Ads ad-300x250
  • Latest
  • Trending
He steals $1.7 million of crypto in 1 click thanks to a stupid bug

He steals $1.7 million of crypto in 1 click thanks to a stupid bug

August 4, 2022
Google Cloud becomes a validator of Tezos (XTZ)

Google Cloud becomes a validator of Tezos (XTZ)

February 23, 2023
How do Web3 and NFTs enrich the live music experience?

How do Web3 and NFTs enrich the live music experience?

January 23, 2023
Paxos offers $1.5 billion deal to MakerDAO for DAI collateralization

Paxos offers $1.5 billion deal to MakerDAO for DAI collateralization

January 23, 2023
SOL down 96.5% since its ATH: Will the Solana blockchain survive FTX?

SOL down 96.5% since its ATH: Will the Solana blockchain survive FTX?

December 30, 2022
The Human Rights Foundation funds the Bitcoin ecosystem (BTC) with $325,000

The Human Rights Foundation funds the Bitcoin ecosystem (BTC) with $325,000

December 22, 2022
What is flipping in crypto?

What is flipping in crypto?

December 18, 2022
BlackRock predicts an unprecedented recession in 2023

BlackRock predicts an unprecedented recession in 2023

December 10, 2022
Waltio outlines strategy to reduce its taxation on cryptocurrencies

Waltio outlines strategy to reduce its taxation on cryptocurrencies

December 1, 2022
BlockFi files for bankruptcy after FTX collapse

BlockFi files for bankruptcy after FTX collapse

November 29, 2022
Solana’s Phantom wallet opens to Ethereum and Polygon

Solana’s Phantom wallet opens to Ethereum and Polygon

November 29, 2022
Vladimir Putin predicts a blockchain-based international payment system

Vladimir Putin predicts a blockchain-based international payment system

November 28, 2022
The Shiba Inu (SHIB) soon at the World Economic Forum?

The Shiba Inu (SHIB) soon at the World Economic Forum?

November 26, 2022
CoinsMag
SignIn / SignUp
  • HOME
  • NEWS
    Google Cloud becomes a validator of Tezos (XTZ)

    Google Cloud becomes a validator of Tezos (XTZ)

    SOL down 96.5% since its ATH: Will the Solana blockchain survive FTX?

    SOL down 96.5% since its ATH: Will the Solana blockchain survive FTX?

    The Human Rights Foundation funds the Bitcoin ecosystem (BTC) with $325,000

    The Human Rights Foundation funds the Bitcoin ecosystem (BTC) with $325,000

    Waltio outlines strategy to reduce its taxation on cryptocurrencies

    Waltio outlines strategy to reduce its taxation on cryptocurrencies

    BlockFi files for bankruptcy after FTX collapse

    BlockFi files for bankruptcy after FTX collapse

    Solana’s Phantom wallet opens to Ethereum and Polygon

    Solana’s Phantom wallet opens to Ethereum and Polygon

  • BLOCKCHAINS
    • All
    • Algorand
    • Avalanche
    • Bitcoin
    • BNB Chain
    • Cardano
    • Cosmos
    • Dogecoin
    • Elrond
    • Ethereum
    • Monero
    • Polkadot
    • Polygon
    • Ripple
    • Shiba Inu
    • Solana
    • Stellar
    • Ternoa
    • Terra
    • Tezos
    • Tron
    Google Cloud becomes a validator of Tezos (XTZ)

    Google Cloud becomes a validator of Tezos (XTZ)

    How do Web3 and NFTs enrich the live music experience?

    How do Web3 and NFTs enrich the live music experience?

    SOL down 96.5% since its ATH: Will the Solana blockchain survive FTX?

    SOL down 96.5% since its ATH: Will the Solana blockchain survive FTX?

    The Human Rights Foundation funds the Bitcoin ecosystem (BTC) with $325,000

    The Human Rights Foundation funds the Bitcoin ecosystem (BTC) with $325,000

    What is flipping in crypto?

    What is flipping in crypto?

