Skip to content Skip to sidebar Skip to footer

dForce Loses Over $3M in Shocking Attack

Decentralized finance (DeFi) protocol dForce has suffered a reentrancy vulnerability attack leading to the loss of $3.6 million worth of crypto assets.

DForce confirms the return of exploited $3.65m to their vaults

The attacker targeted the protocol’s vault on the automated market maker (AMM) platform Curve Finance, which operates on the Arbitrum and Optimism blockchains.

dForce Exploited for $3.65M 

The hack was first flagged by Twitter user @ZoomerAnon who announced that dForce had lost about $1.7 million in a series of flash loan transactions on the Optimism chain. The attack was later confirmed by blockchain security firm PeckShield, which rounded the total losses to 2,300 ETH tokens ($3.65 million).

The hacker exploited a reentrancy vulnerability present in a smart contract function that dForce uses to obtain oracle prices on Arbitrum and Optimism when connected to Curve.

A reentrancy attack occurs when a bad actor exploits a bug in a smart contract and repeatedly withdraws funds transferred to an unauthorized contract. Such attacks are publicly known to occur on protocols linked to Curve, while the AMM remains untouched.

PeckShield further explained that the perpetrator had manipulated the price of wrapped staked ETH in the Curve vault (wstETHCRV-gauge) and was able to liquidate several flash loan positions using the wstETHCRV-gauge as collateral.

The initial amount, 0.99ETH, was withdrawn from the DeFi system RAILGUN Project and transferred through Synapse Network to Arbitrum and Optimism. At press time, the funds were still sitting in the exploiter’s account.

DForce confirms the return of exploited $3.65m to their vaults

dForce Offers Bounty to the Attacker

dForce confirmed that the attack, which was distinct to only its wstETH/ETH-Curve vault, had been contained, and all vaults paused. The protocol assured users that funds supplied to other vaults, including lending, were safe.

The platform also disclosed that the exploiter created a $2.3 million protocol debt after liquidating 1,031.42 and wstETH/ETH on Arbitrum and Optimum, respectively.

DForce confirms the return of exploited $3.65m to their vaults

“We have engaged with security firm @SlowMist_team and our ecosystem partners to further investigate the matter and would like to offer a bounty to the exploiter if the funds were returned. Stay tuned for further updates,” dForce said.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.


SUBSCRIBE

You may subscribe to our updates using the form below.

You may subscribe to our updates here.

Financial Futurism © 2024. All rights reserved.

Disclaimer: The information provided here is not financial advice - it is for informational or entertainment purposes only. The opinions expressed here are not necessarily those of Financial Futurism writers or staff. Trading and investing involve risk, so you should always conduct your own research before investing. If you are planning to make an investment, you should contact an authorized financial expert. You should not invest money that you cannot lose.

.

Financial Futurism © 2024.
All rights reserved.

Disclaimer: The information provided here is not financial advice - it is for informational or entertainment purposes only. The opinions expressed here are not necessarily those of Financial Futurism writers or staff. Trading and investing involve risk, so you should always conduct your own research before investing. You should not invest money that you cannot lose.