On-chain Data Suggests Crypto Hacks and DeFi Exploits are on … – Securities.io
More than $320 million was lost to bad actors within the crypto space in the first quarter of the year as per data compiled by smart contract security platform CertiK. The figure represented a significant decline from that in the preceding quarter (Q4 2022) and from a similar period in the previous year. The blockchain security firm attributed this decrease to distressing incidents that rocked the industry across the three months.
Notable among them, an upheaval in the stablecoin markets and a banking crisis extending into the digital assets space. These and other unfortunate incidents prompted investors to move their funds to the sidelines while also putting off potential entrants and inflows as a result. Barely halfway into Q2, more exploit incidents have been reported with attributable losses headed to equal the figure reported in Q1.
In March, about $211 million was stolen in crypto, dominated by a $197 million hack on Euler Finance. The amount siphoned last month was slightly less than half of this, with blockchain security firm Certified Kernel Tech (CertiK) estimating a figure of $103.7 million in losses to exploits, hacks, and scams.
April and March numbers brought the total amount stolen by malicious actors in the first four months to $429.7 million year-to-date. Another major incident in April was the Ethereum Maximal Extractable Value (MEV) bot sandwich attack which resulted in a $25.4 million loss. Bitrue exchange also reportedly had $23 million in Ether and other currencies drained from one of its hot wallets.
Decentralized finance aggregator, Yearn Finance led in flash loan attacks last month, with only users running on an older version of the protocol affected. PeckShield reported on April 13 that a hacker targeted a bug to mint an extremely huge amount of yUSDT 1.3 quadrillion tokens, worth about $11.6 million from just 10,000 USDT. In a series of swaps that ensued afterward, the attacker was able to obtain 61,000 USDP, 1.5 million TUSD, 1.79 million BUSD, 1.2 million USDT, 2.58 million USDC, and 3 million DAI.
Multi-chain lending pool Hundred Finance lost $7.4 million on April 15 after suffering a security breach involving flash loaning WBTC on Ethereum layer two Optimism. The protocol has since placed a $500,00 bounty on the hacker after efforts to negotiate seemingly bore no fruits. Hundred Finance was previously hit to the tune of $6.5 million in a reentrancy attack in March 2022. The blockchain security firm further showed that total funds lost to exit scams increased to $9.4 million in April, heralded by the decentralized exchange Merlin.
zkSync decentralized exchange Merlin's loss of $1.82 million came on April 25, during the three-day public sale of its MAGE tokens, despite brandishing an audit by CertiK. The DEX, whose popularity stems from the attractive yield offered on deposits, confirmed the attack advising all users to disengage their wallet permissions. CertiK meanwhile termed it a private key management issue.
In a thread addressing the incident, the blockchain security firm later highlighted that it had pointed out centralization risk under Decentralization Efforts in its audit report of Merlin. Some, however, question the quality of work done by the firm. Meanwhile, the malicious code that allegedly caused the loss of funds was identified by eZKalibur, a decentralized exchange, and launchpad also built on zkSync. eZKalibur pointed out that the initialize function created a backdoor of sorts, allowing an unlimited amount of tokens to be transferred from the contract's address to the feeTo address.
CertiK said on April 26 that it was exploring a compensation plan for the affected while still urging the responsible individuals to return 80% of the funds and keep the rest as a white hat bounty. It further said that rather than an attack, Merlin was a victim of rogue developers which explains why the entity was able to siphon the liquidity pool with such ease. The blockchain security team said the perpetrators are believed to be in Europe and that it is working with law enforcement agencies to bring them to justice should direct negotiations hit a brick wall.
In an update on the situation on Friday, CertiK insisted that all this was a rug pull by Merlin developers who took advantage of their wallet privileges to defraud users. It added that attempts to collaborate with the remaining Merlin team were plagued by challenges as certain core members were unwilling to verify their identities, making validation and eventual assistance of the victims difficult. CertiK has frozen $160,000 of the stolen funds so far and is closely monitoring the remaining amount in hopes of recovery. It is working with law enforcement agencies in the US and UK towards these efforts and also pledged $2 million to help the victims and fight exit scams.
A price oracle manipulation hack struck lending protocol 0VIX at the end of April, causing it to lose more than $2 million following an exploit on the vGHST token, a staked token of blockchain gaming initiative inspired by the popular Tamagotchi game. Blockchain security company PeckShield revealed that the hackers behind the 0VIX Protocol attack utilized a flash loan worth $6.12 million in stablecoins to open vGSHT lending positions.
The attacker(s) afterward manipulated the protocol's price oracle and the vGSHT lending pool in extension they manufactured a spike in the price of GHST, which made the vGHST lending pool insolvent, enabling them to liquidate the pools and walk away with the collateral from the pools. The protocol's core team suspended Polygon POS and zkEVM operations (its token lending markets), adding that it had initiated efforts to manage the situation.
In a subsequent update, the 0VIX Protocol Association said it resumed operations on the zkEVM, allowing users of the 0VIX Polygon zkEVM market unrestricted access to their funds. It asked all users to verify their positions and health factor and repay any outstanding debts. The update further clarified that the pause on 0VIX zkEVM had only been a preventive measure, as the exploit did not affect it. The Association, however, didnt divulge any further details to protect the integrity of ongoing investigations, adding that it, along with its security partners, remained dedicated to recovering the compromised funds.
This week, Level Finance was hacked for $1 million worth of its native LVL token. The BNB Chain-native non-custodial spot and perpetual contracts exchange confirmed on May 1 that the attacker targeted its LevelReferralControllerV2 referral contract that enables repeated claims, making away with more than 214 LVLs which they exchanged for 3,345 BNB.
Blockchain security company PeckShield said that the hack resulted from a bug that allowed repeated referral claims (in the same epoch), which Level Finance confirmed was from a recent update to its incentive mechanism. The platform temporarily halted its referral program to end the attack, though the event did not affect its liquidity pools or linked DAOs.
In a more recent incident, DeFi protocol Deus Finance confirmed over the weekend that it was the victim of a hack on its BNB Smart Chain and Arbitrum deployments. Though not confirmed yet, the manipulation saw it lose more than $6 million in crypto assets. The attack was front run by a bot according to PeckShield, allowing the hacker to make away with 1,337,375 BUSD from DEI/BUSD pools, and a further $5 million on the ARB/ETH pools. Deus paused all contracts and DEI tokens on-chain burned in response to mitigate against more losses. The protocol team added that it actively evaluating the underlying collateral of the DEI, and will devise a comprehensive recovery and redemption plan depending on pre-burn DEI balances.
Recognizing that some individuals may have taken part in arbitrage endeavors following the breach and gotten stuck while at it, Deus said it was actively assessing to see whether these transactions can be reversed expeditiously to resolve the matter. The DeFi platform pointed out that the Deus v3 system, currently in use, is isolated from DEI and therefore was unaffected by the events. It has also urged the attacker to relinquish 80% of the proceeds and consider the rest a white hat bounty. In a tweet earlier today, the DEI stablecoin issuer Deus Finance said the exploiter(s) had complied and sent back 2,023 ETH to a recovery multi-sig wallet address managed by trusted members of Yearn Finance.
Excerpt from:
On-chain Data Suggests Crypto Hacks and DeFi Exploits are on ... - Securities.io
- DeFi, smart contracts, and robot wallets will shape our world in 2025 | Opinion - crypto.news - January 30th, 2025 [January 30th, 2025]
- Gas and dApps: Connecting Smart Contracts for Efficient Blockchain Operations - Geek Vibes Nation - January 30th, 2025 [January 30th, 2025]
- If You Invested $1,000 In Ethereum When Jamie Dimon Said Cryptos With Smart Contracts Have Value, Here's How Much You'd Have Today - Grayscale Bitcoin... - January 26th, 2025 [January 26th, 2025]
- How Blockchain and Smart Contracts Are Transforming Online Gambling - SIDE-LINE MAGAZINE - January 26th, 2025 [January 26th, 2025]
- The Future of Ethereums Smart Contracts: Unlocking New Possibilities Market - HPBL - January 26th, 2025 [January 26th, 2025]
- AGII Redefines Smart Contracts with AI Integration in Web3 - CoinTrust - January 11th, 2025 [January 11th, 2025]
- The Future of Ethereum: Beyond Smart Contracts! - Bit Perfect Solutions - January 11th, 2025 [January 11th, 2025]
- ADAs Smart Contracts Revolutionized Crypto, but 1Fuel Takes It to the Next Level - CryptoDaily - January 6th, 2025 [January 6th, 2025]
- XRP Revolutionizing Smart Contracts! How Ripple is Shaping the Future of Digital Transactions - Bit Perfect Solutions - January 6th, 2025 [January 6th, 2025]
- Ethereum Smart Contracts Are Being Reimagined by Lightchain AI Ecosystem Press release Bitcoin News - Bitcoin.com News - December 22nd, 2024 [December 22nd, 2024]
- Why Qubetics Presale, Solanas Scalability, and Stacks Smart Contracts Rank Among the Best Cryptos with 1000X Potential - The Merkle News - December 22nd, 2024 [December 22nd, 2024]
- Chainlink Crypto Revolution! The Oracle Network Thats Redefining Smart Contracts - Bit Perfect Solutions - December 22nd, 2024 [December 22nd, 2024]
- Web3 and AI Platform AGII Redefines Smart Contracts with AI-Powered Efficiency and Adaptive Intelligence - Benzinga - December 22nd, 2024 [December 22nd, 2024]
- How AI and smart contracts will impact construction - Construction News - December 8th, 2024 [December 8th, 2024]
- XRP soars: Why has zero venture capital, no smart contracts, and low user numbers led to a market value of $180 billion? - ChainCatcher - December 8th, 2024 [December 8th, 2024]
- Court Rules OFAC Exceeded Authority in Sanctioning Tornado Cash Smart Contracts - Lawyer Monthly Magazine - November 28th, 2024 [November 28th, 2024]
- Fifth Circuit Rules OFAC Overstepped in Sanctioning Tornado Cash's Immutable Smart Contracts - Decrypt - November 26th, 2024 [November 26th, 2024]
- Ethereum Time Machine: A New Era for Smart Contracts and Future-Based Transactions - Crypto News Flash - November 16th, 2024 [November 16th, 2024]
- Ethereum researcher unveils time machine for even smarter, smart contracts - StartupNews.fyi - November 16th, 2024 [November 16th, 2024]
- FlexiNetAI Is Disrupting Blockchain Space With Innovative Smart Contracts - StreetInsider.com - November 2nd, 2024 [November 2nd, 2024]
- From Code to Intelligence: How Yeager.ai is Building Internet-Native Smart Contracts - hackernoon.com - November 2nd, 2024 [November 2nd, 2024]
- Smart Contracts Platforms Market Poised for Explosive Growth, Reaching $230.4 Billion by 2032 - openPR - October 23rd, 2024 [October 23rd, 2024]
- Healthcare Smart Contracts Market Business Insights, Key Trend Analysis - News in Assen - October 7th, 2024 [October 7th, 2024]
- From Court to Code: Smart Contracts and Arbitration - JD Supra - September 21st, 2024 [September 21st, 2024]
- VeChain CEO Says Incentivizing EV Drivers For Reducing C02 Emissions Is "Very Cheap" Because Of Smart contracts - 99Bitcoins - September 21st, 2024 [September 21st, 2024]
