D3ploy Unpacks Biggest Security Breaches of the Week – BSC NEWS
DeFi experienced six major exploits that resulted in losses of over $33 million USD, from April 7th to 14th, 2023. The incidents highlighted the need for conducting regular security audits to address vulnerabilities in smart contracts.
We're excited to announce our new security series in collaboration with D3ploy, a leading Web3 security team dedicated to enhancing the safety of the industry. Together, we'll provide regular updates on the most significant security threats and vulnerabilities encountered.
The week of April 7th to 14th, 2023, witnessed a series of high-profile exploits in the decentralized finance (DeFi) industry, causing significant financial losses and demonstrates that while DeFi holds immense potential to revolutionize the financial industry, it is still in its infancy and has a long way to go in terms of security and robustness.
By learning from these exploits we as a DeFi communitiy can work together to strengthen the ecosystem and pave the way for a more secure and stable decentralized financial future.
The six major exploits that occurred during this period include:
The total estimated value lost across these exploits is over $33 million USD, with some funds recovered across various incidents. These security breaches underscore the importance of conducting regular security audits to identify and address vulnerabilities in smart contracts, particularly when releasing updates.
Lets explore each individual exploit in a little more depth
South Korean centralized exchange GDAC experienced a severe hot wallet hack on April 9th, 2023, resulting in the loss of 14,324,040 $USD worth of cryptocurrency. The stolen assets included 60.8 $BTC, 350.5 $ETH, 220,000 $USDT, and 10,000,000 $WEMIX. This theft accounted for approximately 23% of GDACs total assets under custody.
The exchanges emergency response team acted quickly to suspend all deposit and withdrawal services and block related servers. GDAC reported the incident to the police and the Korea Internet & Security Agency (KISA) for technical support, as well as notifying the Financial Intelligence Unit (FIU). GDAC urged asset issuers, exchanges, and DeFi managers to freeze assets and collaborated with various organizations to recover the stolen funds.
Yearn Finance, a yield aggregator, and Aave Protocol, a lending and borrowing platform, fell victim to a flash loan attack on April 8th, 2023, resulting in a combined loss of 11,512,509 $USD worth of $ETH and $DAI. The attacker executed the exploit using two malicious smart contracts and took a flash loan for 2,000,000 $USDT, 5,000,000 $USDC, and 5,000,000 $DAI from Balancer. The borrowed assets were used to exploit a vulnerability in Yearn Finances USDT pool, allowing the attacker to mint a significant number of ycUSDT and yUSDT tokens, which were then swapped for various stablecoins.
A smaller attack occurred simultaneously, affecting Aaves LendingPoolCoreV1 contract. The attacker repaid all users USDT positions in the Aave V1 protocol. The stolen assets were transferred to destination wallets, with 1,000 $ETH bridged through TornadoCash.
On the morning of April 10th, 2023, Terraport was exploited, leading to losses of approximately 4 million USD in Terra, LUNC, and USTC tokens. The exploit was made possible due to a mathematical weakness in the algorithm used to calculate LP prices.
The malicious actor added a small amount of liquidity to the protocol and then manipulated the LP share price, allowing them to withdraw a large amount of liquidity. Two pools were affected, the first one drained for 9,148,426 TERRA ($1.8 million) and 15,100,861,997 LUNC ($1.88 million), and the second one for 576,736 TERRA ($115K) and 5,487,381 USTC ($117K). The total losses amounted to about $4 million USD.
SushiSwap, a cross-chain decentralized exchange, experienced an exploit on April 7th, 2023, due to a bug related to approvals of its RouterProcessor2 contract. The vulnerability led to losses of nearly 3,505,000 $USD from the user named sifuvision.eth.
The hack was caused by a smart contract bug on SushiSwaps RouterProcessor2 contract, which allowed attackers to bypass security checks and withdraw affected users approved tokens. The incident affected users who swapped on the platform within four days before detection. After detecting the exploit, Jared Grey, head developer at SushiSwap, urged users to revoke permissions for all contracts on their platform while they worked with security teams to mitigate issues.
An interesting part of the story is that the initial hack of 100 $ETH was performed by a white hat, who tweeted about the vulnerability and returned 90 $ETH back. However, several EOA addresses used the same vulnerability to exploit the same user for a more significant amount of 1,790 $ETH. Jared Grey announced the returning of 300 $ETH with the help of the community and is working on returning 700 $ETH from the Lido Vault.
MetaPoint, a metaverse running on the Binance Smart Chain, was hacked on April 11th, 2023, through a vulnerability found within their deposit function. When a user used the deposit function, it created a new contract and deposited tokens into that contract. The issue arose because this newly created contract had an approve function that gave unrestricted access to $META tokens without any restrictions or limitations.
