{"id":20995,"date":"2022-03-16T07:42:01","date_gmt":"2022-03-16T06:42:01","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=20995"},"modified":"2022-03-16T07:42:14","modified_gmt":"2022-03-16T06:42:14","slug":"agave-and-hundred-finance-defi-protocols-attacked-with-a-loss-of-11-million","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/agave-and-hundred-finance-defi-protocols-attacked-with-a-loss-of-11-million\/","title":{"rendered":"Agave And Hundred Finance DeFi Protocols Attacked With A Loss Of $11 Million"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">Following the attack, Agave and Hundred Finance have stopped operations to allow proper investigation into the incident.<\/h5>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"848\" height=\"477\" data-id=\"20996\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/white_hat_hacker.jpg\" alt=\"\" class=\"wp-image-20996\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/white_hat_hacker.jpg 848w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/white_hat_hacker-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/white_hat_hacker-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/white_hat_hacker-150x84.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/white_hat_hacker-750x422.jpg 750w\" sizes=\"(max-width: 848px) 100vw, 848px\" \/><\/figure>\n<figcaption class=\"blocks-gallery-caption\">Agave and Hundred Finance attacked with a loss of $11 million<\/figcaption><\/figure>\n\n\n\n<p>After performing a &#8220;re-entrancy&#8221; attack against DeFi lending protocol applications Agave and Hundred Finance, a hacker made off with <a href=\"https:\/\/blockscout.com\/xdai\/mainnet\/block\/21120284\/transactions\" data-type=\"URL\" data-id=\"https:\/\/blockscout.com\/xdai\/mainnet\/block\/21120284\/transactions\" target=\"_blank\" rel=\"noreferrer noopener\">around $11 million<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> in Wrapped ETH, Wrapped BTC, Chainlink, USDC, Gnosis, and Wrapped XDAI.<\/p>\n\n\n\n<p>The incident comes less than 24 hours after the Deus Finance heist, in which hackers stole more than $3 million in Dai and Ethereum from the loan contract platform.<\/p>\n\n\n\n<p>According to CoinGecko data, Agave's token, AGVE, plummeted by 20% following the hack. Following the announcement of the exploit, Hundred Finances' token HND plummeted 3.5 percent, although it has since recovered to a 24-hour high.<\/p>\n\n\n\n<p>&#8220;Agave is now researching an exploit on the agave finance protocol,&#8221; <a href=\"https:\/\/mobile.twitter.com\/Agave_lending\/status\/1503725275917565954\" data-type=\"URL\" data-id=\"https:\/\/mobile.twitter.com\/Agave_lending\/status\/1503725275917565954\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Agave tweeted<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> at 1:30 p.m. UTC on Tuesday. &#8220;We will update you as soon as we learn more.&#8221; The contracts have been put on hold until the problem is handled, according to the report.<\/p>\n\n\n\n<p>The Hundred Finance team also tweeted that it had been exploited on the Gnosis chain and had halted trading while it investigated.<\/p>\n\n\n\n<p>According to on-chain research, <a href=\"https:\/\/etherscan.io\/address\/0x0a16a85be44627c10cee75db06b169c7bc76de2c\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">the attacker's address<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> delivered over 2,100 ETH to a crypto mixer, valued over $5.5 million, in an attempt to launder the stolen tokens.<\/p>\n\n\n\n<p>Shegen (@shegenerates), a Solidity developer and creator of an NFT liquidity protocol app, tweeted that she lost $225,000 in the attack and that her investigations revealed that the attacker used a wETH contract function on Gnosis Chain to continue borrowing crypto before the apps could calculate the debt, which would prevent further borrowing.<\/p>\n\n\n\n<p>The attacker used this technique repeatedly, borrowing against the same collateral until the funds in the protocols were depleted.<\/p>\n\n\n\n<p>While the <a href=\"https:\/\/coinscreed.com\/staging\/introduction-to-decentralized-finance-defi-cryptocurrencies-and-smart-contract.html\" data-type=\"post\" data-id=\"3850\">smart contract<\/a> on Agave is virtually the same as the one on Aave, which secures $18.4 billion, Shegen told Cointelegraph that &#8220;every security researcher has audited it,&#8221; therefore &#8220;it's reasonable to trust the contract is safe.&#8221;<\/p>\n\n\n\n<p>&#8220;I think this theft stands out more than other larger ones,&#8221; Shegen said, noting that while it was a tiny hack compared to others that took millions of dollars, the similarities to Aave meant &#8220;it seemed top tier safe, but wasn't and that break of confidence hurts.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p>\u201cIt\u2019s like you can't even trust \u201csafe\u201d code.\u201d<\/p><\/blockquote><\/figure>\n\n\n\n<p>The difference between Aave and Agave, according to blockchain security researcher Mudit Gupta, is that &#8220;Aave actively checks for re-entrancy before putting tokens on the public network to avoid similar attacks.&#8221;<\/p>\n\n\n\n<p>Shegen indicated that she did not hold the Agave developers responsible for the attack's failure to be prevented.<\/p>\n\n\n\n<p>&#8220;Maybe the developer should not have allowed tokens with callbacks to be utilized in the platform, or put more re-entrancy guards,&#8221; she said.<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p>\u201cCurve, for example, was not hacked today, because it has extra re-entrancy guards, but I don't blame Luigy and the Agave team because it's so unlikely that this would have happened, and slipped past many people.\u201d<\/p><\/blockquote><\/figure>\n\n\n\n<p>Shegen also refused to criticize Gnosis for producing tokens with a callback function that the hacker exploited, claiming that the feature prevents users from losing their cryptocurrency by accident.<\/p>\n\n\n\n<p>&#8220;That's a fantastic feature for bridged tokens; it's simply a sad and unlucky condition in my perspective.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following the attack, Agave and Hundred Finance have stopped operations to allow proper investigation into the incident. After performing a &#8220;re-entrancy&#8221; attack against DeFi lending protocol applications Agave and Hundred Finance, a hacker made off with around $11 million in Wrapped ETH, Wrapped BTC, Chainlink, USDC, Gnosis, and Wrapped XDAI. The incident comes less than [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":20997,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[8151,8150,8152],"class_list":["post-20995","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-agave","tag-hacking-2","tag-hundred-finance"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/white_hat_hacker-1.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/20995","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=20995"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/20995\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/20997"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=20995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=20995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=20995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}