{"id":15372,"date":"2021-12-20T09:29:47","date_gmt":"2021-12-20T08:29:47","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=15372"},"modified":"2021-12-20T09:29:57","modified_gmt":"2021-12-20T08:29:57","slug":"defi-protocol-grim-finance-hacked-with-losses-worth-30-million","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/defi-protocol-grim-finance-hacked-with-losses-worth-30-million\/","title":{"rendered":"DeFi protocol Grim Finance hacked with losses worth $30 Million"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">The latest DeFi protocol to be hit by an exploit is <a href=\"https:\/\/coinscreed.com\/staging\/bitcoiner-loses-900-btc-in-a-defi-attack.html\" data-type=\"post\" data-id=\"14566\">Grim Finance<\/a>, the hack took place on Saturday and was made public by the project in a tweet. All deposits into the Grim Finance vaults have been put on hold to stop any more thefts.<\/h5>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/12\/image-159.png\" alt=\"DeFi protocol Grim Finance hacked with losses worth $30 Million \n\" class=\"wp-image-15373\" width=\"769\" height=\"426\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/12\/image-159.png 637w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/12\/image-159-300x166.png 300w\" sizes=\"(max-width: 769px) 100vw, 769px\" \/><\/figure><\/div>\n\n\n\n<p>An &#8220;aggressive attack&#8221; took $30 million worth of tokens from Grim Finance, a DeFi\u00a0protocol, on Saturday, it said. In a tweet from the project, &#8220;The exploit was found in the contract for the vault, so all of the <a href=\"https:\/\/www.google.com\/search?q=DeFi+protocol+Grim+Finance+hacked+with+losses+worth+%2430+Million&rlz=1C1SQJL_enNG889NG889&oq=DeFi+protocol+Grim+Finance+hacked+with+losses+worth+%2430+Million&aqs=chrome..69i57.1072j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\">vaults and funds are at risk<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>.&#8221;<\/p>\n\n\n\n<p>When users get liquidity provider tokens from decentralized exchanges, Grim promises to get more value out of them if they keep them in a Grim vault.<\/p>\n\n\n\n<p>Grim calls itself a &#8220;compounding yield optimizer.&#8221; Grim says in its protocol documentation that it wants to &#8220;help users get more rewards, without any hassle.&#8221;<\/p>\n\n\n\n<p>Built on top of the Fantom Opera blockchain, which is a smart contract-enabled platform built with the Solidity language and is compatible with Ethereum.<\/p>\n\n\n\n<p>The protocol is built on top of this platform. The hacker used a reentrancy attack, which is an exploit that lets someone make <a href=\"https:\/\/coinscreed.com\/staging\/binance-prohibits-singapore-users-from-making-fiat-deposits-and-spot-crypto-trading.html\" data-type=\"post\" data-id=\"11072\">fake deposits<\/a> into a vault while the first transaction is still going on. This means that the protocol was fooled.<\/p>\n\n\n\n<p>Hello Grim Community,<\/p>\n\n\n\n<p>It is with heavy hearts that we inform you that our platform was exploited today by an external attacker roughly 6 hours ago. The attackers address has been identified with over 30 million dollars worth of theft here&nbsp;<a href=\"https:\/\/t.co\/qA3iBTSepb\" target=\"_blank\">https:\/\/t.co\/qA3iBTSepb<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u2014 Grim Finance (@financegrim)\u00a0<a href=\"https:\/\/twitter.com\/financegrim\/status\/1472357770846519312?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 19, 2021<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p><\/blockquote>\n\n\n\n<p>&#8220;We've told Circle (USDC), DAI, and AnySwap about the attacker's address so that they might be able to stop any more money transfers,&#8221; Grim tweeted. The attacker has already been laundering the stolen money through stablecoin transfers.<\/p>\n\n\n\n<p>Smart contract auditors and investors say that Grim Finance should have used a reentrancy guard. Rugdoc.io says that Grim Finance should have known better and used a reentry guard.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>&#8220;We hope that all projects can learn from this incident that there is a lot of solidity knowledge that most experienced <a href=\"https:\/\/coinscreed.com\/staging\/the-sandbox-everything-you-need-to-know.html\" data-type=\"post\" data-id=\"15352\">solidity developers<\/a> have.&#8221; &#8220;If you haven't done this yet, don't do big projects that cost a lot. Don't get audits from companies that everyone knows aren't worth the money.&#8221;<\/p><\/blockquote>\n\n\n\n<p>Grim shared a report from Solidity Finance that looked at its finance token and vault contracts. According to Solidity Finance's report, &#8220;ReentrancyGuard is used in places where reentry attacks are likely to happen.&#8221;<\/p>\n\n\n\n<p>In the middle of the day on Sunday, all deposits into the Grim Finance vaults have been put on hold to stop any more thefts.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The latest DeFi protocol to be hit by an exploit is Grim Finance, the hack took place on Saturday and was made public by the project in a tweet. All deposits into the Grim Finance vaults have been put on hold to stop any more thefts. An &#8220;aggressive attack&#8221; took $30 million worth of tokens [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":15373,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[73],"tags":[5643,6086,5817],"class_list":["post-15372","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defi-news","tag-defi-2","tag-grim-finance","tag-hack-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/12\/image-159.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/15372","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=15372"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/15372\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/15373"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=15372"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=15372"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=15372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}