Pages:
Author

Topic: DeFi hacks [history] - page 2. (Read 19375 times)

hero member
Activity: 2100
Merit: 562
January 24, 2024, 11:30:31 AM
Observing the numerous incidents you've shared within the DeFi space, it's evident that security remains a significant challenge. The frequency and scale of these hacks highlight the vulnerabilities inherent in the current decentralized financial ecosystem. As the space continues to evolve, addressing these security concerns and implementing robust measures to safeguard users' funds will be crucial for the sustained growth and adoption of DeFi. The community's response and ability to learn from these incidents will play a pivotal role in shaping a more secure and resilient decentralized financial landscape.
legendary
Activity: 1820
Merit: 1121
January 24, 2024, 06:33:01 AM
DeFi protocol Concentric.fi suffered a hacker attack and lost approximately US$1.6 million, reminding not to interact for now
CertiK Alert monitors that the DeFi protocol Concentric Finance platform built based on the Camelot v3 protocol has been attacked by vulnerabilities, and the initial loss is estimated to be US$1.6 million. Concentric Finance reminds you not to interact with this protocol for the time being.

https://www.coinlive.com/news-flash/424934
legendary
Activity: 1932
Merit: 4602
January 17, 2024, 07:49:45 AM
https://coingape.com/socket-loses-3-3-million-in-hack-due-to-input-validation-flaw/

Socket Loses $3.3 Million in Hack Due to Input Validation Flaw

"Blockchain interoperability protocol Socket reported a security breach on Tuesday that resulted in over $3.3 million in losses. The incident impacted wallets that had granted infinite approvals to Socket contracts. It was attributed to a vulnerability in user input validation.

The exploit was linked to a specific route in the system that had been added just three days before the attack. As per blockchain security firm PeckShield, the problematic route has since been deactivated to prevent further misuse."
newbie
Activity: 12
Merit: 0
January 04, 2024, 05:07:25 PM
Great topic, love this list! Thanks

I hope DeFi will have less and less of those as DEX improves.
legendary
Activity: 1932
Merit: 4602
January 04, 2024, 05:10:15 AM
First hack in 2024
https://ambcrypto.com/radiant-capital-falls-prey-to-this-security-hack-details-here/
Radiant Capital falls prey to this security hack.

"Radiant Capital faced a cyber attack, resulting in a loss of over $4.4 million.
The breach prompts a temporary pause, leading to a decline in sentiment for both Radiant Capital and Arbitrum.
Radiant Capital [RDNT] is a platform that seeks to unify fragmented liquidity across various lending protocols and chains in the decentralized finance (DeFi) space. However, recent events have cast a shadow on its integrity as the platform fell victim to a malicious attack."
legendary
Activity: 1820
Merit: 1121
January 03, 2024, 10:25:30 AM
Levana Protocol, a platform known for its blockchain-based perpetual futures swap protocol, has fallen victim to a devastating crypto hack.
The exploit led to the loss of more than $1 million worth of cryptocurrency tokens from Levana's liquidity pools. This incident highlights the growing challenges blockchain platforms face in ensuring the security of user funds and the need for robust security measures.

https://www.econotimes.com/Blockchain-Based-Levana-Protocol-Falls-Victim-to-1-Million-Crypto-Hack-1668721
legendary
Activity: 1932
Merit: 4602
January 03, 2024, 05:25:24 AM
https://www.theblock.co/post/269809/orbit-chains-bridge-reportedly-hacked-for-81-5-million
Orbit Chain's bridge reportedly hacked for $81.5 million

"Orbit Chain’s cross-chain bridge has reportedly been hacked for $81.5 million in cryptocurrencies and stablecoins.
The exact nature of the hack is unknown.

Orbit Bridge, a cross-chain bridge protocol, has seen unusual outflows of $81.5 million in several cryptocurrencies in what appears to be a major hack.

In five separate transactions, each to a fresh wallet, the Orbit Bridge sent $50 million in stablecoins (30 million Tether, 10 million DAI, and 10 million USDC), 231 wBTC (about $10 million), and 9,500 eth (about $21.5 million). The hack was first noticed by X user Kgjr. "
legendary
Activity: 1708
Merit: 1615
Payment Gateway Allows Recurring Payments
December 28, 2023, 06:34:20 AM
Scammers stole $880k via fake Discord server for Across Protocol
Crypto sleuth ZachXBT warned in a Telegram channel that Across Protocol’s documentation was linked to a fake Discord server.
In a Telegram post on Dec. 26, crypto sleuth ZachXBT raised concerns about a potential security breach related to Across Protocol’s documentation.

The warning highlighted a link within the protocol’s documentation leading users to a fake Discord server, suggesting the protocol’s vanity invite address might have been compromised. The incident reportedly led to a loss of $880,000 worth of crypto tied to one unknown blockchain entity.
legendary
Activity: 1820
Merit: 1121
December 27, 2023, 12:23:51 PM
Thunder Terminal claims funds safe after $240K attack, hacker says otherwise
The on-chain trading platform confirmed a 3rd party compromise has led to funds being drained from 114 wallets but claims it has already fixed the issue. The hacker has a different take.
On-chain trading platform Thunder Terminal says user funds are now safe after thwarting a $240,000 exploit that compromised 114 wallets on its platform. The hacker, however, says it’s "all lies" and is demanding an additional ransom for user data.

https://cointelegraph.com/news/thunder-terminal-hack-exploit-wallet-compromise-hacker-demands-ransom
legendary
Activity: 1932
Merit: 4602
December 13, 2023, 04:45:31 PM
https://invezz.com/news/2023/12/13/okx-dex-losses-370k-in-hack-users-assured-reimbursement/

"OKX Dex has faced a suspected hacking incident, resulting in losses exceeding $370,000.
OKX Dex swiftly responded to the breach by removing the compromised proxy address.
OKX also deactivated the affected contracts and reassured users of asset safety.

OKX‘s decentralized exchange and cross-chain bridge aggregator OKX Dex has fallen victim to a suspected hacking incident, resulting in losses exceeding $370,000. The breach raised alarms among users who noticed unauthorized transactions from wallets previously authorized on the platform.

The hacker is said to have exploited the vulnerability in OKX Dex’s authorization process as users exchange their crypto assets."
legendary
Activity: 1932
Merit: 4602
December 06, 2023, 10:42:41 AM
https://beincrypto.com/florence-finance-loses-1-45-million-hackers/
"Scammers have stolen $1.45 million in USDC from the real-world asset lending project, Florence Finance, via a phishing attack.
The Florence Finance attack involved address poisoning, a common phishing technique where a fraudulent, similar-looking address is used.
Co-founder and CEO of Cyvers, Deddy Lavid, has emphasized the need for heightened security measures in the digital finance sector."
legendary
Activity: 1932
Merit: 4602
November 29, 2023, 11:33:45 AM
https://twitter.com/KyberNetwork/status/1728800315955437743

"The KyberSwap team has been in contact with the owners of the frontrun bots that extracted about $5.7M* worth of funds from KyberSwap pools on Polygon and Avalanche during the exploit.
We have negotiated with the owners of the frontrun bots to return 90% of the users’ funds taken by them to: 0x8180a5CA4E3B94045e05A9313777955f7518D757,
in return for a 10% bounty as described in this on-chain message: https://polygonscan.com/tx/0x8a0880f1662e39fa838e89fa751669e4a1eee5c15586dc447453274f7b8ce746
.."
member
Activity: 295
Merit: 28
Enterapp
November 24, 2023, 11:58:36 AM
What do you think is the reason why this case always happens every year? If you look at history, there will always be things like this.
Is it that easy to hack or is the security of each project different, or is this a game of the people closest to it, because they are the ones who can reach it the easiest, and there are many other possibilities.

Now the question is whether it is wise not to trust an exchange with all your coins. Indeed, this is an easy target for bandits and no matter how strong the security system created by the exchange, it will still be searchable and this year 2023 the cryptocurrency market is very unstable.
hero member
Activity: 700
Merit: 577
Hire Bitcointalk Camp. Manager @ r7promotions.com
November 24, 2023, 11:24:08 AM
What do you think is the reason why this case always happens every year? If you look at history, there will always be things like this.
Is it that easy to hack or is the security of each project different, or is this a game of the people closest to it, because they are the ones who can reach it the easiest, and there are many other possibilities.
Most of them are hacked by closed friends and also careless or improper security caused by the developer. When a project is launched the developer should put the security of the site in his mind first and always and if it is not enough they should buy more security space for the site so that when a hacker visit the site it would bounced back but whereby you only develop the site and dump it like that without any extra security measures to prevent and protect the site then hackers will be very happy to penetrate.