- How Smart Contracts are Reinventing the Gaming Experience - SMEStreet - September 21st, 2024 [September 21st, 2024]
- W3.io Launches Industry Alliance to Develop the First Orchestration Cloud for Smart Contracts - Decrypt - September 19th, 2024 [September 19th, 2024]
- Smart Contracts Market: Enabling Secure and Automated Transactions - openPR - September 19th, 2024 [September 19th, 2024]
- How Smart Contracts are Enhancing Trust in Crypto-Based Gambling Platforms - UseTheBitcoin - September 19th, 2024 [September 19th, 2024]
- Meticulous Research Projects the Smart Contracts Market to Reach $8.7 Billion by 2031 - openPR - September 19th, 2024 [September 19th, 2024]
- Smart Contracts: where are we now and does AI have a role to play? - Travers Smith - September 10th, 2024 [September 10th, 2024]
- Friend.tech's FRIEND token tanks to record low as team abandons control of smart contracts - Crypto Briefing - September 10th, 2024 [September 10th, 2024]
- Friend.Tech Faces Uncertain Future After Transferring Control of Smart Contracts - BSC News - September 10th, 2024 [September 10th, 2024]
- Ripples Vision: Native Smart Contracts on XRPL Mainnet and Launching the XRPL EVM Sidechain - CryptoGlobe - September 6th, 2024 [September 6th, 2024]
- Ripple Will Support Ethereum Compatible Smart Contracts Soon - Live Bitcoin News - September 6th, 2024 [September 6th, 2024]
- Smart Contracts On The XRP Ledger, Ripples Change Of Heart Worries Community | Bitcoinist.com - Bitcoinist - September 6th, 2024 [September 6th, 2024]
- Ripple to bring smart contracts on XRP Ledger - crypto.news - September 6th, 2024 [September 6th, 2024]
- Ripple to Add Ethereum-Compatible Smart Contracts to XRP Ledger - Cryptonews - September 6th, 2024 [September 6th, 2024]
- Ripple to Add Ethereum Smart Contracts to its XRP Ledger - Watcher Guru - September 6th, 2024 [September 6th, 2024]
- Flare Labs CEO Says Smart Contracts on XRP Ledger Will Make FXRP Even Better - The Crypto Basic - September 6th, 2024 [September 6th, 2024]
- Ripple Introduces Smart Contracts and Innovative NFT Features to the XRP Ledger - Crypto News Flash - September 6th, 2024 [September 6th, 2024]
- Tensions Rise in XRP Community as Ripple Reverses Stance on XRPL Smart Contracts - The Crypto Basic - September 6th, 2024 [September 6th, 2024]
- XRP Ledger set to gain smart contracts and EVM Sidechain - CryptoTvplus - September 6th, 2024 [September 6th, 2024]
- XRP to Moon: Ripple To Expand XRP Ledger with Ethereum-Compatible Smart Contracts - Coinpedia Fintech News - September 6th, 2024 [September 6th, 2024]
- Ripple Announces Smart Contracts for XRP Ledger, Expanding Features for NFTs, AMMs, and DEXs - BSC News - September 6th, 2024 [September 6th, 2024]
- Ripple To Add Ethereum Smart Contracts To XRP Ledger By yolowire.com - Investing.com Canada - September 6th, 2024 [September 6th, 2024]
- Ripple to Enhance XRP Ledger with Ethereum-Compatible Smart Contracts - Crypto News Australia - September 6th, 2024 [September 6th, 2024]
- Ripple to launch smart contracts on XRP Ledger (XRPL), boosting DeFi capabilities and DApps - Invezz - September 6th, 2024 [September 6th, 2024]
- Soroban: Unlocking DeFi Opportunities with Smart Contracts on Stellar - The Defiant - DeFi News - August 20th, 2024 [August 20th, 2024]
- How Are Smart Contracts Different From DApps: Top 5 Amazing Examples Of Each - Blockchain Magazine - August 20th, 2024 [August 20th, 2024]
- Bitcoin Sidechains: CertiK Shares Insights on Clarity Smart Contracts which Are Utilized By Stacks Chain - Crowdfund Insider - August 16th, 2024 [August 16th, 2024]
- Blockchain Currencys Role in the Evolution of Smart Contracts - NFL Draft Diamonds - August 16th, 2024 [August 16th, 2024]
