Pages:
Author

Topic: DeFi hacks [history] - page 4. (Read 19555 times)

legendary
Activity: 2016
Merit: 4765
September 27, 2023, 06:03:36 AM
https://www.coindesk.com/tech/2023/09/25/mixin-network-losses-nearly-200m-in-hack/
"Mixin Network has confirmed a report from SlowMist, a blockchain security consultancy, that it has been hacked for nearly $200 million.
“In the early morning of September 23…the database of Mixin Network's cloud service provider was attacked by hackers, resulting in the loss of some assets on the mainnet,” Mixin Network said in a statement. “The funds involved are approximately US$200 million.”
Mixin Network is a service similar to a layer-2 protocol, designed to make cross-chain transfers cheaper and more efficient.
But the problem with this, as many have pointed out on Twitter, is that it's reliant on a centralized database, creating a single point of failure."
legendary
Activity: 2002
Merit: 1689
September 20, 2023, 09:21:12 AM
It has come to our notice that Harbor protocol has been exploited over the past few hours, resulting in a drain on a portion of the funds sitting in the stable-mint and stOSMO, LUNA and WMATIC vaults.
exploit against a Harbor DeFi protocol ​​
$250,000 losses
Over $7m Stolen in Separate Attacks Against DeFi Protocols Exactly And Harbor
https://www.bitdegree.org/crypto/news/over-7m-stolen-in-separate-attacks-against-defi-protocols-exactly-and-harbor


GMBL Computer, a DeFi gambling protocol, was exploited for nearly 500 ETH, worth around $800,000 in today's prices.
The hacker's identity is known, and GMBL has offered a bounty for the return of funds to avoid legal action.
Despite accusations of an inside job, GMBL reported that half the stolen funds have already been recovered.
https://beincrypto.com/defi-gmbl-computer-exploited-eth-funds-returned/
legendary
Activity: 2016
Merit: 4765
September 06, 2023, 10:35:51 AM
https://www.bleepingcomputer.com/news/security/crypto-casino-stakecom-loses-41-million-to-hot-wallet-hackers/
Crypto casino Stake.com loses $41 million to hot wallet hackers

"Online cryptocurrency casino Stake.com announced that its ETH/BSC hot wallets had been compromised to perform unauthorized transactions, with over $40 million in crypto reportedly stolen.

The platform immediately reassured users that their funds were safe, and all other wallets not directly impacted by the attack, including those holding BTC, LTC, XRP, EOS, and TRX, remained fully operational."

___
https://twitter.com/peckshieldalert/status/1698870451815285045
"PeckShieldAlert A total of ~$41M worth of cryptos were drained from Stake.com , with ~$15.7M on #Ethereum (9.62K $ETH), ~$7.85M on #Polygon (14.24M $MAITC), and $17.75M on #BNBChain (82.65K $BNB)"
legendary
Activity: 2002
Merit: 1689
September 06, 2023, 09:32:13 AM
North Korean hackers have allegedly stolen hundreds of millions in crypto to fund nuclear programs
North Korea-linked hackers stole $200 million worth of crypto from January to Aug. 18, accounting for over 20% of all stolen crypto this year, according to a recent report by TRM Labs.
https://www.cnbc.com/2023/09/06/north-korea-hackers-stole-crypto-to-fund-nuclear-program-trm-chainalysis.html
legendary
Activity: 2016
Merit: 4765
August 30, 2023, 07:41:39 AM
https://www.theblock.co/post/246196/exactly-protocol-exploited-7-million-optimism-layer-2-network
"The exploit has resulted in estimated losses of over $7 million, according to security firms.

Exactly Protocol, a DeFi project that offers interest rate markets on the Optimism Layer 2 network, has become the latest victim of a security attack. The exploit, which was detected by security firms including BlockSec and Beosin, has resulted in estimated losses of over 4300 ether ($7.3 million)."


