DeFi protocol Grim Finance lost $30M in 5x reentrancy hack
DeFi protocol Grim Finance lost $30M in 5x reentrancy hack
An apparent security flaw in the Grim Finance protocol allowed the assailant to simulated five boosted deposits.
9165 Total views
47 Total shares
The decentralized finance (DeFi) protocol Grim Finance reported $thirty million in losses due to a reentrancy exploit of the platform's deposits.
Grim Finance officially announced on Saturday that an "external attacker" had exploited the DeFi platform, stealing "over $30 million" worth of cryptocurrencies.
According to Grim Finance, the hack was an "avant-garde attack," with the assaulter exploiting the protocol's vault contract through v reentrancy loops, which immune them to fake five additional deposits into a vault while the platform was processing the first deposit.
Grim paused all vaults afterward the attack to minimize the risk for future funds: "We accept paused all of the vaults to forestall any hereafter funds from being placed at risk, please withdraw all of your funds immediately."
Grim noted that they also notified entities involved in operating major cryptocurrencies similar Circle (USDC), Dai (DAI) and the cross-chain protocol AnySwap regarding the attacker address to freeze farther fund transfers.
Grim Finance positions itself every bit a "compounding yield optimizer" built on a DeFi-focused blockchain protocol, Fantom, allowing users to stake liquidity provider tokens by employing complex vault strategies.
According to the Fantom (FTM) Blockchain Explorer data, Grim Finance Exploiter continued transacting on Dominicus. One of the addresses associated with the exploit holds $ane.ii meg in Bitcoin (BTC), $1.7 million in SpookyToken (BOO) aslope $13,700 in FTM tokens.
Some in the crypto customs suggested that Grim Finance should concur responsibleness for the exploit due to failing to adopt proper reentrancy protection tools. DeFi security platform Rugdoc.io besides argued that the protocol gave the user "more privilege than is necessary."
five) So what was the big fault of grim finance?
— Rugdoc.io (@RugDocIO) Dec 18, 2022
ane. No reentrancy baby-sit on a blueprint that admittedly needs it (@0xPaladinSec always points this out)
2. Giving the user more privilege than is necessary: There is absolutely no need for the user to be able to choose the deposit token
Related: Finance Redefined: 2 DeFi hacks top $120M, and $500M Algo Fund launches, Nov. 26–December. 3
The rising popularity of DeFi has triggered a number of new challenges for the cryptocurrency industry as hackers were rushing to exploit the flaws of the emerging industry. In early December, DeFi protocol BadgerDAO was reportedly exploited to the tune of $120 million.
Source: https://cointelegraph.com/news/defi-protocol-grim-finance-lost-30m-in-5x-reentrancy-hack
Posted by: garnernuir1940.blogspot.com

0 Response to "DeFi protocol Grim Finance lost $30M in 5x reentrancy hack"
Post a Comment