In sometimes, co-workers, or a mistake of the owner of the DeFi caused the hack. And this has happened to me before. I mistakenly send a code that was sent to me in Facebook and it used to hacked my Facebook account, they are some emails DeFi received and they were trying to quote those messages by replying them and a code which was secretly sent was forwarded to them and the site was hacked.
full member
Activity: 1554
Merit: 101
November 24, 2023, 08:06:14 AM
What do you think is the reason why this case always happens every year? If you look at history, there will always be things like this.
Is it that easy to hack or is the security of each project different, or is this a game of the people closest to it, because they are the ones who can reach it the easiest, and there are many other possibilities.
legendary
Activity: 1932
Merit: 4602
November 24, 2023, 06:22:53 AM
https://www.msn.com/en-us/news/technology/infstones-to-implement-key-rotations-following-vulnerability-disclosure-in-lido-protocol/ar-AA1kqfJR
InfStones to Implement Key Rotations Following Vulnerability Disclosure in Lido Protocol
"Addressing the Tailon library vulnerability
The vulnerability, which was discovered in the open-source Tailon library, posed a potential risk to the Lido Finance protocol. Lido Finance, known for being the largest liquid staking protocol on Ethereum, oversees a substantial amount of ether, amounting to 9.23 million with a market value exceeding $19 billion. The protocol allows users to deposit ETH and participate in network staking through validator nodes. These nodes issue a derivative token to users, representing their staked deposit. A network of contributors, known as operators, is responsible for running these ETH validator nodes."
legendary
Activity: 1820
Merit: 1121
November 23, 2023, 10:39:24 AM
Data shared by blockchain security platform PeckShield shows that more than $86.6 million in digital assets were transferred from the HECO Chain bridge to suspicious addresses. The security firm suggests that the bridge is compromised and an exploit is ongoing.

In response to the incident, Tron founder Justin Sun announced that HTX will fully compensate users for any losses incurred in the hack. The company has also temporarily suspended deposits and withdrawals as they investigate the incident. The executive said services will resume after the investigation is completed.


https://cointelegraph.com/news/heco-chain-bridge-hack-86-million-lost

HTX and Heco Cross-Chain Bridge Undergo Hacker Attack.
https://twitter.com/justinsuntron/status/1727304656622326180?
legendary
Activity: 1932
Merit: 4602
November 23, 2023, 05:54:24 AM
https://cryptonews.com/news/kyberswap-hacked-for-48-million-hackers-suggest-negotiations.htm
"KyberSwap Hacked for $48 Million, Hackers Suggest Negotiations
KyberSwap, a decentralized exchange, has been compromised in a hack resulting in the theft of $48 million, prompting the platform to advise users to withdraw their funds while the attackers hint at entering negotiations.

On-chain data indicates that the hack on KyberSwap resulted in significant losses of $48 million across several blockchain networks, including 20 million from Arbitrum, $15 million from Optimism and $7 million from Ethereum.

The stolen funds were primarily deposited in Ethereum (ETH), Wrapped Ethereum (wETH), and USD Coin (USDC). The analysis of the incident indicates a direct attack on the exchange’s liquidity pools instead of a vulnerability in the platform’s code."
legendary
Activity: 1932
Merit: 4602
November 15, 2023, 10:40:11 AM
Raft Suffers $3.3M Exploit That Drove Down Stablecoin 50%, but Hacker Likely Lost Money on Attack
https://www.coindesk.com/tech/2023/11/10/defi-platform-raft-suffers-33m-exploit-but-hacker-likely-takes-a-loss-on-the-attack/
"Decentralized finance (DeFi) platform Raft lost some $3.3 million in ether (ETH) after being hacked Friday afternoon – but the attacker may have suffered a loss on the heist.
On-chain data shows that the attacker drained 1,577 ETH from Raft, then sent 1,570 ETH to a burn address – destroying most of the stolen assets and leaving only 7 ETH for themselves. The hacker's address received 18 ETH via crypto mixer service Tornado Cash before the attack, blockchain data on Arkham shows, likely to fund transactions.
After executing the transfers and paying the blockchain fees, the exploiter's crypto wallet was left with only 14 ETH, fewer funds than the initial 18 ETH.
This means that they face a 4 ETH loss on the whole maneuver."

TrustPad Attack Post-Mortem
https://trustpad.medium.com/trustpad-attack-post-mortem-c09ccc01e0ef
exploit to one of TrustPad’s staking contracts
legendary
Activity: 1932
Merit: 4602
November 08, 2023, 06:43:37 AM
https://twitter.com/AstridFinance/status/1718236380009230406
"Unfortunately our smart contract was exploited due to a fix recommended by our auditor.

We have paused the contract.

We have taken a snapshot of all holders and will offer full refund and make everyone whole. Please wait as our team work out the refund process.

We truly apologize for what happened and will make sure everyone is refunded accordingly "

Damage approximately 245 000 dollars  AstridFinance

https://twitter.com/AstridFinance/status/1718563845323866383
"Hacker has decided to return our funds (minus 20% as per the bounty), as such we consider this as settled amicably."
https://etherscan.io/tx/0x27cbd5f2f12067bcc9be3bafa9140b849ee1ee68ae5329c2a4ba789685111ad7
Pages:
Jump to: