protocol,” it explained.


The price of Value Defi’s native token, value liquidity, plunged as much as 28% on the day of the attack to $1.99 from $2.76, according to Coingecko data. At press time, the token was trading at $2.05, down 4.9% in 24 hours.


This latest exploit comes just two daysafter another $2 million heist at defi lending protocol Akropolis.


What do you think about the frequency of flash loan attacks in the defi industry? Let us know in the comments section below. Sharktron Defi Project Devs Exit Scam: Tron Foundation Says Part of Missing Funds Now Frozen SECURITY | Nov 10, 2020 OFAC Warns Americans Against Facilitating Ransomware Payments SECURITY | Oct 5, 2020 Tags in this story Akropolis, Decentralized finance (Defi), Defi protocol hacked, Emiliano Bonassi, Flash loan, Value Defi


Image Credits: Shutterstock, Pixabay, Wiki Commons Use Bitcoin and Bitcoin Cash to play online casino games here. Show comments

News Feed

South Africa Retailer Pick n Pay Now Accepts Payment in Bitcoin at 39 Outlets
South Africa Retailer Pick n Pay Now Accepts Payment in Bitcoin at 39 Outlets Pick n Pay, the South African retailer, has revealed that some of its grocery stores are now accepting
Bitcoin miner Hut 8 lands $150M investment amid AI boom
Savannah Fortis10 hours agoBitcoin miner Hut 8 lands $150M investment amid AI boomCoatue Management invested $150 million in the Bitcoin miner Hut 8 Corp due to its capability to power generative AI applications with its
Goldman Sachs’ Blankfein Admits His View on Cryptocurrency Is Evolving — Says Crypto ‘Is Happening’
Goldman Sachs" Blankfein Admits His View on Cryptocurrency Is Evolving — Says Crypto "Is Happening" Lloyd Blankfein, a former Goldman Sachs CEO who is now the firm’s senio
Brayden Lindrea7 hours agoBitcoin miners Marathon, Riot, CleanSpark increase BTC output in SeptemberMarathon Digital, in particular, produced 1,242 BTC in September, which accounted for a record 4.3% share of Bitcoin min
CorionX and Syscoin Join Hands to Drive Stablecoin Adoption, CorionX IEO Enters Third Round
CorionX and Syscoin Join Hands to Drive Stablecoin Adoption, CorionX IEO Enters Third Round9th October 2020, Zug, Switzerland – The non-profit Corion Foundation is pleased to
Joe Biden: US Bringing 30 Countries Together to Stop ‘Illicit Use of Cryptocurrency’
Joe Biden: US Bringing 30 Countries Together to Stop "Illicit Use of Cryptocurrency" President Joe Biden says that the U.S. will bring together 30 countries to stop “the ill
Chinese Central Bank Governor: User Privacy and Financial Security Key Principles Guiding CBDC Design Process
Chinese Central Bank Governor: User Privacy and Financial Security Key Principles Guiding CBDC Design Process According to Yi Gang, governor of China’s central bank, the proc
Ethereum, Tron and EOS Control 98% of All Dapp Volume
Ethereum, Tron and EOS Control 98% of All Dapp Volume 2019 was a good year for dapps and a particularly good one for Tron and Ethereum. That’s the upshot of Dapp Review&rsq
Colombia’s Financial Superintendent Approves Nine Crypto Platforms to Work With National Banks
Colombia"s Financial Superintendent Approves Nine Crypto Platforms to Work With National Banks In Colombia, the entity managed by the Ministry of Finance and Pub
Dogecoin Price Breaks Out Of Bearish Trendline And Enters Ascending Channel Headed For $0.3
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Bitget Introduces MegaSwap for a Re-Invented DeFi Experience
Bitget Introduces MegaSwap for a Re-Invented DeFi Experience press release PRESS RELEASE. Seychelles, December 26, 2022 – Leading global cryptocurrency exchange, Bitget launc
Ethereum L2 Eclipse CEO steps back amid sexual misconduct claims
Jesse Coghlan4 hours agoEthereum L2 Eclipse CEO steps back amid sexual misconduct claimsEclipse founder and CEO Neel Somani said he would “work to clear my name and defend myself” and will move away from a public-fac