• bitcoinBitcoin (BTC) $ 91,428.00
  • ethereumEthereum (ETH) $ 3,120.23
  • tetherTether (USDT) $ 0.998775
  • bnbBNB (BNB) $ 908.28
  • xrpXRP (XRP) $ 2.06
  • usd-coinUSDC (USDC) $ 0.999759
  • tronTRON (TRX) $ 0.298845
  • staked-etherLido Staked Ether (STETH) $ 3,118.14
  • dogecoinDogecoin (DOGE) $ 0.137758
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • cardanoCardano (ADA) $ 0.388452
  • wrapped-stethWrapped stETH (WSTETH) $ 3,818.19
  • bitcoin-cashBitcoin Cash (BCH) $ 613.66
  • moneroMonero (XMR) $ 638.46
  • whitebitWhiteBIT Coin (WBT) $ 54.95
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,394.65
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 91,211.00
  • wrapped-eethWrapped eETH (WEETH) $ 3,386.02
  • usdsUSDS (USDS) $ 0.999652
  • chainlinkChainlink (LINK) $ 13.15
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998590
  • leo-tokenLEO Token (LEO) $ 9.07
  • wethWETH (WETH) $ 3,119.07
  • stellarStellar (XLM) $ 0.221716
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 91,326.00
  • suiSui (SUI) $ 1.78
  • zcashZcash (ZEC) $ 398.14
  • ethena-usdeEthena USDe (USDE) $ 0.999266
  • avalanche-2Avalanche (AVAX) $ 13.67
  • litecoinLitecoin (LTC) $ 76.37
  • hyperliquidHyperliquid (HYPE) $ 24.31
  • canton-networkCanton (CC) $ 0.141375
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • hedera-hashgraphHedera (HBAR) $ 0.115866
  • usdt0USDT0 (USDT0) $ 0.998703
  • susdssUSDS (SUSDS) $ 1.08
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.168114
  • daiDai (DAI) $ 0.999970
  • the-open-networkToncoin (TON) $ 1.74
  • crypto-com-chainCronos (CRO) $ 0.099899
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • paypal-usdPayPal USD (PYUSD) $ 0.999864
  • usd1-wlfiUSD1 (USD1) $ 0.998986
  • polkadotPolkadot (DOT) $ 2.08
  • uniswapUniswap (UNI) $ 5.40
  • mantleMantle (MNT) $ 0.953925
  • rainRain (RAIN) $ 0.008711
  • memecoreMemeCore (M) $ 1.69
  • bittensorBittensor (TAO) $ 283.46
  • aaveAave (AAVE) $ 168.60
  • bitget-tokenBitget Token (BGB) $ 3.57
  • pepePepe (PEPE) $ 0.000006
  • tether-goldTether Gold (XAUT) $ 4,592.36
  • okbOKB (OKB) $ 111.02
  • nearNEAR Protocol (NEAR) $ 1.71
  • falcon-financeFalcon USD (USDF) $ 0.997303
  • jito-staked-solJito Staked SOL (JITOSOL) $ 174.23
  • ethereum-classicEthereum Classic (ETC) $ 12.36
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,118.15
  • pax-goldPAX Gold (PAXG) $ 4,606.47
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.206332
  • internet-computerInternet Computer (ICP) $ 3.17
  • ethenaEthena (ENA) $ 0.215496
  • aster-2Aster (ASTER) $ 0.695309
  • solanaWrapped SOL (SOL) $ 138.94
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.151771
  • htx-daoHTX DAO (HTX) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.78
  • binance-staked-solBinance Staked SOL (BNSOL) $ 151.98
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • worldcoin-wldWorldcoin (WLD) $ 0.560606
  • global-dollarGlobal Dollar (USDG) $ 0.999718
  • kucoin-sharesKuCoin (KCS) $ 11.15
  • pump-funPump.fun (PUMP) $ 0.002457
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • ripple-usdRipple USD (RLUSD) $ 0.999983
  • aptosAptos (APT) $ 1.79
  • wbnbWrapped BNB (WBNB) $ 907.37
  • bfusdBFUSD (BFUSD) $ 0.998483
  • skySky (SKY) $ 0.057195
  • hash-2Provenance Blockchain (HASH) $ 0.024520
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,602.81
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999641
  • kaspaKaspa (KAS) $ 0.047204
  • cosmosCosmos Hub (ATOM) $ 2.54
  • ondo-financeOndo (ONDO) $ 0.391577
  • render-tokenRender (RENDER) $ 2.34
  • gatechain-tokenGate (GT) $ 10.27
  • arbitrumArbitrum (ARB) $ 0.203208
  • algorandAlgorand (ALGO) $ 0.130677
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,309.88
  • myx-financeMYX Finance (MYX) $ 5.88
  • midnight-3Midnight (NIGHT) $ 0.066963
  • filecoinFilecoin (FIL) $ 1.48
  • official-trumpOfficial Trump (TRUMP) $ 5.36
  • story-2Story (IP) $ 3.00
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,804.32
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 91,551.00
  • ignition-fbtcFunction FBTC (FBTC) $ 91,527.00
  • vechainVeChain (VET) $ 0.011386
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 91,307.00
  • nexoNEXO (NEXO) $ 0.957612
  • flare-networksFlare (FLR) $ 0.011240
  • usddUSDD (USDD) $ 0.998425
  • bonkBonk (BONK) $ 0.000010
  • xdce-crowd-saleXDC Network (XDC) $ 0.046152
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,380.97
  • usdtbUSDtb (USDTB) $ 0.999484
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,284.73
  • ousgOUSG (OUSG) $ 113.94
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.95
  • sei-networkSei (SEI) $ 0.120491
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999869
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999709
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.011880
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 91,351.00
  • clbtcclBTC (CLBTC) $ 91,345.00
  • morphoMorpho (MORPHO) $ 1.30
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,333.52
  • blockstackStacks (STX) $ 0.384088
  • beldexBeldex (BDX) $ 0.090922
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 161.51
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • jupiter-exchange-solanaJupiter (JUP) $ 0.208594
  • usdaiUSDai (USDAI) $ 1.00
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.282786
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.95
  • wrapped-flareWrapped Flare (WFLR) $ 0.011245
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,312.68
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,117.75
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999832
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.958038
  • optimismOptimism (OP) $ 0.314870
  • tezosTezos (XTZ) $ 0.561471
  • c8ntinuumc8ntinuum (CTM) $ 0.137587
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • curve-dao-tokenCurve DAO (CRV) $ 0.399043
  • dashDash (DASH) $ 45.50
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,118.78
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.57
  • chilizChiliz (CHZ) $ 0.054156
  • usual-usdUsual USD (USD0) $ 0.997922
  • spx6900SPX6900 (SPX) $ 0.592146
  • tbtctBTC (TBTC) $ 91,405.00
  • lido-daoLido DAO (LDO) $ 0.620515
  • lighterLighter (LIT) $ 2.07
  • aerodrome-financeAerodrome Finance (AERO) $ 0.562433
  • injective-protocolInjective (INJ) $ 5.14
  • gtethGTETH (GTETH) $ 3,116.21
  • ghoGHO (GHO) $ 0.999744
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999228
  • true-usdTrueUSD (TUSD) $ 0.998382
  • flokiFLOKI (FLOKI) $ 0.000051
  • ether-fiEther.fi (ETHFI) $ 0.735658
  • msolMarinade Staked SOL (MSOL) $ 187.84
  • fasttokenFasttoken (FTN) $ 1.09
  • celestiaCelestia (TIA) $ 0.542709
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,367.41
  • syrupMaple Finance (SYRUP) $ 0.394549
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • stader-ethxStader ETHx (ETHX) $ 3,362.36
  • the-graphThe Graph (GRT) $ 0.041214
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,493.27
  • newton-projectAB (AB) $ 0.004461
  • jasmycoinJasmyCoin (JASMY) $ 0.008585
  • riverRiver (RIVER) $ 21.66
  • sbtc-2sBTC (SBTC) $ 91,280.00
  • starknetStarknet (STRK) $ 0.081992
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.205490
  • usdbUSDB (USDB) $ 1.01
  • staked-aaveStaked Aave (STKAAVE) $ 167.37
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • doublezeroDoubleZero (2Z) $ 0.117519
  • iotaIOTA (IOTA) $ 0.095516
  • justJUST (JST) $ 0.040762
  • sun-tokenSun Token (SUN) $ 0.020690
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.19
  • conflux-tokenConflux (CFX) $ 0.075216
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.384036
  • bitcoin-svBitcoin SV (BSV) $ 19.12
  • pyth-networkPyth Network (PYTH) $ 0.065353
  • fartcoinFartcoin (FARTCOIN) $ 0.373421
  • gnosisGnosis (GNO) $ 141.00
  • dogwifcoindogwifhat (WIF) $ 0.370930
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.877507
  • apenftAINFT (NFT) $ 0.00000037
  • pendlePendle (PENDLE) $ 2.15
  • chain-2Onyxcoin (XCN) $ 0.008482
  • cap-usdCap USD (CUSD) $ 1.00
  • crvusdcrvUSD (CRVUSD) $ 0.999355
  • euro-coinEURC (EURC) $ 1.17
  • kaiaKaia (KAIA) $ 0.060959
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 91,331.00
  • telcoinTelcoin (TEL) $ 0.003721
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.137626
  • olympusOlympus (OHM) $ 21.51
  • kinesis-goldKinesis Gold (KAU) $ 147.57

Three DeFi hacks net $10 million in 48 hours despite ‘renaissance moment’

0 88

Three DeFi hacks net $10 million in 48 hours despite ‘renaissance moment’

Yesterday, two hacks on decentralized finance (DeFi) protocols netted a total of over $5 million, with a further $5 million siphoned off from compromised wallets on Wednesday.

While the founders of two OG protocols, Aave and Maker (now Sky), bro’d down over Starcraft while basking in a “DeFi renaissance moment,” some of the sector’s less well-established projects were going down in history for the wrong reasons.

Repeat DeFi hack or a new bug?

First up was Onyx Protocol whose $3.8 million loss was first thought to be a repeat of the well-known bug that drained $2.1 million from the project toward the back end of last year.

Onyx is a fork of Compound Finance, which contains an infamous vulnerability in which freshly-launched, empty lending markets are briefly left open to a price manipulation attack, if not handled correctly.

Given the popularity of Compound’s v2 codebase with fast-forking DeFi devs, the bug is exploited with alarming regularity across the sector, and was initially identified as having been the cause of Onyx’s latest loss.

However, as the team pointed out in a ‘post-mortem’ thread on X (formerly Twitter), this time the vulnerability also lay in the platform’s ‘NFT Liquidation contract.’ The attacker was able to drain the vUSD stablecoin which was then sold off, causing it to depeg.

Something’s not adding up

Next came ‘bitcoin restaking’ protocol Bedrock which appeared to be overly bullish on ETH, costing it around $2 million.

The faulty code allowed users to mint Bedrock’s uniBTC token at a 1:1 ratio with staked ETH tokens, not taking into account the price difference between the two assets (valued at the time at approximately $65,000 vs $2,650, respectively).

The uniBTC tokens were then sold off for an alternative wrapped bitcoin token, for a return of almost 25x.

Crypto security auditor Dedaub claims to have identified the vulnerability in advance, stating that such a simple bug could be discovered and exploited automatically by ‘fuzzing bots.’

Despite warning the Bedrock team two hours before the attack, there was no response due time zone differences. However, by raising the issue separately with Pendle, a platform with $30 million of exposure to uniBTC, further losses were successfully averted.

The Bedrock team responded to the incident, reassuring users that all uniBTC collateral remains intact. It estimated the losses at “approximately $2 million (mostly in DEX LPs),” adding that a “comprehensive reimbursement plan is being finalized.”

Compromised keys?

On Wednesday, real-world-asset-focused Truflation warned of “some abnormal activity,” which it attributed to a malware attack.

Blockchain investigator ZachXBT traced total losses of over $5 million from addresses identified as the project’s “treasury multisig and personal wallets,” providing a list of addresses via his Investigations Telegram channel.

While the initial disclosure was scant on details, it does mention a reward to any whitehats able to aid the investigation. This was followed up with an on-chain message to the hacker, offering a 10% ‘bounty’ for the return of the funds.

Assuming funds aren’t returned before 8am (UTC) on Saturday, the bounty will be opened up to the public in return for information leading to a conviction.

Source

Leave A Reply

Your email address will not be published.