Ultimate magazine theme for WordPress.

Beanstalk DeFi project robbed of $182 million in flash loan attack

Decentralized finance (DeFi) project Beanstalk has lost $182 million in a flash lending attack.

It may seem more like a corporate heist than a typical cyber attack. Nonetheless, this security incident was possible after the unknown attacker secured the project’s voting rights, which were required to transfer reserve funds from the project’s liquidity pools.

On April 19, Beanstalk, an Ethereum-based loan-based stablecoin protocol project, announced that the platform had faced a flash loan attack two days earlier.

The cyberattack exploited the project’s protocol governance mechanism. According to an autopsy conducted by Omniscia, the exploit occurred due to the recent implementation of the Curve LP silos, “which ultimately allowed the attacker to perform an emergency execution of a malicious proposal that siphoned project funds.”

Flash lending features in DeFi projects allow users to borrow large amounts of virtual funds for short periods of time. In the case of Beanstalk Farm, voting rights were based on the amount of tokens held.

Omniscia says that after the attacker secured a flash loan — and with it extensive voting rights normally used to accept or reject changes in the protocol’s code — an emergency governance mechanism was abused to create a malicious Proposal to “vote” and allow yourself to send money to a wallet you control.

The lightning loan was then repaid.

According to PeckShield, who first spotted the attack, total losses were $182 million, with the attacker raking in about $80 million. Other losses were due to the fees required to run the flash loan.

Stolen assets were then liquidated in Ethereum (ETH). Beanstalk says about $76 million in non-Beanstalk assets were stolen from liquidity pools.

Beanstalk was halted after discovering the attack, but this was not enough to prevent the theft or recover the stolen funds.

Remaining BEANs in the exploiter contract were burned.

In a tweet, Beanstalk offered the attacker 10% of the stolen funds as a bug bounty if they returned 90%.

Screenshot-2022-04-21-at-13-36-34.png

Notably, the thief also seems to have sent $250,000 to the Ukrainian aid fund Ukraine Crypto Donation.

“Beanstalk Farms, the decentralized development team working on Beanstalk, is preparing a strategy to safely relaunch a more secure Beanstalk with a way forward,” the project reads.

The roadmap has several goals: attract investment to restart Beanstalk; “Preserve as much as possible of each farmer’s stalk, seed and pod positions” and “align new capital with previous stalk and pod owners”.

“This staggering amount of stolen cash will not only bite financially but potentially destroy trust,” commented Jake Moore, Global Cyber ​​Security Advisor at ESET. “Attackers heavily target crypto-financial systems due to the extremely high rewards, while often leaving no evidence whatsoever.”

Previous and related coverage

Do you have a tip? Get in touch securely via WhatsApp | Signal on +447713 025 499 or over at Keybase: charlie0

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: