diff --git a/_posts/2022-11-14-deribit-hot-wallet.md b/_posts/2022-11-14-deribit-hot-wallet.md new file mode 100644 index 0000000..472d8b8 --- /dev/null +++ b/_posts/2022-11-14-deribit-hot-wallet.md @@ -0,0 +1,11 @@ +--- +layout: post +title: Deribit Hot Wallet +date: 2022-11-01 23:59 -0800 +categories: server_hot_wallet_breach +link: https://twitter.com/DeribitExchange/status/1587701883778523136 +--- +Hot wallet compromised, accounting to $28M in losses + +> Deribit hot wallet compromised, but client funds are safe and loss is covered by company reserves. Our hot wallet was hacked for USD 28m earlier this evening just before midnight UTC on 1 November 2022. +> Client assets, Fireblocks or any of the cold storage addresses are not affected. It's company procedure to keep 99% of our user funds in cold storage to limit the impact of these type of events. The hack is isolated & quarantined to our BTC, ETH and USDC hot wallets. \ No newline at end of file diff --git a/_posts/2022-11-14-lightning-consensus-bug.md b/_posts/2022-11-14-lightning-consensus-bug.md new file mode 100644 index 0000000..6e1e72d --- /dev/null +++ b/_posts/2022-11-14-lightning-consensus-bug.md @@ -0,0 +1,15 @@ +--- +layout: post +title: Lightning Network Consensus Bug +date: 2022-11-01 10:44 -0800 +categories: +- protocol_vulnerability +link: https://github.com/btcsuite/btcd/issues/1906 +--- +Consensus conflict between btcd and core. + +> I owe this statement to the community: 1. I love breaking things 2. I broke LND for fun and will break it again if I can 3. I’m not sponsored by @Blockstream 4. I ❤️ @roasbeef @RyanTheGentry @sputn1ck 5. I’m in favor of multiple implementations 6. OP_RETURN was for trolling + +- [Rogue Actor Disrupts Lightning Network With a Single Transaction](https://www.coindesk.com/tech/2022/11/02/rogue-actor-disrupts-lightning-network-with-a-single-transaction) +- [Exploit TX](https://blockstream.info/tx/73be398c4bdc43709db7398106609eea2a7841aaf3a4fa2000dc18184faa2a7e) +- [Twitter thread by hacker](https://twitter.com/brqgoo/status/1587397646125260802) \ No newline at end of file diff --git a/_posts/2022-11-14-rubik-wallet.md b/_posts/2022-11-14-rubik-wallet.md new file mode 100644 index 0000000..d1fd745 --- /dev/null +++ b/_posts/2022-11-14-rubik-wallet.md @@ -0,0 +1,15 @@ +--- +layout: post +title: Rubik Wallet +date: 2022-11-02 01:47 -0800 +categories: cold_storage +link: https://twitter.com/CryptoRubic/status/1587704890800889858 +--- +(Alleged) cold wallet exploit on Rubik's admin wallet resulting in $212k lost. + +> Rubicans, One of our admin’s wallet addresses was compromised. This wallet managed the RBC/BRBC bridge and staking rewards. We suspect it was malicious software that was used to get access to the admin wallet's private keys. +> Around 34M of RBC/BRBC were sold on Uniswap and PancakeSwap. + + +- [Exploit TX](https://etherscan.io/tx/0x75cade00bc191f059826aa77fe5104bccea622b0f4c844147cdb3d64cacee4e3) +- [Hacker Address](https://etherscan.io/address/0xD2D113d7b5c4F8FB4A68cEDa26F894F0fE25F24a) \ No newline at end of file diff --git a/_posts/2022-11-14-skyward-finance.md b/_posts/2022-11-14-skyward-finance.md new file mode 100644 index 0000000..c6a9194 --- /dev/null +++ b/_posts/2022-11-14-skyward-finance.md @@ -0,0 +1,13 @@ +--- +layout: post +title: Skyward Finance +date: 2022-11-01 05:04 -0800 +categories: smart_contract +link: https://twitter.com/BlockSecTeam/status/1587998109648683010 +--- +Insufficient parameter validation. $3.2M lost. Smart contracts in Near blockchain. + +> The root cause is in function redeem_skyward (https://github.com/skyward-finance/contracts/blob/master/skyward/src/treasury.rs#L158), which is used to redeem the treasury from the protocol. +> However, the function does not check whether the provided token_account_ids are duplicated. In this case, the attacker is able to redeem the treasury