Ultimate magazine theme for WordPress.

GYM network log hacked, $2.1 million stolen: Here’s how

Vladislav Sopov

A bug in a single function of a liquidity pool codebase resulted in seven-figure losses

contents

  • GYM Network made it possible to increase the balance without actually depositing any money
  • More compromised protocols?

GYM Network is a cross-protocol DeFi aggregator designed to streamline the process of yield farming on the BNB chain and make it straightforward for newbies.

GYM Network made it possible to increase the balance without actually depositing any money

Today, June 8, 2022, one of its elements, GymSinglePool, was attacked by GYM Network, according to the statement by cybersecurity provider PeckShield.

@GymNet_Official’s GymSinglePool is hacked with a loss of $2.1M (~7.5K BNB). The error is due to the lack of caller verification, which is exploited to top up the balance without making a payment. The stolen funds are now being deposited via @TornadoCash https://t.co/I2eD8WBWXk pic.twitter.com/tUl3wnuIAW

— PeckShield Inc. (@peckshield) June 8, 2022

The pool’s architecture lacked a caller verification tool: malefactors could top up their balances without sending them any money.

This design flaw was exploited, stealing more than $2.1 million. The attackers immediately began transporting their loot to the Tornado Cash transaction obfuscation service.

To sue

GYM, a core native utility and governance token of the protocol, immediately lost over 50% of its price, plunging from $0.00099 to $0.00048.

More compromised protocols?

Ironically, the protocol was audited twice by PeckShield itself and by CertiK. It also uses Alpaca Finance’s codebase, which has been audited 20 times.

Blockchain researcher Kyrian Alex (Kyrian.sol) emphasized that GYM Network is far from the only protocol to contain a similar design flaw:

This isn’t the first protocol to be hacked for “lack of caller verification.” Apparently I need to review many of these clone logs to look for the same vulnerability.

Team representatives confirmed the fact of attack. The GYM Network community coordinator explained that the vulnerability was exposed in a new “Claim and Reinvest” tool deployed two days ago.

At press time, the source of the bug has been identified and fixed, the team adds.

https://platform.twitter.com/widgets.js

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: