Exchange liquidity protocol Curve Finance was targeted by hackers who stole about $570,000, according to a screenshot of the protocol’s wallet shared on Twitter Aug. 9.
After the hack, Curve Finance advised users to avoid using curve.fi or curve.exchange until the protocol operators found the origin of the exploit.
“We are becoming aware of a potential front-end issue approving a bad contract. Please do not carry out any releases or exchange processes for the time being. We’re trying to pinpoint the issue, but for your safety, don’t use curve.fi or curve.exchange for now,” the Telegram announcement said.
Upon initial investigation, the team determined that the attack was likely a violation of the @iwantmyname system and not the registrar layer. “The contract that needs to be revoked is: 0x9eb5f8e83359bb5013f3d8eee60bdce5654e8881 If you agreed to it, please revoke it immediately on https://revoke.cash,” he added.
The team behind the project also came up with the following theory from Lefteris Karapetsas, the founder of the Rotkia app, about the attack affecting their Domain Name System [DNS],
“This is DNS spoofing. Cloned the site, pointed the DNS point to its IP where the cloned site is served, and added permission requests to a malicious contract.”
From the details above, it appears that the hacker likely tampered with the Domain Name System record for the log, redirected users to a fake clone and approved a malicious contract. However, the program’s contract was unaffected by the onslaught.
Curve Finance native token down 8%
Curve Finance is a popular automated market maker [AMM] This provides an efficient way to exchange tokens while maintaining low fees and low slippage by only housing liquidity pools composed of assets with similar behavior.
After the incident, the CRV token saw an 8% decline but recorded a minor 5% recovery.
Immediately after the announcement, the decentralized financing [DeFi] The operators of the protocol said by telegram that they found the cause of the problem and fixed it.
“If you have approved any contracts on Curve in the last few hours, please revoke them immediately,” they continued. The log also advised users to use curve.exchange until curve.fi distribution returns to normal.
“Updates for http://curve.fi should be widespread by now, which means it should be safe to use.”
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.