• Contact Us
  • Privacy Policy
Wednesday, January 27, 2021
CRYPTO NEWS TIPS
No Result
View All Result
  • Home
  • Latest News
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
    • Litecoin
    • Altcoin
  • Live Cryptocurrency Prices
  • Analysis
  • Blockchain
  • Regulation
  • Trading
  • Home
  • Latest News
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
    • Litecoin
    • Altcoin
  • Live Cryptocurrency Prices
  • Analysis
  • Blockchain
  • Regulation
  • Trading
No Result
View All Result
CRYPTO NEWS TIPS
No Result
View All Result
Home Regulation

DeFi Protocol bZx Loses $8 Million in Third Exploit

Crypto News Tips by Crypto News Tips
September 14, 2020
in Regulation
0
Charles Hoskinson: Upcoming Cardano Update Will Provide Substantial Improvements

Decentralized finance (DeFi) lending protocol bZx has suffered a third exploit, and this time the attackers got over $8 million in cryptocurrency by duplicating assets.

The exploit, according to the bZx team, allowed the attackers to use flawed code to duplicate assets or increase their balance of interest-bearing tokens on bZx, dubbed iTokens. After noticing the exploit, bZx halted minting and burning of the tokens, and resumed it after a fix corrected the balances.

The bug, however, saw the attacker mint 2139,199.66 LINK, 4,500.7 ETH, 1.75 million USDT, 1.41 million USDC, and 667,988.8 DAI. In total, the attacker managed to get over $8 million with the attack. The firm’s insurance fund will be covering the losses, so no user funds were at risk.

In its report bZx details it was “heavily audited” by top security firms Peckshield and Certik. It added:

Unfortunately, audits are not silver bullets. Our protocol is the most powerful, fully functioned lending protocol in the space, and this means that there is a lot of code to cover.

Reacting to the incident Certik revealed that during the audits “several issues were identified and remediated,” and added the vulnerability was the result of a “gas optimization being applied on the common ERC balance transfer code whereby data was copied to memory and subsequently reused while having been altered in storage.” To the firm, “security is a journey” and its team is committed to collaborating with bZx further.




Peckshield reacted by pointing out its audits also uncovered “several issues” that were fixed. It added that one audited “cannot guarantee to find all potential issues.” Marc Thalen, the lead engineer at Bitcoin.com, found the exploit and claimed over $20 million were at risk.

1/4 Last night I found an exploit in BRZX. I noticed that a user were capable of duplicating “i tokens”. There was 20+ million $ at risk. I informed the team telling them to stop the protocol and explained the exploit to them. At this point none of the founders were up.. pic.twitter.com/MdJqOH2IPu

— Marc Thalen (@MarcThalen) September 14, 2020

In a tweet thread, Thalen detailed he informed the team about the exploit, and used it with a loan using 100 USDC that allowed him to retrieve iUSDC, which he sent to himself to practically duplicate the funds.

Per Thalen, if bZx did not pause the contract, the attacker would have likely been able to get all $20 million. One of the protocol’s founders reportedly said an independent security panel recommended a $12,500 bounty for his contribution, although the platform’s program mentions a reward up to $350,000 for a critical vulnerability.

It’s worth noting that earlier this year bZx was exploited using flash loans that saw attackers make nearly $1 million in ETH over the course of two attacks. Flash loans are loans taken and repaid in a single transaction.

Featured image via Pixabay.


Credit: Source link

Share234Tweet146
Crypto News Tips

Crypto News Tips

Related Posts

Bitcoin Surpasses Berkshire Hathaway’s Market Cap at $540 Billion
Regulation

Wall Street Bear Says Bitcoin Cannot Be Ignored: Predicts Stock Market Crash

January 27, 2021
A Slightly Stronger Dollar Halts Bitcoin, but Long-Term Outlook Remains Unchanged
Regulation

Bitcoin Market Update for 27 Jan 2021: Price Analysis, ETF, Miners

January 27, 2021
Peter Schiff Denies Companies Selling Gold for Bitcoin
Regulation

$220 Million in Satoshi-Era Bitcoin Moved in Last 10 Months: Report

January 27, 2021
Fidelity Digital To Offer Bitcoin-Backed Cash Loans to Institutional Customers
Regulation

Rothschild Investment Corporation Raises Bitcoin Exposure to $1 Million via GBTC

January 26, 2021
Top-Tier Cryptocurrency Exchanges Dominated Trading Volumes in August: Report
Regulation

MVIS CryptoCompare Indices Surpass $1 Billion in AUM as Crypto Demand Keeps Growing

January 26, 2021
ARK Investment Management CEO on Bitcoin: ‘We Are Extremely Bullish’
Regulation

ARK Invest CEO Cathie Wood: ‘No Better Hedge Against Inflation Than Bitcoin’

January 26, 2021
Load More
Next Post
All You Need to Know About DeFi’s SushiSwap Saga (But Were Afraid to Ask)

All You Need to Know About DeFi's SushiSwap Saga (But Were Afraid to Ask)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Abuse and Ethical Lapses: What Happened When Justin Sun Acquired BitTorrent

Abuse and Ethical Lapses: What Happened When Justin Sun Acquired BitTorrent

October 9, 2020
Why This Finance Author Advocates Bitcoin Over Gold and Real Estate

Why This Finance Author Advocates Bitcoin Over Gold and Real Estate

July 10, 2020

Don't miss it

GameStop’s Short Squeeze Is Far More Than Just Retail Noise
Analysis

GameStop’s Short Squeeze Is Far More Than Just Retail Noise

January 27, 2021
Bitcoin Surpasses Berkshire Hathaway’s Market Cap at $540 Billion
Regulation

Wall Street Bear Says Bitcoin Cannot Be Ignored: Predicts Stock Market Crash

January 27, 2021
A Slightly Stronger Dollar Halts Bitcoin, but Long-Term Outlook Remains Unchanged
Regulation

Bitcoin Market Update for 27 Jan 2021: Price Analysis, ETF, Miners

January 27, 2021
Severe Downside Risks for Bitcoin on Bearish ‘Death Cross’ Appearance
Bitcoin

Severe Downside Risks for Bitcoin on Bearish ‘Death Cross’ Appearance

January 27, 2021
Bitcoin Dips on Stronger Dollar Sentiment; Boost Ahead After Fed Meeting?
Bitcoin

Bitcoin Dips on Stronger Dollar Sentiment; Boost Ahead After Fed Meeting?

January 27, 2021
Peter Schiff Denies Companies Selling Gold for Bitcoin
Regulation

$220 Million in Satoshi-Era Bitcoin Moved in Last 10 Months: Report

January 27, 2021
  • Contact Us
  • Privacy Policy
Call us: +1 234 JEG THEME

© 2021 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Home
  • Latest News
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
    • Litecoin
    • Altcoin
  • Live Cryptocurrency Prices
  • Analysis
  • Blockchain
  • Regulation
  • Trading

© 2021 JNews - Premium WordPress news & magazine theme by Jegtheme.