• bitcoinBitcoin (BTC) $ 112,825.00
  • ethereumEthereum (ETH) $ 4,103.53
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,216.03
  • xrpXRP (XRP) $ 2.51
  • solanaSolana (SOL) $ 202.01
  • usd-coinUSDC (USDC) $ 0.999852
  • staked-etherLido Staked Ether (STETH) $ 4,100.54
  • dogecoinDogecoin (DOGE) $ 0.203625
  • tronTRON (TRX) $ 0.316655
  • cardanoCardano (ADA) $ 0.699376
  • wrapped-stethWrapped stETH (WSTETH) $ 4,992.35
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,416.19
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 112,796.00
  • chainlinkChainlink (LINK) $ 19.04
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.997557
  • ethena-usdeEthena USDe (USDE) $ 0.999777
  • wrapped-eethWrapped eETH (WEETH) $ 4,427.01
  • hyperliquidHyperliquid (HYPE) $ 40.22
  • stellarStellar (XLM) $ 0.335660
  • bitcoin-cashBitcoin Cash (BCH) $ 534.67
  • suiSui (SUI) $ 2.83
  • avalanche-2Avalanche (AVAX) $ 22.86
  • wethWETH (WETH) $ 4,106.65
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • leo-tokenLEO Token (LEO) $ 9.64
  • usdsUSDS (USDS) $ 0.999849
  • hedera-hashgraphHedera (HBAR) $ 0.186178
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 112,779.00
  • usdt0USDT0 (USDT0) $ 1.00
  • litecoinLitecoin (LTC) $ 96.60
  • mantleMantle (MNT) $ 1.97
  • shiba-inuShiba Inu (SHIB) $ 0.000011
  • whitebitWhiteBIT Coin (WBT) $ 42.83
  • the-open-networkToncoin (TON) $ 2.30
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • moneroMonero (XMR) $ 308.67
  • crypto-com-chainCronos (CRO) $ 0.162040
  • polkadotPolkadot (DOT) $ 3.24
  • daiDai (DAI) $ 1.00
  • bittensorBittensor (TAO) $ 456.73
  • uniswapUniswap (UNI) $ 6.77
  • zcashZcash (ZEC) $ 248.50
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.147011
  • aaveAave (AAVE) $ 252.70
  • okbOKB (OKB) $ 181.43
  • memecoreMemeCore (M) $ 2.03
  • bitget-tokenBitget Token (BGB) $ 4.82
  • pepePepe (PEPE) $ 0.000007
  • ethenaEthena (ENA) $ 0.434858
  • nearNEAR Protocol (NEAR) $ 2.47
  • aster-2Aster (ASTER) $ 1.47
  • jito-staked-solJito Staked SOL (JITOSOL) $ 249.43
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • susdssUSDS (SUSDS) $ 1.07
  • aptosAptos (APT) $ 3.67
  • ethereum-classicEthereum Classic (ETC) $ 16.86
  • paypal-usdPayPal USD (PYUSD) $ 0.999825
  • c1usdCurrency One USD (C1USD) $ 1.00
  • ondo-financeOndo (ONDO) $ 0.795442
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,110.49
  • falcon-financeFalcon USD (USDF) $ 0.998246
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.60
  • story-2Story (IP) $ 6.79
  • worldcoin-wldWorldcoin (WLD) $ 0.961999
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.200869
  • binance-staked-solBinance Staked SOL (BNSOL) $ 217.16
  • gatechain-tokenGate (GT) $ 16.30
  • internet-computerInternet Computer (ICP) $ 3.57
  • htx-daoHTX DAO (HTX) $ 0.000002
  • kucoin-sharesKuCoin (KCS) $ 14.35
  • arbitrumArbitrum (ARB) $ 0.342084
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,690.11
  • usdtbUSDtb (USDTB) $ 0.999914
  • chainopera-aiChainOpera AI (COAI) $ 9.30
  • hash-2Provenance Blockchain (HASH) $ 0.036078
  • algorandAlgorand (ALGO) $ 0.203594
  • pi-networkPi Network (PI) $ 0.215277
  • bfusdBFUSD (BFUSD) $ 1.00
  • vechainVeChain (VET) $ 0.019204
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,329.47
  • kaspaKaspa (KAS) $ 0.061267
  • cosmosCosmos Hub (ATOM) $ 3.47
  • wbnbWrapped BNB (WBNB) $ 1,216.98
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 40.12
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.024930
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,328.38
  • tether-goldTether Gold (XAUT) $ 4,150.49
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,439.81
  • render-tokenRender (RENDER) $ 2.85
  • skySky (SKY) $ 0.062746
  • pump-funPump.fun (PUMP) $ 0.004109
  • flare-networksFlare (FLR) $ 0.019102
  • sei-networkSei (SEI) $ 0.224940
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 112,709.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,352.90
  • pax-goldPAX Gold (PAXG) $ 4,164.30
  • official-trumpOfficial Trump (TRUMP) $ 6.30
  • bonkBonk (BONK) $ 0.000016
  • nexoNEXO (NEXO) $ 1.22
  • jupiter-exchange-solanaJupiter (JUP) $ 0.377219
  • pancakeswap-tokenPancakeSwap (CAKE) $ 3.48
  • filecoinFilecoin (FIL) $ 1.67
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • spx6900SPX6900 (SPX) $ 1.22
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 112,536.00
  • immutable-xImmutable (IMX) $ 0.570603
  • xdce-crowd-saleXDC Network (XDC) $ 0.060616
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997030
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,414.31
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 230.90
  • morphoMorpho (MORPHO) $ 1.92
  • doublezeroDoubleZero (2Z) $ 0.283056
  • celestiaCelestia (TIA) $ 1.19
  • injective-protocolInjective (INJ) $ 9.56
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 112,953.00
  • clbtcclBTC (CLBTC) $ 115,989.00
  • solmevSolMev (SN116) $ 2,398.72
  • fasttokenFasttoken (FTN) $ 2.01
  • lido-daoLido DAO (LDO) $ 0.965749
  • optimismOptimism (OP) $ 0.481940
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.327112
  • blockstackStacks (STX) $ 0.469682
  • msolMarinade Staked SOL (MSOL) $ 268.72
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • curve-dao-tokenCurve DAO (CRV) $ 0.589961
  • aerodrome-financeAerodrome Finance (AERO) $ 0.896246
  • plasmaPlasma (XPL) $ 0.449278
  • ousgOUSG (OUSG) $ 112.92
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,925.24
  • sonic-3Sonic (S) $ 0.202902
  • global-dollarGlobal Dollar (USDG) $ 0.999943
  • the-graphThe Graph (GRT) $ 0.069953
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,103.91
  • pyth-networkPyth Network (PYTH) $ 0.125247
  • flokiFLOKI (FLOKI) $ 0.000074
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.08
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.85
  • havvenSynthetix (SNX) $ 1.99
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.999747
  • saros-financeSaros (SAROS) $ 0.258943
  • kaiaKaia (KAIA) $ 0.113715
  • tezosTezos (XTZ) $ 0.622810
  • tbtctBTC (TBTC) $ 112,422.00
  • ether-fiEther.fi (ETHFI) $ 1.26
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,105.14
  • aethirAethir (ATH) $ 0.044873
  • gtethGTETH (GTETH) $ 4,111.14
  • stader-ethxStader ETHx (ETHX) $ 4,398.56
  • pendlePendle (PENDLE) $ 3.68
  • newton-projectAB (AB) $ 0.007577
  • iotaIOTA (IOTA) $ 0.151280
  • conflux-tokenConflux (CFX) $ 0.118430
  • myx-financeMYX Finance (MYX) $ 3.15
  • usdaiUSDai (USDAI) $ 1.03
  • beldexBeldex (BDX) $ 0.079223
  • dogwifcoindogwifhat (WIF) $ 0.579447
  • dashDash (DASH) $ 46.38
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.38
  • theta-tokenTheta Network (THETA) $ 0.570579
  • ethereum-name-serviceEthereum Name Service (ENS) $ 16.98
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,517.95
  • galaGALA (GALA) $ 0.012046
  • the-sandboxThe Sandbox (SAND) $ 0.224580
  • starknetStarknet (STRK) $ 0.126884
  • usual-usdUsual USD (USD0) $ 0.998211
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,099.26
  • raydiumRaydium (RAY) $ 2.04
  • swethSwell Ethereum (SWETH) $ 4,513.02
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.824907
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,413.09
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 112,777.00
  • swissborgSwissBorg (BORG) $ 0.539607
  • jasmycoinJasmyCoin (JASMY) $ 0.010941
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.36
  • rna-2RNA (SN117) $ 4,708.96
  • decentralandDecentraland (MANA) $ 0.272066
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.203880
  • bittorrentBitTorrent (BTT) $ 0.00000052
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.998121
  • vaultaVaulta (A) $ 0.314415
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,283.25
  • true-usdTrueUSD (TUSD) $ 0.999558
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,421.17
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.10
  • flowFlow (FLOW) $ 0.297722
  • usddUSDD (USDD) $ 1.00
  • syrupMaple Finance (SYRUP) $ 0.426556
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999905
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999911
  • zero-gravity0G (0G) $ 2.19
  • sun-tokenSun Token (SUN) $ 0.024262
  • ai-companionsAI Companions (AIC) $ 0.464143
  • bitcoin-svBitcoin SV (BSV) $ 22.87
  • jito-governance-tokenJito (JTO) $ 1.17
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,104.64
  • frax-etherFrax Ether (FRXETH) $ 4,061.72
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 28.01

Onyx Protocol Loses $3.8 Million in Preventable Hack

0 66

Onyx Protocol Loses $3.8 Million in Preventable Hack

Onyx Protocol, a Compound Finance fork, suffered a $3.8 million loss on Thursday to mark another entry in a series of attacks as bad actors explore system vulnerability.

Cyber-attacks continue to plague the crypto industry, highlighting the need for enhanced security.

$3.8 Million Hack Hits Onyx Protocol

Blockchain security firm PeckShield highlighted suspicious transactions on OnyxDAO, drawing attention to a possible attack on the protocol. In a follow-up post, the on-chain detective revealed losses reaching $3.8 million, indicating that the hacker was already swapping the funds.

Onyx Protocol Loses $3.8 Million in Preventable Hack

Onyx Protocol Hack. Source: PeckShield

Web3 security firm Cyvers corroborated the incident, citing suspicious transactions involving OnyxDAO on the Ethereum blockchain. According to Cyvers, most of the loss was in VUSD stablecoin.

“Our system has detected a suspicious transaction involving OnyxDAO on the ETH chain! The total loss is around $3.2 million [at the time]. Most of the losses are in VUSD. Attacker currently holds 521 ETH ($1.36 million). The rest of the digital assets are not swapped yet,” Cyvers wrote.

Additional investigations by PeckShield revealed that the attacker capitalized on a known precision issue presented as a bug in the forked Compound V2 code base. They then siphoned 4.1 million VUSD, 7.35 million XCN, 5,000 DAI, 0.23 WBTC, and 50,000 USDT. Reportedly, the bug leveraged a nearly empty market to manipulate the exchange rate.

Notably, hackers used the same approach in October 2023, hacking the same protocol for $2.1 million. In the October incident, the vulnerability was a rounding error. At the time, researchers ascribed the vulnerability to Onyx Protocol being a fork of Compound Finance.

How the Code Vulnerability Occurs

With many DeFi protocols being open-source, developers tend to avoid the long approach. They opt to build off of an existing code as opposed to implementing functionality from scratch.

The approach is considered popular as it can improve efficiency and security when done correctly. The downside is that if the template code is not secure, the fork may inherit the vulnerabilities.

“In the case of the Onyx protocol, the Compound Finance code that it used had a known vulnerability that had already been exploited in Hundred Finance and Midas Capital, which also forked the Compound Finance code. However, the Onyx Protocol used the same code and lacked the community support and vigilance needed to prevent the vulnerability from being exploited,” security firm Halborn reported.

This means the Onyx Protocol hack could have been prevented, given the prevalence of rounding errors. Notably, guidance already exists when launching new markets on Compound Finance and its forks.

“At Hexagate, we recommend any Compound V2 fork, when launching new markets to mint some cTokens and burn them to make sure the total supply never goes to zero. When the total supply goes to zero, the protocol becomes vulnerable and this strategy mitigates this situation,” security firm Hexgate guided in April 2023.

These incidences, including a $4.6 million attack on decentralized infrastructure Truflation on Wednesday, reflect the prevalent challenge in the crypto industry, where bad actors use different mechanisms to steal digital assets.

Source

Leave A Reply

Your email address will not be published.