Hackers Drain DeFi Protocol Harvest Finance of $24 Million

2020-10-26 10:44

A $24 million DeFi hack involving Harvest Finance has exposed the vulnerability of the entire DeFi ecosystem. 

Economic Exploit of Harvest Finance

Working as a yield aggregator, Harvest Finance provides liquidity to other DeFi pools to obtain gains for its liquidity providers (LPs). Hackers allegedly leveraged this mechanism in Curve’s Y pool for their attack.

The economic attack was performed through the curve y pool, stretching the price of the stablecoins in Curve out of proportion and depositing and withdrawing a large amount of assets through harvest.

To protect users, we've pulled y pool and btc curve strategy funds to the vault

— Harvest Finance (@harvest_finance) October 26, 2020

Reportedly, arbitrage manipulation using a $50 million flash loan enabled the attackers to stretch the price of the stablecoins on Curve’s Y pool. The hackers then used the stablecoin and BTC pools on Harvest Finance to obtain a greater amount of stablecoins in exchange for the highly-priced tokens on Curve. 

In less than seven minutes, the attackers drained $24 million from Harvests’ liquidity. 

The total volume of trading on Curve’s USDT and USDC shot from $10 million to over $2.7 billion during the exploit. 

The nature of the attack has been discussed in detail in the academic paper by researchers from Imperial College London (ICL). It outlines how to use flash loans to manipulate the price of token pairs and drain liquidity from DeFi pools. 

A New DeFi Hack, Every Day 

There is a stark similarity between the Harvest Finance hack with a previous $15 million DeFi attack on Eminence in that the attackers returned a portion to the lead developer’s address. 

While it was 50% of the amount with Eminence, this time, Harvest hackers sent back 10% of the total hack to the ETH deployer address. This raises suspicions around a signature move by a single entity or a trend adopted by developers. 

“The attacker” sent some funds back because they’re such nice people. If this isn’t strong evidence that “the attacker” and “the devs” are the same then I don’t know what is. https://t.co/lNcE2DkcA6

— Riccardo Spagni (@fluffypony) October 26, 2020

As reported earlier, the anonymous developers of Harvest Finance have raised several red flags. The anonymity in DeFi is also adding to the developer’s advantage, who goes untraced and richer in crypto money from the hacks. 

Similar to Notcoin - Blum - Airdrops In 2024

origin »

BlockMason Credit Protocol (BCPT) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.04 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Цена в час новости $ 0.018279 (-100%)

million finance harvest drain defi protocol hackers

million finance → Результатов: 126


Фото:

DeFi project Harvest Finance loses $24 million to hackers

By now, everyone knows that the DeFi sector has been the center of the attention of the crypto industry in 2020. The sector has grown by billions and billions of dollars in only a few months. However, just like it started attracting new users and investors, as well as their money — it also started attracting hackers interested in stealing that money.

2020-10-26 12:15


Фото:

Boringdao Raises $1.4M: Project’s Tokenized BTC Bridge Backed by 200% Collateral

There’s a new tokenized bitcoin project coming to the decentralized finance (defi) ecosystem that’s recently received $1. 4 million from blockchain investors. The project called Boringdao, a decentralized bridge between Ethereum and alternative blockchains, plans to launch the company’s bBTC tunnel this month in order to introduce another tokenized bitcoin.

2020-10-10 05:00


Фото:

Cumulative Ethereum Transaction Fees in 2020 Supersede Bitcoin’s by a Long Shot

This week the research and analysis team Coin Metrics published a report on how decentralized finance (defi) is “fueling Ethereum’s growth. ” Meanwhile, the researchers also highlighted that Ethereum’s cumulative transaction fees in 2020 are now over $350 million and more than double the aggregated total of Bitcoin’s network fees.

2020-9-30 10:30


YFI Founder Andre Cronje ‘Still Building’ the DeFi Project that Got Hacked for $16 Million

Amidst the craze and shift toward non-fungible tokens (NFT), DeFi sweetheart yEarn’s founder Andre Cronje’s latest project saw rug pulled on $16 million. The project was Eminence Finance (EMN), an unreleased and unfinished gaming multiverse project whose smart contracts were deployed last night but without any announcement.

2020-9-29 17:47


NFT Sales Heat Up as Rarible Marketplace Passes $5M in Volume

While decentralized finance (DeFi) has grabbed most of the recent headlines, the non-fungible token (NFT) market has quietly picked up steam over the summer.   According to a Sept. 16 report from crypto asset data website Messari, Rarible, an NFT marketplace, has passed $5 million in sales so far this month—more than quadrupling sales numbers from August.

2020-9-23 17:09


Decentralized Exchange Aggregator, ParaSwap, Raises $2.7M to Streamline DeFi Token Swaps

France-based decentralized exchange aggregator, ParaSwap, raises $2. 7 million in a seed funding round from some of the top investors across the crypto ecosystem. The funding is set to boost API integration and development in a bid to enhance the building of decentralized finance (DeFi) applications.

2020-9-17 18:58