Skip to main content

Hackers steal $8 million worth of cryptocurrencies from DeFi Protocol bZx

 


  • The hackers stole over $8 million worth of crypto funds due to a vulnerability found in the bZx system.
  • The bZx protocol suffered its first attack this year, as a hacker siphoned $1 million from the system.
  • In each of the first attacks, the hacker used different methods to steal funds from the Defi lending protocol.

Hackers were able to infiltrate the DeFi lending protocol bZx and stole more than $8 million worth of cryptocurrencies. This is not the first time the DeFi protocol has been attacked this year.

This time, the hackers were 8 times more potent than the previous attack on the margin and leverage-based trading and lending platform. The hackers leveraged a duplication vulnerability that gave them access to siphon USDCUSDTETH, and LINK, with a combined worth of over $8 million.

Anton Bukov, a team member of the bZx group shared a thread on Twitter to admit that the firm was hit by another attack. He also said the hacking was initiated due to the fault in the line of code for a smart contract. The hacking was successful after the hackers initiated the iToken transactions to siphon ETH.

How the attack occurred

When researchers delved deeper to find out how the hackers were able to infiltrate the DeFi protocol again, the report showed that there was a vulnerability in the “transferfrom0 protocol”, which allowed the successful transfer of ERC20 between protocols.

This made it easier to initiate the function when creating and transferring the iToken, giving the hackers the avenue to increase their balance. The hackers were able to initiate a transfer function using the same form & to address of the main function. Immediately after that, they used an InternalTransferFrom function with a single argument, allowing the lines to code faulty.

Subsequently, the hackers were able to increase the balance of –balancesTo while reducing the –balancesFrom, based on the report. After stealing $8 million from the DeFi protocol, the bZx hackers immediately patched the faulty code. After code coding companies Peckshield and Certik approved, the DeFi lending protocol decided to patch the code.

This is not the first time bZx has been attacked

With this recent spate of attacks, it seems bZx is facing a hard time this year. Based on an earlier report, a hacker successfully stole $1 million worth of ETH from the portal in two successful attempts in February.

In the first attack that occurred on February 14, the hacker made use of different methods in the attacks. First, the hacker took 10,000 ETH from dYdX and took a 112 wBTC loan on compound using 5,500 ETH.

In the second attack, which occurred four days later, the attacker drained the system off $600,000 by leveraging ‘oracle manipulation’ to cheat the system.

Source: invezz.com

Comments

Contact us

Name

Email *

Message *

Popular posts from this blog

Cryptocurrencies Adding to the Safety and Security in the UK Gambling Industry

These are exciting times for the UK gambling industry. The impact of internet technology is now being felt with online gambling now controlling the industry.  The adoption of cutting-edge technology is reasonable for the boom in the industry. From live casinos, mobile apps to artificial intelligence, incredible trends continue shaping the gambling industry. However, it is the rise of cryptocurrency casinos that seeks to redefine UK gambling.  Many operators now include crypto coins such as bitcoin, Ethereum and Litecoin as part of their banking methods. Others offer exclusive bitcoin payments and promotions based on digital tokens. This revolutionary trend has a huge impact due to enhanced safety and security on these platforms. Players looking for peace of mind when playing online now opt to use cryptocurrencies. This post looks at how cryptos guarantee the safety and security of players at online casinos. How Cryptocurrency Gambling Works There’s a lot of talk ab...

Coinbase to Require Recipient Information for Crypto Transfers From Users in Canada, Singapore and Japan

  Customers in those countries who send crypto outside their Coinbase accounts must provide recipients’ names, addresses and in some cases, additional information, as of early April. Cryptocurrency exchange Coinbase Global (COIN) will soon require its customers in Canada, Japan and Singapore who send cryptocurrency to another financial institution or exchange to provide the name, address and in the case of Japan, the destination wallet of the recipient. Coinbase has been sending notices to its customers in those countries that the changes will take effect in early April in order to comply with local travel rules in those places. Coinbase didn't immediately respond to requests for additional comment on the moves, but confirmed that they were taking place. The move  does not seem to be going over well  with Coinbase customers in those countries, who value the anonymity of transactions using cryptocurrency. According to a  FAQ provided by Coinbase , for Canadian users, ...

Quomodocunquize

                                       Definition:  " To make money in any way possible . ” Example:  Rather than quomodocunquizing,  invest your money wisely . Please, please, please use a hardware cold wallet like Ledger . It's  a  cold wallet ,  cold  =  not exposed  to  internet  =  only your hardware device . ...  Use Ledger  as  cold storage . Too many people spend money they earned..to buy things they don't want..to impress people that they don't like. --Will Rogers A wise person should have money in their head, but not in their heart. --Jonathan Swift Wealth consists not in having great possessions, but in having few wants. --Epictetus Money often costs too much. --Ralph Waldo Emerson Everyday is a bank account, and time is our currency. No one is rich, no one is poor, we've got 24 hours each. --Christopher...