- How to Bridge to Internet Computer? - Watcher Guru - July 15th, 2024 [July 15th, 2024]
- Why (Almost) Everyone in Ethereum Is So Excited About a Wallet-Related Proposal - Unchained - Unchained - April 13th, 2024 [April 13th, 2024]
- Ethereum's Pectra upgrade slated for Q4 2024, bringing smart contract features and improved UX for wallets - Crypto Briefing - April 13th, 2024 [April 13th, 2024]
- Ethereum's Pectra upgrade to make normal wallets 'smart' and improve UX - Cointelegraph - April 13th, 2024 [April 13th, 2024]
- Ex-Amazon engineer sentenced to 3 years in prison for $12m crypto hack - crypto.news - April 13th, 2024 [April 13th, 2024]
- How Are Smart Contracts Transforming Financial Transactions? - IT News Africa - April 13th, 2024 [April 13th, 2024]
- Enhancing Smart Contract Security With SolidityScan and Blockscout Integration - Business - April 13th, 2024 [April 13th, 2024]
- Top 15 Use Cases of Blockchain in the Real World, 2024 - Analytics Insight - April 13th, 2024 [April 13th, 2024]
- exSat Unveiled: Pioneering the Future of Bitcoin Scalability and Interoperability with Layer 2 Solutions - FinanceFeeds - April 9th, 2024 [April 9th, 2024]
- ZkLink looks to solve Ethereum's fragmented liquidity with a layer 3 but there are risks - DLNews - April 9th, 2024 [April 9th, 2024]
- 1 in 6 new Base meme coins are scams, 91% have vulnerabilities - TradingView - April 9th, 2024 [April 9th, 2024]
- The AI-Based Smart Contract Audit Firm "Bunzz Audit" Has Officially Launched - Chronicle-Tribune - April 9th, 2024 [April 9th, 2024]
- BlockDAG Smart Contract Leads With 20,000x ROIs As Top Trending Crypto Surpassing Dogecoin Rally And ICP's ... - Blockchain Magazine - April 9th, 2024 [April 9th, 2024]
- The complete guide to full stack BSV blockchain development - CoinGeek - April 9th, 2024 [April 9th, 2024]
- What Is Ethereum Restaking? - Ledger - April 9th, 2024 [April 9th, 2024]
- The Contract Evolution: Are Smart Contracts Outsmarting Tradition? - yTech - April 1st, 2024 [April 1st, 2024]
- Vitalik Buterin Initiates 'The Purge': Ethereum Protocol Simplification for Enhanced Efficiency - TradingView - April 1st, 2024 [April 1st, 2024]
- sCrypt Hackathon 2024: Making Ordinals easier with smart contracts - CoinGeek - April 1st, 2024 [April 1st, 2024]
- Smart Contracts and Family Law: Revolutionizing Agreements for the Modern Family - The Good Men Project - April 1st, 2024 [April 1st, 2024]
- NEAR launches tool for signing transactions on Bitcoin, Ethereum and more - Blockworks - April 1st, 2024 [April 1st, 2024]
- sCrypt Hackathon 2024: Project Babbage on why users should be at the center of digital economy - CoinGeek - April 1st, 2024 [April 1st, 2024]
- Cardano Gains Momentum: Innovative Developments Promise Continued Expansion and Evolution - West Island Blog - April 1st, 2024 [April 1st, 2024]
- How smart accounts and account abstraction can unlock Ethereum's full utility - Cointelegraph - March 22nd, 2024 [March 22nd, 2024]
- Stellar will invest $100M in Soroban smart contract apps in bid to beat Ethereum - VentureBeat - March 22nd, 2024 [March 22nd, 2024]
- Top 10 Intriguing Ways EVM (Ethereum Virtual Machine) Was Popularized By DeFi Craze - Blockchain Magazine - March 22nd, 2024 [March 22nd, 2024]
- Cardano (ADA)'s Smart Contract Boom: Is ADA Heading to $5? - CryptoTicker.io - Bitcoin Price, Ethereum Price & Crypto News - March 22nd, 2024 [March 22nd, 2024]
- Blockchain evolution with MANTA for Sora and intelligent contracts - Cointelegraph - March 22nd, 2024 [March 22nd, 2024]
- Top 10 Amazing Ways Ethereum Limitations Can Be Resolved By DApps Support - Blockchain Magazine - March 22nd, 2024 [March 22nd, 2024]