https://www.msn.com/en-us/money/markets/magnate-finance-executes-64-million-exit-scam-on-base-network-details/ar-AA1fLTXK
"Magnate Finance executes $6.4 million exit scam on Base Network
Magnate Finance, a lending project operating on the Ethereum Layer 2 network Base, has executed an exit scam, making off with an estimated $6.4 million. The event, described as a rug pull by security firm PeckShield, has sent shockwaves through the cryptocurrency community."
legendary
Activity: 1876
Merit: 1138
August 23, 2023, 01:31:46 PM
Base project RocketSwap Labs has outlined its emergency program to bounce back from a brute force hack that swiped $865,000 or 471 Ether  from the protocol on Aug. 14.
The team explained on Aug. 15 that they plan on redeploying a new farm contract and open-source it on-chain, relinquish minting rights — presumably of RCKT — and will soon call on the hackers to return the assets, among other things

https://cointelegraph.com/news/base-dex-rocketswap-announces-emergency-plan-after-exploit
legendary
Activity: 2016
Merit: 4765
August 16, 2023, 09:41:59 AM
"In August 2023, Steadefi — a leveraged yield aggregation platform — was the victim of an attack. The attacker gained access to the private keys used to manage the project’s deployed contract, resulting in about $1.1 million in losses."

https://www.halborn.com/blog/post/explained-the-steadefi-hack-august-2023

"Blockchain security firm PeckShield revealed fresh vulnerabilities targeting decentralized finance (DeFi) projects on Aug. 9. According to the firm, Aave’s Earning Farm has been compromised by a reentrancy attack, resulting in the theft of at least $287,000 worth of Ether "

https://cointelegraph.com/news/aave-earning-farm-protocol-targeted-by-reentrancy-attack-peckshield

"Uwerx Loses $327,000 To A Flash Loan Attack

A flash loan attack on August 2 cut Uwerx's successful launch celebration short. The attacker flash-loaned 20,000 ETH (approximately $36,726,400) and swapped it for 5,053,637 WERX."
https://www.theportugalnews.com/news/2023-08-12/uwerxs-road-to-redemption-overcoming-hurdles-after-successful-launch-due-to-hack/80409

UZD Stablecoin Plummets As Zunami Protocol Loses Over $2.1 Million To Exploit
https://www.ibtimes.com/uzd-stablecoin-plummets-zunami-protocol-loses-over-21-million-exploit-3708535



legendary
Activity: 1876
Merit: 1138
August 09, 2023, 07:44:39 AM
Solana-based decentralized exchange Cypher lost close to $1 million in crypto Monday due to an exploit or security incident.
The protocol’s contracts are now frozen as contributors attempt to make contact with hackers to negotiate a return of funds.
Cypher is one of the fastest-growing protocols on the solana blockchain in part because of its loyalty program, which rewards depositors and traders with points that many users expect is the setup for an airdrop.
The exploit comes during Cypher’s biannual hacker house mtnDAO which it hosts in Salt Lake City alongside fellow Solana trading protocol marginfi. In its discord channel, marginfi said it was not impacted by the hack.

https://www.coindesk.com/business/2023/08/07/solana-based-cypher-protocol-experiences-exploit-freezes-smart-contract/
legendary
Activity: 3192
Merit: 1509
August 06, 2023, 10:37:31 PM
Curve Offers Hackers 10% Bounty in Exchange for Return of Crypto

Curve Finance and other victims of this week’s crypto lending heist have offered their hackers a 10% bounty in exchange for the return of the rest of their tokens.

"You will have no risk of us pursuing this further, no risk of law enforcement issues, etc," Curve, Metronome and Alchemix wrote in an on-chain message sent to a hacker's Ethereum address. The trio gave a deadline of August 6 at 0800 UTC, at which point their bounty will become a vigilante payout to whomever provides information that leads to the hacker's arrest and conviction.

https://markets.businessinsider.com/news/currencies/curve-offers-hackers-10-bounty-in-exchange-for-return-of-crypto-1032514282

https://twitter.com/curvefinance/status/1687180381714358272?


News update. It appears that the hacker did not return the stolen funds to Curve Finance.

Curve is offering a $1.85 million bounty to anyone who can accurately identify the DeFi protocol's exploiter in a way that leads to definitive legal repercussions.

"The deadline for the voluntary return of funds in the Curve exploit passed at 0800 UTC," Curve publicly wrote in an Ethereum transaction's input data, adding: "We now extend the bounty to the public, and offer a reward valued at 10% of remaining exploited funds (currently $1.85M USD) to the person who is able to identify the exploiter in a way that leads to a conviction in the courts."


Source https://www.theblock.co/post/243464/curve-exploit-identity-bounty


However, he returned the funds of 2 DeFi protocols, Alchemix and Jpeg'd which he also sent a message telling eveyone that he was returning them because he was not scared, only returning them because he did not want to ruin the projects.

"I want to clarify that I'm refunding you not because you can find me, it's because I don't want to ruin your project," they explained in a transaction, adding: "Maybe it's a lot of money for a lot of people, but not for me, I'm smarter than all of you."

From the same news source.
legendary
Activity: 1876
Merit: 1138
August 05, 2023, 05:10:39 PM
Curve Offers Hackers 10% Bounty in Exchange for Return of Crypto

Curve Finance and other victims of this week’s crypto lending heist have offered their hackers a 10% bounty in exchange for the return of the rest of their tokens.

"You will have no risk of us pursuing this further, no risk of law enforcement issues, etc," Curve, Metronome and Alchemix wrote in an on-chain message sent to a hacker's Ethereum address. The trio gave a deadline of August 6 at 0800 UTC, at which point their bounty will become a vigilante payout to whomever provides information that leads to the hacker's arrest and conviction.

https://markets.businessinsider.com/news/currencies/curve-offers-hackers-10-bounty-in-exchange-for-return-of-crypto-1032514282

https://twitter.com/curvefinance/status/1687180381714358272?
legendary
Activity: 2016
Merit: 4765
August 02, 2023, 07:36:36 AM
https://beincrypto.com/kannagi-finance-zksync-era-rug-pull/

A Rocky Week for zkSync Era: EraLend Security Breach and Kannagi Finance Rug Pull


Kannagi Finance has walked away with $2.4 million worth of users' assets.
The incident is the first rug pull to affect the scaling solution zkSync Era.
It comes off the back of the $3.4 million hack EraLend suffered earlier.

"EraLend Loses $3.4M in Security Breach
On Tuesday, July 25, cyber attackers pilfered a staggering $3.4 million from EraLend, a lending platform operating on the zkSync Era. In the aftermath, the EraLend team promptly halted all activities.

A subsequent update revealed they had pinpointed a potentially involved crypto exchange account. Furthermore, they suspect that the culprits may have utilized a certain VPN provider to obscure their online tracks.

“We’ve pinpointed a suspicious CEX account that appears to be linked to an individual potentially involved in the incident. We are collaborating closely with the local police department, providing them with all relevant information,” said EraLend."
legendary
Activity: 2618
Merit: 1505
August 01, 2023, 04:06:26 AM
Curve Finance lost $52 million as a result of the hack, this was caused by the exploitation of several liquidity pools as a result of an error in smart contracts using versions 0.2.15, 0.2.16 and 0.3.0. XNUMX.

https://twitter.com/PeckShieldAlert/status/1685794015915229184
legendary
Activity: 2016
Merit: 4765
July 26, 2023, 05:34:21 AM
first ZKsync protocol

https://www.bitcoininsider.org/article/220933/era-lend-zksync-exploited-34m-reentrancy-attack
Era Lend on zkSync exploited for $3.4M in reentrancy attack

The lending app was drained of funds using a “read-only reentrancy” bug, a type of vulnerability that is often difficult for auditors to spot.

"Lending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract."
hero member
Activity: 868
Merit: 624
Buy on Amazon with Crypto
July 21, 2023, 09:04:55 AM
https://cointelegraph.com/news/eth-curve-omnipool-platform-conic-finance-hacked-for-3-2-million-in-eth

Curve omnipool platform Conic Finance hacked for $3.2 million in ETH
"According to initial analysis by Peckshield, the root cause for Conic Finance’s hack was the new CurveLPOracleV2 contract.

Conic Finance, a liquidity pool balancing platform for the decentralized finance (DeFi) protocol Curve, has suffered an exploit on the Ethereum omnipool.

Conic Finance has been exploited for $3.26 million in Ether, the Web3 risk-alert source Beosin Alert reported on July 21. Nearly the entire amount of stolen cryptocurrency was sent to a new Ethereum address in just one transaction, according to data provided by Beosin."

sad to see this and fortunately only Ethereum pool exploits and all other pools are safe. according to latest tweet, Conic team has fixed this pool issue now and all withdrawl can be done safely. They also claim that it not possible to exploit Ethereum mining pool gain.

hackers are in the search of finding any small door to enter and trying their best to steal fund. Dex projects should do many security audit to be safe and should close all doors for hackers.
legendary
Activity: 2016
Merit: 4765
July 21, 2023, 08:17:21 AM
https://cointelegraph.com/news/eth-curve-omnipool-platform-conic-finance-hacked-for-3-2-million-in-eth

Curve omnipool platform Conic Finance hacked for $3.2 million in ETH
"According to initial analysis by Peckshield, the root cause for Conic Finance’s hack was the new CurveLPOracleV2 contract.

