• bitcoinBitcoin (BTC) $ 67,833.00
  • ethereumEthereum (ETH) $ 2,045.83
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 632.80
  • xrpXRP (XRP) $ 1.41
  • usd-coinUSDC (USDC) $ 0.999907
  • solanaSolana (SOL) $ 87.64
  • tronTRON (TRX) $ 0.285155
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • dogecoinDogecoin (DOGE) $ 0.098830
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • cardanoCardano (ADA) $ 0.294687
  • whitebitWhiteBIT Coin (WBT) $ 50.59
  • usdsUSDS (USDS) $ 0.999950
  • bitcoin-cashBitcoin Cash (BCH) $ 485.93
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 8.79
  • hyperliquidHyperliquid (HYPE) $ 29.10
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • canton-networkCanton (CC) $ 0.175055
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 9.21
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 349.21
  • ethena-usdeEthena USDe (USDE) $ 0.999609
  • stellarStellar (XLM) $ 0.165107
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999771
  • rainRain (RAIN) $ 0.009391
  • hedera-hashgraphHedera (HBAR) $ 0.104242
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 56.02
  • daiDai (DAI) $ 0.999212
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999772
  • avalanche-2Avalanche (AVAX) $ 9.41
  • zcashZcash (ZEC) $ 242.40
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.954448
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.116240
  • usdt0USDT0 (USDT0) $ 0.998824
  • crypto-com-chainCronos (CRO) $ 0.078274
  • the-open-networkToncoin (TON) $ 1.31
  • tether-goldTether Gold (XAUT) $ 5,175.92
  • polkadotPolkadot (DOT) $ 1.61
  • memecoreMemeCore (M) $ 1.44
  • uniswapUniswap (UNI) $ 3.94
  • pax-goldPAX Gold (PAXG) $ 5,205.65
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • mantleMantle (MNT) $ 0.649188
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • bittensorBittensor (TAO) $ 188.77
  • aaveAave (AAVE) $ 118.55
  • falcon-financeFalcon USD (USDF) $ 0.997367
  • aster-2Aster (ASTER) $ 0.712553
  • global-dollarGlobal Dollar (USDG) $ 1.00
  • okbOKB (OKB) $ 78.55
  • pepePepe (PEPE) $ 0.000004
  • pi-networkPi Network (PI) $ 0.169650
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • skySky (SKY) $ 0.068632
  • bitget-tokenBitget Token (BGB) $ 2.24
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • htx-daoHTX DAO (HTX) $ 0.000002
  • nearNEAR Protocol (NEAR) $ 1.14
  • internet-computerInternet Computer (ICP) $ 2.63
  • ethereum-classicEthereum Classic (ETC) $ 8.99
  • bfusdBFUSD (BFUSD) $ 0.999340
  • ondo-financeOndo (ONDO) $ 0.271004
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.114516
  • worldcoin-wldWorldcoin (WLD) $ 0.406174
  • kucoin-sharesKuCoin (KCS) $ 8.74
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.00
  • gatechain-tokenGate (GT) $ 7.13
  • pump-funPump.fun (PUMP) $ 0.001901
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • morphoMorpho (MORPHO) $ 1.86
  • midnight-3Midnight (NIGHT) $ 0.060216
  • cosmosCosmos Hub (ATOM) $ 1.91
  • quant-networkQuant (QNT) $ 64.41
  • hash-2Provenance Blockchain (HASH) $ 0.016804
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • ethenaEthena (ENA) $ 0.106957
  • nexoNEXO (NEXO) $ 0.869333
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • kaspaKaspa (KAS) $ 0.031525
  • usdtbUSDtb (USDTB) $ 1.00
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • flare-networksFlare (FLR) $ 0.009673
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.24
  • algorandAlgorand (ALGO) $ 0.089456
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • official-trumpOfficial Trump (TRUMP) $ 3.42
  • pippinpippin (PIPPIN) $ 0.785335
  • wbnbWrapped BNB (WBNB) $ 759.61
  • filecoinFilecoin (FIL) $ 1.03
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.992540
  • render-tokenRender (RENDER) $ 1.48
  • usddUSDD (USDD) $ 0.999987
  • ousgOUSG (OUSG) $ 114.42
  • stable-2​​Stable (STABLE) $ 0.036828
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • xdce-crowd-saleXDC Network (XDC) $ 0.035342
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • vechainVeChain (VET) $ 0.007687
  • decredDecred (DCR) $ 35.27
  • beldexBeldex (BDX) $ 0.080204
  • arbitrumArbitrum (ARB) $ 0.103594
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • usual-usdUsual USD (USD0) $ 0.997716
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • jupiter-exchange-solanaJupiter (JUP) $ 0.160038
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • bonkBonk (BONK) $ 0.000006
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • ghoGHO (GHO) $ 1.00
  • a7a5A7A5 (A7A5) $ 0.012889
  • true-usdTrueUSD (TUSD) $ 0.999715
  • clbtcclBTC (CLBTC) $ 76,920.00
  • blockstackStacks (STX) $ 0.264946
  • sei-networkSei (SEI) $ 0.071353
  • fasttokenFasttoken (FTN) $ 1.09
  • euro-coinEURC (EURC) $ 1.18
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.711329
  • usdaiUSDai (USDAI) $ 1.00
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.007175
  • dashDash (DASH) $ 35.66
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • kite-2Kite (KITE) $ 0.248063
  • tbtctBTC (TBTC) $ 70,942.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.33
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • tezosTezos (XTZ) $ 0.399007
  • justJUST (JST) $ 0.046491
  • kinesis-goldKinesis Gold (KAU) $ 167.15
  • ether-fiEther.fi (ETHFI) $ 0.516196
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • power-protocolPower Protocol (POWER) $ 1.80
  • curve-dao-tokenCurve DAO (CRV) $ 0.254668
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.164835
  • c8ntinuumc8ntinuum (CTM) $ 0.084755
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • story-2Story (IP) $ 1.02
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • lighterLighter (LIT) $ 1.42
  • cocaCOCA (COCA) $ 1.30
  • bittorrentBitTorrent (BTT) $ 0.00000036
  • usxUSX (USX) $ 0.999797
  • chilizChiliz (CHZ) $ 0.033377
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • gnosisGnosis (GNO) $ 129.79
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • layerzeroLayerZero (ZRO) $ 1.69
  • hastra-primePRIME (PRIME) $ 1.02
  • aerodrome-financeAerodrome Finance (AERO) $ 0.367204
  • kaiaKaia (KAIA) $ 0.057242
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • apenftAINFT (NFT) $ 0.00000033
  • injective-protocolInjective (INJ) $ 3.23
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • bitcoin-svBitcoin SV (BSV) $ 16.12
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • adi-tokenADI (ADI) $ 3.27
  • sun-tokenSun Token (SUN) $ 0.016198
  • pyth-networkPyth Network (PYTH) $ 0.053237
  • iotaIOTA (IOTA) $ 0.070114
  • spx6900SPX6900 (SPX) $ 0.324410
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • celestiaCelestia (TIA) $ 0.338245
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • the-graphThe Graph (GRT) $ 0.027148
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • crvusdcrvUSD (CRVUSD) $ 0.995874
  • flokiFLOKI (FLOKI) $ 0.000030
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • jasmycoinJasmyCoin (JASMY) $ 0.005778
  • doublezeroDoubleZero (2Z) $ 0.081324
  • syrupMaple Finance (SYRUP) $ 0.240540
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • olympusOlympus (OHM) $ 17.60
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • fraxLegacy Frax Dollar (FRAX) $ 0.985771
  • lido-daoLido DAO (LDO) $ 0.315475
  • siren-2Siren (SIREN) $ 0.358491
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • heliumHelium (HNT) $ 1.40
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • conflux-tokenConflux (CFX) $ 0.050409
  • optimismOptimism (OP) $ 0.122590
  • btse-tokenBTSE Token (BTSE) $ 1.55
  • telcoinTelcoin (TEL) $ 0.002642
  • staked-aaveStaked Aave (STKAAVE) $ 126.65

Just another day in DeFi: A hack, a rug-pull, and $10M saved

0 61

Just another day in DeFi: A hack, a rug-pull, and $10M saved

The decentralized finance (DeFi) sector is a financial frontier zone, home to some of crypto’s most risk-on experiments.

As a result, few days go by without a dose of DeFi drama. But it’s not all bad news…

Backdoor vulnerability left $10M at risk

Security researchers at VennBuild announced the discovery of a “critical backdoor” vulnerability, in which suspected North Korean hackers had laid a trap affecting “thousands of smart contracts, leaving over $10,000,000 at risk for months.”

Uncovered in conjunction with other researchers from Dedaub and the DeFi Security Alliance (SEAL), the plot involved front-running the initialization of proxy contracts to malicious versions, whilst covering their tracks via spoofed logs.

A VennBuild researcher, going by the X handle “deebeez,” explained: “The backdoor gave hackers full control, forwarding calls to the original contract while [block explorer] Etherscan showed no issues.”

They suspect the traps were set by “a sophisticated group waiting for a bigger target, not small wins,” and as such hadn’t yet been exploited.

“We stayed stealthy to avoid tipping them off. A high-stakes game.”

Hacker offered 10% bounty if they return Texture’s USDC

Worse luck came for Solana-based lending platform Texture, which announced a hack of $2.2 million from its USDC Vault contract last night.

The team took to X to offer the culprit a 10% bounty if they returned the remaining funds. Taking a hardball approach to the negotiations, they say the hacker “made an opsec mistake, but it’s not too late to avoid escalating the situation.”

The bad cop routine appears to have spooked the thief, who has now returned 90% of the funds, according to the Texture team.

Earlier the same day, a $42 million hack hit decentralized perps exchange GMX on the Arbitrum network.

The effects weren’t limited to GMX itself, however. Lending platform Abracadabra suffered “collateral” damage of $9 million in a market using GMX’s (exploited) GLP token as collateral.

Many GMX v1 forks were also feared to be vulnerable to a similar attack.

Kinto accused of rug-pull

Screenshots of red candles aren’t uncommon on any crypto enthusiast’s timeline, but the recent price action of Kinto’s K token was more eye-catching than most.

While many were quick to accuse the team of a rug-pull, insiders selling large quantities of tokens and crashing the price, it appears there’s more to the story.

Granted, Kinto’s initial response was suspiciously vague and only served to fan the flames of suspicion. One X user replied simply, “This doesn’t even address the issue,” while others accused the team of rugging by selling “their bags.”

However, a later update described an eerily similar situation to the proxy backdoor trap uncovered by VennBuild and others.

Kinto co-founder Ramon Recuero says a “state actor… upgraded the implementation of the K token on Arbitrum and used it to mint fake K tokens that they dumped immediately,” adding that “Arbiscan didn’t detect the bogus proxy implementation.”

It feels like, in DeFi, chaos isn’t the exception but the rule.

Source

Leave A Reply

Your email address will not be published.