tokens multiple times with the same skyward share withdrawn once. + +- [Exploit TX](https://explorer.near.org/transactions/92Gq7zehKPwSSnpoZ7LGGtSmgmBb4wP2XNDVJqUZRGqz) \ No newline at end of file diff --git a/_posts/2022-11-14-solend-oracle-manipulation.md b/_posts/2022-11-14-solend-oracle-manipulation.md new file mode 100644 index 0000000..471966d --- /dev/null +++ b/_posts/2022-11-14-solend-oracle-manipulation.md @@ -0,0 +1,11 @@ +--- +layout: post +title: Solend Price Manipulation +date: 2022-11-02 00:00 -0800 +categories: smart_contract +link: https://twitter.com/solendprotocol/status/1587671511137398784 +--- +Price oracle manipulation attack in Solana lending protocol. Resulted in $1.26M in bad debt. + +> An oracle attack on USDH affecting the Stable, Coin98, and Kamino isolated pools was detected, resulting in $1.26M in bad debt. All other pools including the Main pool are safe. +> Note that the attack did not involve Pyth. diff --git a/_posts/2022-11-14-vecrv-brive-v2.md b/_posts/2022-11-14-vecrv-brive-v2.md new file mode 100644 index 0000000..9f69c0b --- /dev/null +++ b/_posts/2022-11-14-vecrv-brive-v2.md @@ -0,0 +1,18 @@ +--- +layout: post +title: veCRV Brive V2 +date: 2022-10-27 06:45 -0800 +categories: smart_contract +link: https://github.com/yearn/yearn-security/blob/master/disclosures/2022-11-01.md +--- +Reward manipulation logic error. + +> Disclaimer: The Yearn team did not write or deploy the original BribeV2 contract. However, as a heavy user of it, decided to act quickly to deploy a new contract so that operations could resume. +> During a routine check, irregularities were discovered in the amount of SPELL bribes being claimed by some users of the BribeV2 contract. Following analysis, it was determined to be an attacker exploiting a flaw in the way the contract calculates bribe allocations. +> The flaw causes bribes to be allocated based on each user's locked amount of CRV rather than allocating based on their veCRV balance. +> The attacker was found to have exploited this since September 2021, tricking the contract into awarding them higher allocations than they should deserve for the actual weight they contributed to a gauge. +> Other BribeV2 users were unknowingly subject to faulty bribe calculations due to the fact that lock time was not taken into account. +> Yearn developers patched the vulnerability and deployed a new version of the contract (yBribe) which properly allocates bribes to users. + +- [Yearn's Bilateral Responsible Disclosure Agreements](https://github.com/yearn/yearn-security/blob/master/SECURITY.md#bilateral-responsible-disclosure-agreements) +- [Suspect TX](https://etherscan.io/tx/0x47e10eebda1b9afbabe622d3deece757d6d49a0510081635fc7dc21efe50aeeb) \ No newline at end of file diff --git a/_posts/2022-11-15-contract-0xf8f8.md b/_posts/2022-11-15-contract-0xf8f8.md new file mode 100644 index 0000000..73f86c7 --- /dev/null +++ b/_posts/2022-11-15-contract-0xf8f8.md @@ -0,0 +1,17 @@ +--- +layout: post +title: Smart Contract 0xf8f8 +date: 2022-11-05 02:01 -0800 +categories: +- smart_contract +link: https://twitter.com/AnciliaInc/status/1588727453815492611 +--- +Insufficent access control. $100k lost in smart contract deployed in Binance Smart Chain + +> Seems contract https://bscscan.com/address/0xf8f8925e96f1abe977fe3d096bf935d9da7d879c has been attacked. There are a lots of wallets have granted allowance to contract 0xf8f8. Please revoke the allowance! Attacker has been moving out multiple tokens from 0xf8f8. +> There are two tx related to this attack: https://bscscan.com//tx/0x0a969282f3659d56dfda335122b5fa76b51efe2617bb45cb55cabe8f9abaf0ad https://bscscan.com//tx/0xcd0a3708f16e29f09b6056e1f74de44c815ba3c34a359c9bd43112df1c67ed4a contract 0xf8f8 does not have permission check and it relies on user input. Attacker could just call the vulnerable function in f8f8 many times to move user's token out. +> 4/ the attacker started to move money to Tornado. :( + +- [Contract Address](https://bscscan.com/address/0xf8f8925e96f1abe977fe3d096bf935d9da7d879c) +- [Attacker Address](https://bscscan.com/address/0x656887a96b6e462c48ac37da32855e9d3f4a6bed) +- [Suspect TX](https://bscscan.com//tx/0x0a969282f3659d56dfda335122b5fa76b51efe2617bb45cb55cabe8f9abaf0ad) \ No newline at end of file diff --git a/_posts/2022-11-15-gate-hot-wallet.md b/_posts/2022-11-15-gate-hot-wallet.md new file mode 100644 index 0000000..768045d --- /dev/null +++ b/_posts/2022-11-15-gate-hot-wallet.md @@ -0,0 +1,14 @@ +--- +layout: post +title: Gate Hot Wallet +date: 2018-04-21 00:00 -0700 +categories: +- server_hot_wallet_breach +link: https://twitter.com/1A1zP1/status/1591911832809349120 +--- +Unauthorized access to private keys. $234M stolen, allegedly, by North Korea. Gate kept it hidden to the public. + +> You talk about the importance of security but how about you finally disclose @gate_io was quietly hacked by NK for $230m on April 21 2018 & how you actively kept this hidden from customers/public +> If you go to the DOJ press release, one of the addresses listed is 0xc49 which is a deposit address for Bittrex. Two hope away from it is an address that received 31,600 ETH on April 21 2018 from the Old @gate_io hot wallet 0x05e. + +- [zachxbt thread](https://twitter.com/zachxbt/status/1592337921922994177) diff --git a/_posts/2022-11-15-loopring-ddos.md b/_posts/2022-11-15-loopring-ddos.md new file mode 100644 index 0000000..fc80237 --- /dev/null +++ b/_posts/2022-11-15-loopring-ddos.md @@ -0,0 +1,15 @@ +--- +layout: post +title: Loopring DDoS +date: 2022-11-04 21:00 -0800 +categories: +- cloud_infrastructure_breach +link: https://loopring.org/#/post/loopring-ddos-attack-post-mortem +--- +DDoS attack on Loopring L2 chain. The Loopring gateway on AWS was targeted. + +> On November 4 (GMT+8) at 21:00 hrs Loopring was targeted with an aggressive DDoS attack. During the incident, the rate per second (RPS) was significantly increased. The Loopring gateway was unable to handle such an overwhelming volume of requests resulting in the unavailability of the services. +> 22:07 Nov 4th Loopring contacted AWS security engineers for additional support. +> This DDoS attack only prevented Loopring from providing external services; it had no impact on the security of assets on Loopring. During the attack, the Loopring relayer continued to generate ZKP blocks and submitted them to the Ethereum blockchain. +> This event served as a good reminder to devote additional resources and layers of protection by leveraging AWS services. Loopring, in coordination with AWS, will implement a more robust security architecture for future challenges. +> The majority of Loopring's external services are built on AWS. Loopring will leverage AWS's security capability to better mitigate future potential security threats. Following this incident, Loopring will work more closely with AWS to identify risks and deploy improved shielding and protection, ensuring that our customers receive a robust service. \ No newline at end of file diff --git a/_posts/2022-11-15-moocake.md b/_posts/2022-11-15-moocake.md new file mode 100644 index 0000000..8f0b49e --- /dev/null +++ b/_posts/2022-11-15-moocake.md @@ -0,0 +1,15 @@ +--- +layout: post +title: Moo Cake smart contract +date: 2022-11-06 09:30 -0800 +categories: +- smart_contract +link: https://twitter.com/BeosinAlert/status/1589501207181393920 +--- +Insufficent access control via a flash loan. $140k lost. Smart contract in Binance Smart Chain. + +> Beosin EagleEye monitored a flashloan attack on MooCakeCTX contract. The loss is ~$140K. There is no time restrictions on collateral and rewards, and the prevention of caller is not comprehensive enough, enabling the attacker to increase dividends via flashloan. +> The attacker executed two more attacks and returned the flashloan with a profit of 424 $BNB (~ $140,000). +> Suggestion: When developing contracts, pay attention to flashloan attack scenario, the security of the way rewards are issued, and the secure use of library functions. + +- [Suspect TX](https://bscscan.com/tx/0x03d363462519029cf9a544d44046cad0c7e64c5fb1f2adf5dd5438a9a0d2ec8e) \ No newline at end of file diff --git a/_posts/2022-11-15-pando-rings.md b/_posts/2022-11-15-pando-rings.md new file mode 100644 index 0000000..4793d28 --- /dev/null +++ b/_posts/2022-11-15-pando-rings.md @@ -0,0 +1,16 @@ +--- +layout: post +title: Pando Rings +date: 2022-11-05 07:19 -0800 +categories: +- smart_contract +link: https://pando.im/news/2022/2022-11-06-alert-to-pando-community-hack-of-pando-rings/ +--- +Price oracle manipulation. $21.8M assets stolen. + +> Pando Rings suffered from a hack yesterday on November 5th, 2022. The attacker exploited a vulnerability in Pando Rings price oracle and manipulated the price of sBTC-WBTC (liquidity provider token of the trading pair BTC-WBTC on 4swap) to attempt a theft of approximately $70 million worth of crypto assets. +> $21,877,098.03 worth of crypto assets including ETH, EOS and BTC were unfortunately transferred out from the attacker's two perpetrating Mixin wallets before measures could be taken. Though fortunately, among the transferred funds, Pando team was able to get support and assistance from our community and the transferred 2,022,662.9979 EOS (valuing at approximately $2,362,761.24) has now been frozen. +> And for the larger rest of the hacked funds (approximately at the value of $50 million) that are still in the hacker's wallets, we took as promptly measures as could be done, got assistance from Mixin Network and have had the funds frozen + +- [Twitter Announcement](https://twitter.com/pando_im/status/1589045252413100032) +- [Exploit Address](https://etherscan.io/address/0xd3f04ce2d37b182432e2f804f9913a02071cea54) \ No newline at end of file diff --git a/_posts/2022-11-15-peakdefi.md b/_posts/2022-11-15-peakdefi.md new file mode 100644 index 0000000..2b889f2 --- /dev/null +++ b/_posts/2022-11-15-peakdefi.md @@ -0,0 +1,16 @@ +--- +layout: post +title: Peak DeFi +date: 2022-11-04 09:18 -0800 +categories: +- smart_contract +link: https://twitter.com/AnciliaInc/status/1588646551684988928 +--- +Insufficent access control. $40k lost in smart contract deployed in Ethereum network. + +> @AnciliaInc We detected an attack on ETH contract https://etherscan.io/address/0x07cdb44fa1e7eceb638c12a3451a3dc9ce1400e4, it lost about 32k Matic tokens and hacker gained around ~300k. +> The root cause is that the contract does not have permission check on its sellLeftoverToken() function. +> Seems like the fund belongs to @PEAKDEFI PeakDeFiFund. @PEAKDEFI you might need to check this up. + +- [Contract Address](https://etherscan.io/address/0x07cdb44fa1e7eceb638c12a3451a3dc9ce1400e4) +- [Suspect TX](https://etherscan.io//tx/0x0faa90b780a7939bfbeb3d7c8dfb1c8a318219f7be60c4a698991fd635e95813) \ No newline at end of file diff --git a/_posts/2022-11-15-pnetwork-bridge.md b/_posts/2022-11-15-pnetwork-bridge.md new file mode 100644 index 0000000..3d61447 --- /dev/null +++ b/_posts/2022-11-15-pnetwork-bridge.md @@ -0,0 +1,19 @@ +--- +layout: post +title: pNetwork Bridge +date: 2022-11-03 08:27 -0800 +categories: +- protocol_vulnerability +- bridge_vulnerability +link: https://twitter.com/hackenclub/status/1588307631529041920 +--- +Bridge misconfiguration resulted in $4.3M stolen. Binance Smart Chain network. + +> As it can be seen from BSC explorer, an attacker minted ≈27.8 billions of $GALA tokens twice in Binance Smart Chain (@BNBCHAIN) network +> Then, the attacker started to sell the $GALA tokens via PancakeSwap (@PancakeSwap), dumping the price by more than 99% +> pGALA on BSC Notice: A misconfiguration of the http://p.Network