Conic Finance, a liquidity pool balancing platform for the decentralized finance (DeFi) protocol Curve, has suffered an exploit on the Ethereum omnipool.

Conic Finance has been exploited for $3.26 million in Ether, the Web3 risk-alert source Beosin Alert reported on July 21. Nearly the entire amount of stolen cryptocurrency was sent to a new Ethereum address in just one transaction, according to data provided by Beosin."
legendary
Activity: 1876
Merit: 1138
July 19, 2023, 08:44:12 AM
Rodeo Finance Exploited For $888,000 In Another DeFi Hack on Arbitrum Network

Arbitrum Network-based Rodeo Finance lost 472 ether ($888,000) in a DeFi exploit today.

Blockchain security firm PeckShield revealed that the Rodeo Finance hacker transferred the stolen funds from Arbitrum to Ethereum.

Further analysis revealed that the attacker exchanged the stolen tokens for various other assets before converting them back to ether.

Hackers once again used Oracle manipulation technique to alter price feeds and exploit the platform out of nearly one million dollars worth of crypto.

https://cryptonews.com/news/arbitrum-based-rodeo-finance-exploited.htm
legendary
Activity: 2016
Merit: 4765
July 12, 2023, 08:13:18 AM
add
_____
https://cointelegraph.com/news/arcadia-finance-hacked-on-ethereum-and-optimism-for-455k
DeFi protocol Arcadia Finance hacked on Ethereum and Optimism for $455K
"A loophole in the code allowed the hacker to drain funds worth roughly $455,000 from Arcadia’s Ethereum and Optimism vaults.
A hacker drained approximately $455,000 from noncustodial decentralized finance (DeFi) protocol Arcadia Finance by exploiting a code vulnerability.

Blockchain investigator PeckShield alerted about the hack on Arcadia Finance, highlighting the cause as “the lack of untrusted input validation.” The code supposedly lacked a validation mechanism to cross-check unverified inputs. This loophole allowed the hacker to drain funds worth roughly $455,000 from Ethereum (darcWETH) and Optimism (darcUSDC) vaults."
member
Activity: 350
Merit: 21
Popkitty.io - Blockchain Social Media
July 08, 2023, 08:27:34 AM
Sometimes i seen somewhere the Defi hacks and finally i,m really satisfied about Defi hacking news from this post and best way to knowing as well always is better than others news.

It is very sad to read the series of events presented by zasad@ (OP). Of course there are many answers. we have to choose a good platform, store private keys to be safe and so on for let alone for ordinary people. If it's a disaster, even people who understand will also be affected if they have invested because it is safe at the start.

I think this is what a lot of people fear, saving then investing in crypto ends up being a tug of the rug and in vain. so, if this is the condition, who will be held responsible and blamed.
legendary
Activity: 3192
Merit: 1509
July 08, 2023, 03:07:48 AM
@zasad. I am quite shocked that the Multichain bridge was hacked 3 times. The second hack should have been very concerning already, I reckon. After this third hack, I shake my head. Everyone should start being skeptical about the developers and investigate. I also heard some stories that Multichain's CEO was arrested in China on May.

In any case, this is a list of all hacked DeFi bridges. It might be good to add for your list.

https://gist.github.com/cwhinfrey/9fd1bbc31bbcff08fca242b90c7f875d
legendary
Activity: 2016
Merit: 4765
July 07, 2023, 05:57:58 AM
https://www.ibtimes.com/crypto-cons-this-week-multichain-fantom-bridge-loses-126m-aptos-network-compromised-airdrop-scam-3703896
Crypto Cons This Week: Multichain Fantom Bridge Loses $126M, Aptos Network Compromised By Airdrop Scam
"Multichain Fantom bridge lost $126M in WBTC, USDC, DAI, wETH, and Link from the exploit
The official Twitter accounts of the Aptos Network and that of its CEO were hacked on Friday
The hacked accounts posted details about a fraudulent airdrop

The Fantom bridge was looted of funds, approximately around $126 million consisting of crypto assets like WBTC, USDC, DAI, wETH, and Link.

The bad actors siphoned $30.9 million in WBTC, $13.6 million in wETH, and $57 million in USDC from the said bridge."
Pages:
Jump to: