Defi Protocol That Bragged About Having Flash Loan Attack Prevention Hacked for $6 Million

Defi Protocol That Bragged About Having Flash Loan Attack Prevention Hacked for $6 Million
фото показано с : news.bitcoin.com

2020-11-17 13:03

A decentralized finance (defi) protocol that bragged about having flash loan attack prevention has been exploited for $6 million in DAI, in a flash loan attack.

Value Defi, a yield aggregating protocol, boasted of having the “highest security” in a Nov. 13 tweet that now appears to have been deleted. The protocol claimed that its technology was capable of preventing flash loan attacks.

Hardly a day later, hackers plundered Value Defi’s multi-stablecoin vault of a total of $8 million of the stablecoin DAI. The attacker returned $2 million to the protocol and pocketed $6 million — and with it left one audacious message stating, “do you really know flashloan?”

Value Defi said it suffered a “complex attack that resulted in a net loss of $6 million.”

The hacker took out a loan of 80,000 ether from the defi lending platform Aave and also borrowed an additional $116 million in DAI from Uniswap. According to Value Defi’s postmortem of the incident, the attacker swapped the ETH loan for stablecoins and deposited part of the flash-loaned DAI into the protocol’s vault.

He then made a series of stablecoin swaps involving USDT, USDC, and DAI — a technique that eventually exploits Value Defi’s vault withdrawal method. Aave developer Emiliano Bonassi exclaimed:

This is the complex exploit I’ve ever seen. It used two flashloans.

Flash loans allow users to borrow money without collateral because the lender expects the funds to be returned within one transaction block, almost immediately. Hackers have used this loophole in defi to steal millions of dollars.

In its postmortem, Value Defi said it was looking at ways to compensate affected users. It stated that users can claim 20% in DAI from the $2 million that was returned by the hackers. The protocol is also hiking transaction fees to generate income for compensation.

“We will create a compensation fund which will be funded by a combination of the dev fund, insurance fund and a portion of the fees that are currently generated by the protocol,” it explained.

The price of Value Defi’s native token, value liquidity, plunged as much as 28% on the day of the attack to $1.99 from $2.76, according to Coingecko data. At press time, the token was trading at $2.05, down 4.9% in 24 hours.

This latest exploit comes just two days after another $2 million heist at defi lending protocol Akropolis.

What do you think about the frequency of flash loan attacks in the defi industry? Let us know in the comments section below.

The post Defi Protocol That Bragged About Having Flash Loan Attack Prevention Hacked for $6 Million appeared first on Bitcoin News.

Similar to Notcoin - Blum - Airdrops In 2024

origin »

BlockMason Credit Protocol (BCPT) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.04 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Цена в час новости $ 0.0195725 (-100%)

flash loan defi having attack protocol million

flash loan → Результатов: 31


Flash Loans - Mapping the esoteric landscape of DeFi

Andy talks with self-described ‘flash loans maximalist’ Stani Kulechov, founder and CEO of the Aave Protocol. We explore the exotic and esoteric landscape of Decentralized Finance. Against the backdrop of the recent DeFi exploits, we discuss the new flash loan innovation that allows traders to take out a loan without collateral by paying back the loan in the same smart contract transaction.

2020-2-27 12:30


Фото:

Hacker Makes $360,000 ETH From a Flash Loan Single Transaction Involving Fulcrum, Compound, DyDx and Uniswap

From nothing, $360,000 has gone into the pocket of someone in seven steps. One, get out a flashloan for 10,000 eth (worth about $3 million) from trading platform DyDx. Send... The post Hacker Makes $360,000 ETH From a Flash Loan Single Transaction Involving Fulcrum, Compound, DyDx and Uniswap appeared first on Trustnodes.

2020-2-16 19:31