  • DEFI
    Paxos offers $1.5 billion deal to MakerDAO for DAI collateralization

    Paxos offers $1.5 billion deal to MakerDAO for DAI collateralization

    BlackRock predicts an unprecedented recession in 2023

    BlackRock predicts an unprecedented recession in 2023

    Free crypto / referral codes

    This (other) billionaire, who prefers Dogecoin to Bitcoin

    This (other) billionaire, who prefers Dogecoin to Bitcoin

    Google and the king of crypto oracles Chainlink (LINK) unveil their joint project

    Google and the king of crypto oracles Chainlink (LINK) unveil their joint project

    The Bitcoin (BTC) hashrate is on the rise again

    The Bitcoin (BTC) hashrate is on the rise again

    Burger King accepts Dogecoin (DOGE) in Brazil… for dog food

    Burger King accepts Dogecoin (DOGE) in Brazil… for dog food

    791 bitcoins bought for $5 9 years ago have finally come to life

    791 bitcoins bought for $5 9 years ago have finally come to life

    Binance: the rise of the BUSD impresses

    Binance: the rise of the BUSD impresses

  • NFT
    How do Web3 and NFTs enrich the live music experience?

    How do Web3 and NFTs enrich the live music experience?

    Is Apple planning to release a movie about Sam Bankman-Fried and the FTX case?

    Is Apple planning to release a movie about Sam Bankman-Fried and the FTX case?

    In the United States, a house in NFT has just been sold for $175,000

    In the United States, a house in NFT has just been sold for $175,000

    CNN is accused of rug pull by the community after its NFT project was stopped

    CNN is accused of rug pull by the community after its NFT project was stopped

    The OpenSea marketplace lands on Avalanche (AVAX)

    The OpenSea marketplace lands on Avalanche (AVAX)

    Japan sees the future in nft and metaverse

    Japan sees the future in nft and metaverse

  • GAMES
    Square Enix partners with Oasys to develop blockchain games

    Square Enix partners with Oasys to develop blockchain games

    Epic Games gets a head start on its Steam competitor

    Epic Games gets a head start on its Steam competitor

    Do you have to be a bot to enjoy web 3 (bad) games?

    Do you have to be a bot to enjoy web 3 (bad) games?

    StepN partners with Atletico and WhaleFin for a collection of exclusive NFTs

    StepN partners with Atletico and WhaleFin for a collection of exclusive NFTs

    Crypto Gaming, an industry revolution this year?

    Crypto Gaming, an industry revolution this year?

  • METAVERSE
    Solana’s Phantom wallet opens to Ethereum and Polygon

    Solana’s Phantom wallet opens to Ethereum and Polygon

    Is Apple planning to release a movie about Sam Bankman-Fried and the FTX case?

    Is Apple planning to release a movie about Sam Bankman-Fried and the FTX case?

    World Cup in Qatar: FIFA plunges into the mawkishness

    World Cup in Qatar: FIFA plunges into the mawkishness

    The United Arab Emirates: a first “meta-nation”?

    The United Arab Emirates: a first “meta-nation”?

    At Meta, employees are forced to log into the Horizon Worlds metaverse

    At Meta, employees are forced to log into the Horizon Worlds metaverse

    No, Decentraland does not have only 38 daily active users

    No, Decentraland does not have only 38 daily active users

    Japan sees the future in nft and metaverse

    Japan sees the future in nft and metaverse

    Yuga Labs unveils its new community board in charge of the project’s evolution

    Yuga Labs unveils its new community board in charge of the project’s evolution

  • FREE CRYPTOS
  • TUTORIALS
    Buy a Ledger wallet on Amazon – Is it really secure?

    Buy a Ledger wallet on Amazon – Is it really secure?

    Odysee | EARN Lbry Credits (LBC) watching videos

    Odysee | EARN Lbry Credits (LBC) watching videos

    Web 3.0: better infrastructure needed to stop centralization

    Web 3.0: better infrastructure needed to stop centralization

    Avoiding NFTs scams: how to spot scams

    Avoiding NFTs scams: how to spot scams

    Is buying real estate in the metaverse a wise investment?

    Is buying real estate in the metaverse a wise investment?