bridge necessitated the redeployment of pGALA. We’re working directly w/the Gala team and w/ exchanges to provide the necessary pGALA balances to restore functionality of pGALA deposits & withdrawals. +> All GALA tokens on Ethereum as well as the underlying bridge collateral are SAFE. + +- [Official Announcement](https://twitter.com/pNetworkDeFi/status/1588266897061031936) +- [Attacker Address](https://bscscan.com/address/0x6891a233bca9e72a078bcb71ba02ad482a44e8c1) +- [Suspect TX](https://bscscan.com/tx/0x439aa6f526184291a0d3bd3d52fccd459ec3ea0a8c1d5bf001888ef670fe616d) \ No newline at end of file diff --git a/_posts/2022-11-16-abracadabra-oracle.md b/_posts/2022-11-16-abracadabra-oracle.md new file mode 100644 index 0000000..90a9447 --- /dev/null +++ b/_posts/2022-11-16-abracadabra-oracle.md @@ -0,0 +1,13 @@ +--- +layout: post +title: Abracadabra Price Oracle Manipulation +date: 2022-11-08 10:27 -0800 +categories: smart_contract +link: https://twitter.com/spreekaway/status/1590118020319354880 +--- +Price oracle manipulation attack in Abracadabra protocol in Ethereum network. $110k lost to the attacker. + +> seems MIM just ate a bunch of bad debt from someone depositing xSUSHI when the oracle was far above current price, self updating the oracle, and then liquidating themself. +> attacker profited 110,911 MIM + +- [Attacker Address](https://debank.com/profile/0xb7ea0f0f8c6df7a61bf024db21bbe85ac5688005/history) diff --git a/_posts/2022-11-16-brahTopg.md b/_posts/2022-11-16-brahTopg.md new file mode 100644 index 0000000..bcb90b3 --- /dev/null +++ b/_posts/2022-11-16-brahTopg.md @@ -0,0 +1,14 @@ +--- +layout: post +title: Abracadabra Price Oracle Manipulation +date: 2022-11-09 04:55 -0800 +categories: smart_contract +link: https://twitter.com/SlowMist_Team/status/1590685173477101570 +--- +Insufficient function parameter validation in TopGear Brahma vault in Ethereum network. $90k stolen. + +> On November 9, 2022, the brahTOPG project on the ETH chain was attacked, leading to the loss of $89,879. +> The root cause of this attack is that the Zapper contract is rigorously checking for incoming user data, leading to an arbitrary external call issue. The attackers exploit this vulnerability to steal funds from users who are still authorized to the contract. + +- [Suspect TX](https://etherscan.io/tx/0xeaef2831d4d6bca04e4e9035613be637ae3b0034977673c1c2f10903926f29c0) +- [Neptune Post](https://medium.com/neptune-mutual/decoding-brahma-brahtopg-smart-contract-vulnerability-7b7c364b79d8) \ No newline at end of file diff --git a/_posts/2022-11-16-ftx-wallet.md b/_posts/2022-11-16-ftx-wallet.md new file mode 100644 index 0000000..81a0a24 --- /dev/null +++ b/_posts/2022-11-16-ftx-wallet.md @@ -0,0 +1,18 @@ +--- +layout: post +title: FTX Wallet +date: 2018-11-12 02:30 -0700 +categories: +- server_hot_wallet_breach +link: https://twitter.com/zachxbt/status/1591276687228035074 +--- +FTX wallet compromised. $380M stolen. Insider? Hot vs Cold wallet? TBD + +> Multiple former FTX employees confirmed to me they do not recognize these transfers for ~$383m +> Update: $31.4m USDT blacklisted by Tether +> Appears a portion was “whitehat” funds. Would assume this is the 0x97 & 0xd8 address. +> Update: Paxos seems frozen now for 0x59 attacker + +- [Twitter thread](https://twitter.com/0xfoobar/status/1591261359152705538) +- [FTX US TX](https://etherscan.io/tx/0x9c9065a994e2c9dfb21c9c853ea9cf6b7b1829a8bd2258058d80161847f8000e) +- [FTX TX](https://etherscan.io/tx/0x6580bf69c1ee28a1d8a4dec9b949272a449b1c58d91e6692ef34d9ea40fd9653) diff --git a/_posts/2022-11-20-dappnode-profanity.md b/_posts/2022-11-20-dappnode-profanity.md new file mode 100644 index 0000000..eafd8fe --- /dev/null +++ b/_posts/2022-11-20-dappnode-profanity.md @@ -0,0 +1,17 @@ +--- +layout: post +title: Dappnode Profanity +date: 2022-10-29 00:00 -0700 +categories: +- cryptography +- brute_force +network: +- Ethereum +amount: 300_000 +link: https://twitter.com/DAppNode/status/1586769313872101376 +--- +Address compromised through profanity attack vector. + +> The hacker/s ran away with 57.72 ETH and 552.61 GNO (aprox. 165,000 USD) + +-[Profanity Disclosure 1inch](https://blog.1inch.io/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool-68ed7455fc8c) \ No newline at end of file diff --git a/_posts/2022-11-20-friesdao.md b/_posts/2022-11-20-friesdao.md new file mode 100644 index 0000000..39d6b39 --- /dev/null +++ b/_posts/2022-11-20-friesdao.md @@ -0,0 +1,18 @@ +--- +layout: post +title: Fries DAO +date: 2022-10-27 05:58 -0700 +categories: +- cryptography +- brute_force +network: +- Ethereum +amount: 2_300_000 +link: https://docs.google.com/document/d/1xKZmj1aeM9iFrdQ7sieUNvh0_UI60worl1lfs5ImXk0/ +--- +Deployer addresses compromised through profanity attack vector. + +> On October 27th, 5:58PM UTC, friesDAO contracts were exploited by an attacker taking control of our own deployer address through a profanity attack vector. +> The hacker was able to drain the treasury of its USDC through the refund contract, drain the FRIES tokens in the staking contract, subsequently selling it all into the Uniswap pool. + +-[Profanity Disclosure 1inch](https://blog.1inch.io/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool-68ed7455fc8c) \ No newline at end of file diff --git a/_posts/2022-11-20-giveth-profanity.md b/_posts/2022-11-20-giveth-profanity.md new file mode 100644 index 0000000..58b9f9c --- /dev/null +++ b/_posts/2022-11-20-giveth-profanity.md @@ -0,0 +1,19 @@ +--- +layout: post +title: Giveth Profanity +date: 2022-10-30 15:00 -0700 +categories: +- cryptography +- brute_force +network: +- Ethereum +amount: 50_000 +link: https://twitter.com/Givethio/status/1586511169975623682 +--- +Address used to control rewards compromised through profanity attack vector. + +> An attacker exploited our GIVfarm today at about 15:00 UTC. +> This was not a smart contract exploit. Rather, the keys we used to control the rate of rewards to our GIVfarms were compromised. +> The attacker used the compromised keys to change the reward rate for our Mainnet farms to a very large number & then quickly claimed the rewards. + +-[Profanity Disclosure 1inch](https://blog.1inch.io/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool-68ed7455fc8c) \ No newline at end of file diff --git a/_posts/2022-11-20-melody.md b/_posts/2022-11-20-melody.md new file mode 100644 index 0000000..322acc5 --- /dev/null +++ b/_posts/2022-11-20-melody.md @@ -0,0 +1,17 @@ +--- +layout: post +title: Melody Wallet +date: 2022-10-24 04:54 -0700 +categories: +- server_hot_wallet_breach +network: +- BSC +amount: 610_000 +link: https://blog.neptunemutual.com/decoding-melody-vulnerability/ +--- +Melody offchain signing service compromised. 2225 $BNB tokens lost. + +> On October 25, 2022, Melody was hacked due to a vulnerability that allowed the application's token address to be compromised, resulting in the loss of approximately 2225 $BNB tokens. +> The root cause of the attack is that the application's token address was compromised which allowed the hacker to bypass the access control. +> Following the incident, another attacker address repeated the attack, earning 2,450 $SGS and exchanging proceeds for 560 $WBNB. +> The team took the contract to maintenance mode and restarted the withdrawal function after the bug was fixed. diff --git a/_posts/2022-11-20-noodleswap-reentrancy.md b/_posts/2022-11-20-noodleswap-reentrancy.md new file mode 100644 index 0000000..4b4daa4 --- /dev/null +++ b/_posts/2022-11-20-noodleswap-reentrancy.md @@ -0,0 +1,17 @@ +--- +layout: post +title: NoodleSwap +date: 2022-10-25 16:49 -0700 +categories: +- smart_contract +- reentrancy +network: +- Ethereum +amount: 29_000 +link: https://twitter.com/BlockSecTeam/status/1584959295829180416 +--- +Reentrancy vulnerability. $29k loss. + +> Looks @n00dleSwap has an ERC777-based reentrancy issue and is being attacked, causing a loss of $29K. + +- [Exploit TX](https://phalcon.blocksec.com/tx/eth/0x8037b3dc0bf9d5d396c10506824096afb8125ea96ada011d35faa89fa3893aea) \ No newline at end of file diff --git a/_posts/2022-11-20-team-finance.md b/_posts/2022-11-20-team-finance.md new file mode 100644 index 0000000..d1c5841 --- /dev/null +++ b/_posts/2022-11-20-team-finance.md @@ -0,0 +1,20 @@ +--- +layout: post +title: Team Finance +date: 2022-10-27 08:29 -0700 +categories: +- smart_contract +network: +- Ethereum +amount: 15_800_000 +link: https://rekt.news/teamfinance-rekt/ +--- + +Lost $15.8M, of which $7M were recovered. Exploit due to pool migration function bug. + +> @TeamFinance_ was exploited in https://etherscan.io/tx/0xb2e3ea72d353da43a2ac9a8f1670fd16463ab370e563b9b5b26119b2601277ce, leading to the loss of ~$15.8M for the protocol: $11.5M (V2_USDC_CAW)+$1.7M(V2_USDC_TSUKA)+0.7M(V2_KNDX_WETH)+1.9M(V2_FEG_WETH). +> The protocol has a flawed migrate() that is exploited to transfer real UniswapV2 liquidity to an attacker-controlled new V3 pair with skewed price, resulting in huge leftover as the refund for profit. Also, the authorized sender check is bypassed by locking any tokens. +> The initial fund (1.76 ETH) to launch the hack is withdrawn from @FixedFloat. + +- [Peckshield Thread](https://twitter.com/peckshield/status/1585587858978623491) +- [Attack Tx](https://etherscan.io/tx/0xb2e3ea72d353da43a2ac9a8f1670fd16463ab370e563b9b5b26119b2601277ce) \ No newline at end of file diff --git a/_posts/2022-11-20-ulme-price-oracle.md b/_posts/2022-11-20-ulme-price-oracle.md new file mode 100644 index 0000000..2d7981c --- /dev/null +++ b/_posts/2022-11-20-ulme-price-oracle.md @@ -0,0 +1,17 @@ +--- +layout: post +title: ULME Price Manipulation +date: 2022-10-25 08:18 -0700 +categories: +- smart_contract +- price_oracle_manipulation +- flash_loan +network: +- BSC +amount: 50_000 +link: https://medium.com/neptune-mutual/decoding-ulme-token-flash-loan-attack-56470d261787 +--- +Price oracle manipulation using a flash loan. + +> On October 25, 2022, ULME Token was attacked by a hacker who allegedly gained approximately 50,646 BUSD using flash loan. + diff --git a/_posts/2022-11-20-uvtoken.md b/_posts/2022-11-20-uvtoken.md new file mode 100644 index 0000000..d059811 --- /dev/null +++ b/_posts/2022-11-20-uvtoken.md @@ -0,0 +1,18 @@ +--- +layout: post +title: UvToken +date: 2022-10-27 05:02 -0700 +categories: +- smart_contract +- insufficient_access_control +network: +- BSC +amount: 1_500_000 +link: https://medium.com/@numencyberlabs/loss-1-5-m-technical-analysis-for-uvtoken-attacked-83ae7c35f10e +--- +Insufficient access control. $1.5M lost. + +> The hackers stole 1,078 BNB and 1,161,991 BUSD from the attack, with the total losses adding up to approximately $1.5 Million USD. +> The hackers have already transferred the funds to Tornado.Cash. + +- [Attack Tx](https://bscscan.com/tx/0x54121ed538f27ffee2dbb232f9d9be33e39fdaf34adf993e5e019c00f6afd499) \ No newline at end of file diff --git a/_posts/2022-11-20-victor-fortune.md b/_posts/2022-11-20-victor-fortune.md new file mode 100644 index 0000000..75c8ee0 --- /dev/null +++ b/_posts/2022-11-20-victor-fortune.md @@ -0,0 +1,16 @@ +--- +layout: post +title: Victor the Fortune +date: 2022-10-27 10:02 -0700 +categories: +- smart_contract +network: +- BSC +amount: 58_500 +link: https://twitter.com/peckshield/status/1585572694241988609 +--- +Reward manipulation exploit. + +> Seems like Victor the Fortune $VTF exploited (The funds are being drained w/ ~$58.5k)https://bscscan.com/tx/0xeeaf7e9662a7488ea724223c5156e209b630cdc21c961b85868fe45b64d9b086 The exploiter's address: + +- [Exploiter Address](https://bscscan.com/address/0x57c112cf4f1e4e381158735b12aaf8384b60e1ce) \ No newline at end of file