An attacker took advantage of this by deploying a malicious smart contract with unverified source code and draining mass amounts of funds from users who had deposited $POT tokens onto their platform. The exploiter was able to steal 2,518 $BNB, worth 803,242 $USD at current market rates. All the stolen money was transferred through TornadoCash.
OpenAI ATF, a BEP20 token trading on PancakeSwap, experienced a rug pull on April 14th, 2023, by the deployer who removed liquidity worth 340,061 $USD. The deployer removed LP funds over nine transactions and swapped them for $WBTC. Part of the stolen assets remains in the deployers original address.
The turbulent week of April 7th-14th, 2023, witnessed six major exploits in the DeFi industry, resulting in over $33 million USD lost. Some of these funds have been recovered, thanks to the quick response of project teams and the collaboration of the wider DeFi community. The incidents serve as a stark reminder of the importance of conducting regular security audits to identify and address vulnerabilities in smart contracts, especially when releasing updates.
It is crucial for developers, project owners, and users to remain vigilant and prioritize security measures to ensure the overall safety of the DeFi ecosystem. As the industry continues to grow and evolve, so too will the need for robust security practices, including regular audits, thorough testing, and close collaboration.
D3ploy is an industry leading smart contract auditing service offering support to all public and private blockchains.
D3ploy offers comprehensive auditing services that cater to projects of any budget. With an impressive track record of auditing over 50 projects with zero security breaches to date and securing more than $6.5 billion in crypto assets, D3ploy is the ideal choice for DeFi projects seeking to ensure the security of their smart contracts.
Website |Twitter | Telegram |Linkedin |
View post:
D3ploy Unpacks Biggest Security Breaches of the Week - BSC NEWS
- Ethereum News: Ethereum (ETH)bPrice Targets $3.7K Amid Growing Smart Money Confidence and On-chain Strength - Binance - November 24th, 2024 [November 24th, 2024]
- Pattieswap/PattiePad Announces Last Stage Pre-sale of $PATTIE Token on Binance Smart Chain - GlobeNewswire - November 17th, 2024 [November 17th, 2024]
- A beginners guide to the BNB Chain: The evolution of the Binance Smart Chain - Cointelegraph - November 14th, 2024 [November 14th, 2024]
- BABY PEPE; Meet the Largest Pepe Token on the Binance Smart Chain Network! - Binance - October 12th, 2024 [October 12th, 2024]
- IAMDOG Expands to Binance Smart Chain: Bringing Meme Culture, Transparent Rewards, and an Engaging Gaming Experience to Millions - Benzinga - October 7th, 2024 [October 7th, 2024]
- Binance Smart Chain Expands with AI Deal, Why This is Great for FET and RCOF - Live Bitcoin News - September 6th, 2024 [September 6th, 2024]
- Binance to Temporarily Suspend Deposits and Withdrawals on BNB Smart Chain Soon: Heres Why - CryptoPotato - September 6th, 2024 [September 6th, 2024]
- Binance Integrates DeXe (DEXE) on BNB Smart Chain, Opens Deposits and Withdrawals - Blockchain.News - June 18th, 2024 [June 18th, 2024]
- DeFi Exchange 1Inch Expands to Binance Smart Chain Citing ETH Gas Fees - Yahoo News UK - June 18th, 2024 [June 18th, 2024]
- WUSD Stablecoin Expands Reach with Integration on Binance Smart Chain and Solana - PR Newswire - June 18th, 2024 [June 18th, 2024]
- Memereum Surpasses 21 Million Tokens Sold in Presale, Pioneers Blockchain-Based Insurance on Binance Smart ... - CryptoPotato - June 12th, 2024 [June 12th, 2024]
- Exploring the rise of Binance Coin: factors behind its surging value and future prospects - The National - The National - June 12th, 2024 [June 12th, 2024]
- Binance Coin (BNB) Surges Over 6%, Hits All-Time High Amid Network Growth - NullTX - June 12th, 2024 [June 12th, 2024]
- Tupan Launches the New Binance Smart Chain TCT - GlobeNewswire - March 9th, 2024 [March 9th, 2024]
- ChatGPT picks 3 low-fee 'Ethereum killers' to buy as ETH gas fees ... - Finbold - Finance in Bold - November 19th, 2023 [November 19th, 2023]
- Title: Unveiling Polkastream: The Evolution of Web 3.0 Entertainment - Medium - November 19th, 2023 [November 19th, 2023]
- PEPE and FLOKI Meet a New Rival: Investor Attraction to ... - BeInCrypto - November 17th, 2023 [November 17th, 2023]
- Why So Many Crypto Games Are Switching ChainsOr Calling it Quits - Decrypt - November 14th, 2023 [November 14th, 2023]
- USDV stablecoin backed by tokenized treasuries launches - crypto.news - November 14th, 2023 [November 14th, 2023]
- What Fueled Polygon's (MATIC) 10% Price Increase? - Investing.com India - November 14th, 2023 [November 14th, 2023]
- SEC and Binance Agree on Protective Order in the Ongoing Legal ... - BSC NEWS - November 14th, 2023 [November 14th, 2023]
- Ethereum vs. Binance Smart Chain: Where to Make More Money - Medium - October 26th, 2023 [October 26th, 2023]
- What Are Trust Wallet Airdrops and How to Claim One? - Latest Cryptocurrency Prices & Articles - October 26th, 2023 [October 26th, 2023]
- Binance Statistics 2023 (Data on Usage, Revenue, and More) - The Tech Report - October 26th, 2023 [October 26th, 2023]
- 10 Cryptocurrencies That Could Explode in 2024 - Analytics Insight - October 26th, 2023 [October 26th, 2023]
- The Rise of Automated Crypto Trading: Strategies and Success Stories - TechiExpert.com - October 26th, 2023 [October 26th, 2023]
- The Best Crypto to Buy Now - Tekedia - October 26th, 2023 [October 26th, 2023]
- Crypto hacks: The Story - The Cryptonomist - October 15th, 2023 [October 15th, 2023]
- Taurus taps Bank of America and SAP veterans to head European ... - Tekedia - October 15th, 2023 [October 15th, 2023]
- Why Are Whales Flooding Everlodge (ELDG)? Bitcoin Cash (BCH ... - The Crypto Basic - October 15th, 2023 [October 15th, 2023]
- Ankr teams up with XDC Network to launch RPC Integration - crypto.news - October 15th, 2023 [October 15th, 2023]
- Binance froze cryptocurrency accounts associated with Hamas amid ... - Tekedia - October 15th, 2023 [October 15th, 2023]
- TangibleDAO Plans Recovery After USDR Stablecoin Crashes - BeInCrypto - October 15th, 2023 [October 15th, 2023]
- The Environmental Impact of Proof-of-Stake Blockchains: A ... - Tribune Online - October 15th, 2023 [October 15th, 2023]
- Binance Coin Hovers Above $200: BNB Smart Chain Users Rise 40% - Watcher Guru - September 11th, 2023 [September 11th, 2023]
- Binance's indecision to freeze BNB wallets drew controversy in this ... - Cointelegraph - September 11th, 2023 [September 11th, 2023]
- 3 Coins Set To Dominate the Market in 2023 Ethereum (ETH ... - Finbold - Finance in Bold - September 11th, 2023 [September 11th, 2023]
- While Bitcoin Battles Inside Price Channel, Traders Are Buying This ... - Captain Altcoin - September 11th, 2023 [September 11th, 2023]
- Binance Airdrop $3 million BNB to Morocco Earthquake Victims - Watcher Guru - September 11th, 2023 [September 11th, 2023]
- ETH Price Prediction: Uncertain Short-Term Outlook, But These ... - Captain Altcoin - September 11th, 2023 [September 11th, 2023]
- BNB Shows Promising Signs As opBNB Launches, Pomerdoge ... - The Crypto Basic - September 11th, 2023 [September 11th, 2023]
- B2BinPay v17 - Breaking down the latest major platform update - Cointelegraph - September 11th, 2023 [September 11th, 2023]
- 4 Reasons The Bitcoin Price Could Hit $50,000 This Winter ... - Finbold - Finance in Bold - September 11th, 2023 [September 11th, 2023]
- Cronos (CRO) Price Insight - With Growing Utility, Can CRO Reach ... - Inside Bitcoins - September 11th, 2023 [September 11th, 2023]
- How to Bridge to Tron - Watcher Guru - August 13th, 2023 [August 13th, 2023]
- Could the SEC Lawsuit End Binance for Good? Analysts Weigh In - Live Bitcoin News - August 13th, 2023 [August 13th, 2023]
- BNB Chain hard fork to improve security and compatibility with EVM ... - Cointelegraph - August 13th, 2023 [August 13th, 2023]
- How To Get Free 10 BNB with PancakeSwap Full Tutorial 2023 - Medium - August 13th, 2023 [August 13th, 2023]
- How to find BEP-20 wallet address on Trust Wallet & Metamask ... - Cryptopolitan - August 13th, 2023 [August 13th, 2023]
- Curved Finance Receives $5 Million FromBinance - cryptonewsbytes.com - August 13th, 2023 [August 13th, 2023]
- Early activity on Coinbase's Base chain shows promising signs - Blockworks - August 13th, 2023 [August 13th, 2023]
- Solana TVL Soars: Outperforms Ethereum, BSC, and Avalanche ... - Crypto News Flash - August 13th, 2023 [August 13th, 2023]
- Developing Automated Market Making on PancakeSwap: Tools ... - Rebellion Research - August 13th, 2023 [August 13th, 2023]
- Visa Unveils Experimental Solution to Abstract Away Gas Fees ... - Tekedia - August 13th, 2023 [August 13th, 2023]
- Shiba Inu Price Prediction: SHIB's Meteoric Rise; A Meme from the ... - Inside Bitcoins - August 13th, 2023 [August 13th, 2023]
- Exploring DeFi Protocols And Ecosystems: Unveiling The ... - Blockchain Magazine - August 13th, 2023 [August 13th, 2023]
- Altcoin Daily and Raoul Pal Anticipate Alt Season: BNB, AVAX, and ... - Tekedia - August 13th, 2023 [August 13th, 2023]
- The Galactic Meme Coin Making Waves in the Binance Smart Chain - Digital Journal - July 26th, 2023 [July 26th, 2023]
- Top 3 Binance Coins in Q3-2023. - Altcoin Buzz - July 26th, 2023 [July 26th, 2023]
- Binance: Fight The Urge To Buy The Dip (BNB-USD) - Seeking Alpha - July 26th, 2023 [July 26th, 2023]
- The 5 Forces Propelling The Continued Growth Of Ethereum - Blockzeit - July 26th, 2023 [July 26th, 2023]
- Seize the Day: Could Chancer Be the Best New Crypto of 2023? - The Coin Republic - July 26th, 2023 [July 26th, 2023]
- Unraveling the Craze: The Furry Spectacle of Hamster Racing in the ... - Blockzeit - July 26th, 2023 [July 26th, 2023]
- The Future of Crypto Exchanges Centralized DEX Interfaces - Techopedia - July 26th, 2023 [July 26th, 2023]
- 12 Best Blockchain Protocols To Know - Techopedia - July 17th, 2023 [July 17th, 2023]
- Binance Coin: Fueling the Worlds Largest Crypto Exchange - Business News This Week - July 17th, 2023 [July 17th, 2023]
- As the Theta Network Price Rises More Upside Could be Limited - BanklessTimes - July 17th, 2023 [July 17th, 2023]
- Discover Emerging Opportunities With BNB Chain And Uwerx(WERX) - The Portugal News - July 17th, 2023 [July 17th, 2023]
- Benefits of Wrapped Crypto that You Need to Check Out ... - Cryptopolitan - July 17th, 2023 [July 17th, 2023]
- 3 Cryptos to Catapult You into the Millionaires' Club - InvestorPlace - July 17th, 2023 [July 17th, 2023]
- 5 Meme Coins That Are Dominating Crypto Social Media Activity in ... - Analytics Insight - July 17th, 2023 [July 17th, 2023]
- CertiK Completes Comprehensive Security Audit of Automated ... - GlobeNewswire - July 17th, 2023 [July 17th, 2023]
- Parsiq: Real-Time Blockchain Monitoring and Automation - Tech Critter - July 17th, 2023 [July 17th, 2023]
- The Top 10 Blockchain-Based Storage Platforms - MUO - MakeUseOf - July 17th, 2023 [July 17th, 2023]
- Exploring The Best Altcoins For The Next Bull Run: Cardano ... - Tekedia - July 17th, 2023 [July 17th, 2023]
- An Introduction to Binance Smart Contracts for Token Holders - Net Newsledger - June 22nd, 2023 [June 22nd, 2023]
- Palmswap Secures Partnership with Gotbit for the Palmswap ... - GlobeNewswire - June 22nd, 2023 [June 22nd, 2023]
- Exciting Adventure Awaits as My Neighbor Alice Unveils Alpha ... - Finbold - Finance in Bold - June 22nd, 2023 [June 22nd, 2023]
- Among Blockchains Supporting NFTs, Here's Why Ethereum Will ... - Inside Bitcoins - June 22nd, 2023 [June 22nd, 2023]
- ChainGPT Token (CGPT) is Launching on Ethereum - Bridging ... - CryptoPotato - June 22nd, 2023 [June 22nd, 2023]