    FOMO, the crypto investor’s worst enemy – 10 Rules to fight it

    FOMO, the crypto investor’s worst enemy – 10 Rules to fight it

No Result
View All Result
CoinsMag
No Result
View All Result

He steals $1.7 million of crypto in 1 click thanks to a stupid bug

August 4, 2022
in DEFI, News
He steals $1.7 million of crypto in 1 click thanks to a stupid bug

Crypto protocols (bridge, DeFi) are regular targets of hackers, who are not idle, even in summer. The developers of smart contracts as full of holes as Swiss cheese, are not idle either. Big mistakes in the code leave some protocols open to unlikely attacks. After the Nomad hack ($190 million), here is the Reaper Farm.

This is the story of a not-so-smart contract

Smart contract auditing firm Paladin revealed a few hours ago on Twitter a new hack in the decentralized finance (DeFi) ecosystem. This time it’s Reaper Farm, which has seen more than $1.7 million siphoned off according to early estimates.

While this is an impressive sum, it seems negligible compared to other recent hacks. Which doesn’t make it any less serious, of course. But the real seriousness of the situation lies in the unthinkable weakness in the code of the Multi Strategy vaults’ smart contract.

According to Paladin, the hacker managed to impersonate the legitimate receiver of the withdrawals. This hack was enabled by the use of the ERC4626 token standard. It allows to authorize other users to withdraw funds. He exploited a blind spot left by the platform team.

The team reacts quickly and well

The official twitter account of Reaper Farm reacted in late afternoon, less than twenty-four hours after spotting the attack. The team posted a post, spelling out the initial details and pledging to reimburse the damaged users right away.

The team managed to salvage 10% of the blocked funds on the Multi Strategy smart contract… by exploiting the flaw themselves. This was perhaps the best option once the hack was identified. A commendable initiative, but unfortunately rather vain.

The developers acknowledge their responsibility in this attack, linked to a lack of internal vigilance. According to @moonsdontburn (image above), three lines of code would have done the trick.

A lack of external audits is cited after the implementation of certain features and in particular that of the ERC-4626. After a last minute change (with audits performed for the old technical-economic model), the necessary steps were not taken in terms of security.

On his side the hacker sent funds to Binance Smart Chain and Ethereum bridges. He then mixed the stolen tokens in order to confuse the tracks on the blockchain. The team announces that it will increase communications and that a repayment plan will be established after internal discussions.

ShareTweetPinSendShareSend
Previous Post

Aave DAO unanimously approves the launch of the GHO stablecoin

Next Post

Magic Eden’s NFTs platform lands on the Ethereum blockchain

Related Posts

Google Cloud becomes a validator of Tezos (XTZ)
Bitcoin

Google Cloud becomes a validator of Tezos (XTZ)

February 23, 2023
2.2k
SOL down 96.5% since its ATH: Will the Solana blockchain survive FTX?
News

SOL down 96.5% since its ATH: Will the Solana blockchain survive FTX?

December 30, 2022
3.8k
The Human Rights Foundation funds the Bitcoin ecosystem (BTC) with $325,000
Bitcoin

The Human Rights Foundation funds the Bitcoin ecosystem (BTC) with $325,000

December 22, 2022
3.2k

Popular news

  • Google Cloud becomes a validator of Tezos (XTZ)

    Google Cloud becomes a validator of Tezos (XTZ)

    0 shares
    Share 0 Tweet 0
  • Paxos offers $1.5 billion deal to MakerDAO for DAI collateralization

    0 shares
    Share 0 Tweet 0
  • How do Web3 and NFTs enrich the live music experience?

    0 shares
    Share 0 Tweet 0
  • SOL down 96.5% since its ATH: Will the Solana blockchain survive FTX?

    0 shares
    Share 0 Tweet 0
  • The Human Rights Foundation funds the Bitcoin ecosystem (BTC) with $325,000

    0 shares
    Share 0 Tweet 0

Categories

  • Privacy Policy

© 2022 - CoinsMag

No Result
View All Result
  • HOME
  • NEWS
  • BLOCKCHAINS
  • DEFI
  • NFT
  • GAMES
  • METAVERSE
  • FREE CRYPTOS
  • TUTORIALS

© 2022 - CoinsMag

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Ads Blocker Image Powered by Code Help Pro

Ads Blocker Detected!!!

We have detected that you are using extensions to block ads. Please support us by disabling these ads blocker.