The attacker got a $23 million flash loan of ETH from dYdX, converted it to WETH, and started swapping WETH to STA back and forth — they repeated this 24 times. This allowed them to drain the STA balance in the pool all the way to 0.000000000000000001 STA as 1% transaction fee was subtracted on each trade. The STA balance was close to zero, which allowed the attacker to swap it for other assets in the pool very cheaply.
The attacker drained 601.3 ETH (~$134.8k), 11.36 WBTC (~$103.5k), 22,593 LINK (~$102.8k), and 60,915 SNX (~$110.9k). In total, the attacker got access to about $452,000.
DEX Aggregator 1inch said in their writeup that the attacker was “very sophisticated smart contract engineer with extensive knowledge and understanding of the leading DeFi protocols.” The ETH that was used to deploy the smart contracts was mixed through Tornado Cash to hide the source.
Balancer said that they were not aware this specific type of attack was possible but allegedly warned about the unintended effects of deflationary tokens with transfer fees. It vouched to begin adding deflationary tokens to the UI blacklist similarly to what they have already done for no bool transfer tokens. The protocol added that it has already undergone two full audits and has had a third one planned.
This is the fifth high-profile attack on Open Finance protocols. The first two happened on February 15 as attackers drained the lending protocol bZx of more than $1 million. In April, the dForce protocol was drained of $25 million but the entire amount was returned by the attacker for still unknown reasons.
The Block Research was commissioned by Forte to create “Blockchain-Based Gaming: A Primer” which provides a comprehensive introduction to how blockchain technology is being employed in video gaming experiences.
“It’s a global development.” On this episode of The Scoop, 10T Founder and CEO Dan Tapiero joined host Frank Chaparro to discuss his insights into the globalization of crypto markets and how his macro investing strategy has seen his fund 10T pour hundreds of millions into crypto unicorns. To date, Tapiero has already allocated the […]
The U.S. Securities and Exchange Commission is said to be allowing the first Bitcoin futures exchange-traded fund (ETF), per a Bloomberg report. The publication said in a report on Thursday night that the U.S. regulator “isn’t likely to block the products from starting to trade next week,” citing people familiar with the matter. The report […]