Ultimate magazine theme for WordPress.

Another somber day for DeFi as hackers loot $30M from Fantom Blockchain Yield Farming Project

Hackers looted more than $30 million from a decentralized finance project over the weekend, prompting a user exodus that drained more than 95% of the tokens invested in the project.

Popular yield farming project Grim Finance, which launched over the weekend with a $99 million stake, was left with just $4 million worth of Fantom tokens after users emptied the project’s vaults to find more prevent losses.

Learn more: PYMNTS DeFi Series: What is Yield Farming and Liquidity Mining?

The theft comes days after blockchain intelligence firm Chainalysis released its 2021 Crypto Crime Report, which revealed more than $7.7 billion was stolen from cryptocurrency investors this year, an increase of more than 80% compared to 2020. The developers at Grim Finance, however, described the robbery as “advanced”. A “rug pull” attack, which exploited a vulnerability in the smart contracts controlling the project, was the biggest source of loss.

After tweeting, “It is with a heavy heart that we inform you that our platform was exploited by an external attacker today,” the Grim Finance project announced that it had suspended all withdrawals “to prevent future funds from being compromised.” “, adding: Please withdraw all your money IMMEDIATELY.”

A known bug

Powered by the Ethereum-compatible Fantom Opera blockchain, Grim Finance is a “yield optimizer” – a project that allows users to “vault” cryptocurrency tokens they earn by investing in other DeFi lending/credit projects and decentralized exchanges (DEXs). “ can block to earn more interest on the funds won.

Grim Finance, a project whose logo is a crimson specter holding a sickle, explained that the losses were caused by a “reentrancy” bug in the smart contracts that run the platform. Essentially, it allows hackers to make a legitimate deposit and then make multiple fake deposits, thereby tricking the vaults into releasing the phantom funds once the original transaction is complete.

The stolen Fantom (FTM) was then transferred to other DEXs and traded for other cryptocurrencies while the hacker got away with the ill-gotten gains.

One of the first comments in the @GrimFinance Twitter thread announcing the loss denied the developers’ claim that the theft was an “advanced attack” and claimed reentrant bugs were a known type of exploit that should have been discovered during an examination.

That opinion was shared by Rugdoc.io, a community-organized DeFi security project, which laid out the events in very easy-to-understand detail and said the hack was due to a “big no-no” – the project’s failure to make a “Reentrancy Guard” in a place in the smart contract “that it was absolutely needed” and giving users too much control over the process.

Grim’s review by Solidity Finance showed that the project was aware of this type of exploit and claimed that “ReentrancyGuard is deployed where relevant” to prevent reentrancy attacks.

Solidity tweeted a mea culpa, saying Grim Finance’s tender came in the fall when the company was growing rapidly.

“This audit was conducted by an analyst who was new to the team and while our CTO was on vacation; and unfortunately this issue was not addressed in our peer review process,” it said. “We are disappointed that this issue, which we regularly recommend fixing, slipped through our process while we were overwhelmed and hired new analysts in August.”

Solidity said it reviewed more than 900 projects and this was only the second exploit the company had overlooked.

“Since then,” it said, “we have continued to expand our team, strengthened internal competencies and improved our peer review process.”

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: