{"id":21656,"date":"2022-03-23T17:47:57","date_gmt":"2022-03-23T16:47:57","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=21656"},"modified":"2022-03-23T18:11:52","modified_gmt":"2022-03-23T17:11:52","slug":"cashio-crashes-to-zero-after-hack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/cashio-crashes-to-zero-after-hack\/","title":{"rendered":"Cashio crashes to zero after multi million dollar hack"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">Attackers exploited an &#8220;unlimited mint bug&#8221; to rob Cashio, a <a href=\"https:\/\/coinscreed.com\/staging\/terra-stablecoin-becomes-largest-and-stablecoin.html\" data-type=\"post\" data-id=\"15398\" target=\"_blank\" rel=\"noreferrer noopener\">Solana-based stablecoin<\/a> project, off millions of dollars.<\/h5>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"758\" height=\"388\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-161.png\" alt=\"Cashio crashes to zero after multi million dollar hack | Coinscreed\" class=\"wp-image-21661\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-161.png 758w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-161-300x154.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-161-150x77.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-161-750x384.png 750w\" sizes=\"(max-width: 758px) 100vw, 758px\" \/><\/figure>\n\n\n\n<p>After an &#8220;unlimited mint flaw&#8221; allowed attackers to manufacture tokens without providing collateral, the price of Cashio's dollar-pegged stablecoin CASH dropped drastically from $1 to $0.00005.<\/p>\n\n\n\n<p>oxGhostChain, a Cashio developer, took to Twitter to offer a warning &#8220;&#8221;We believe we have uncovered the root problem,&#8221; the team said, adding that they are investigating the issue. <\/p>\n\n\n\n<p>&#8220;Please take your money out of the pools. A postmortem will be published as soon as possible&#8221;, <a href=\"https:\/\/twitter.com\/i\/web\/status\/1506571243067224064\" data-type=\"URL\" data-id=\"https:\/\/twitter.com\/i\/web\/status\/1506571243067224064\" target=\"_blank\" rel=\"noreferrer noopener\">tweeted oxGhostChain<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>.<\/p>\n\n\n\n<p>According to a report, the hack has drained around $28 million from Cashio's protocol. <\/p>\n\n\n\n<p>Nonetheless, Samczsun, a research partner at <a href=\"https:\/\/coinscreed.com\/staging\/crypto-investor-raises-1-5-billion-fund-for-web3-projects.html\" data-type=\"post\" data-id=\"21567\" target=\"_blank\" rel=\"noreferrer noopener\">Web3<\/a> investment company Paradigm, painted a bleaker picture today on Twitter.<\/p>\n\n\n\n<p>According to the researcher, &#8220;Another day, another <a href=\"https:\/\/coinscreed.com\/staging\/defitop-10-crypto-rug-pulls.html\" data-type=\"post\" data-id=\"20336\" target=\"_blank\" rel=\"noreferrer noopener\">Solana phishing scam<\/a>. Cashio App lost roughly $50 million this time (based on a quick skim). What caused this to happen?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Another day, another Solana fake account exploit. This time, <a href=\"https:\/\/twitter.com\/CashioApp?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@CashioApp<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> lost around $50M (based on a quick skim). How did this happen? <a href=\"https:\/\/t.co\/t7ThWL4zr1\" target=\"_blank\">pic.twitter.com\/t7ThWL4zr1<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; samczsun (@samczsun) <a href=\"https:\/\/twitter.com\/samczsun\/status\/1506578902331768832?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">March 23, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>The project has not responded to any request for confirmation of how much they actually lost.<\/p>\n\n\n\n<p>Cashio Dollar is a stablecoin based on <a href=\"https:\/\/coinscreed.com\/staging\/coinbase-wallet-adds-support-for-solana-network.html\" data-type=\"post\" data-id=\"21228\" target=\"_blank\" rel=\"noreferrer noopener\">Solana<\/a> that was launched in November 2021.<\/p>\n\n\n\n<p>Anyone can literally create CASH by depositing Saber USDT-USDC liquidity provider (LP) tokens first.<\/p>\n\n\n\n<p>Saber is a decentralized Solana exchange similar to Uniswap. <\/p>\n\n\n\n<p>Users who deposit tokens into Saber's liquidity pools earn LP tokens, which represent a token of their deposit.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Cashio theft not actually the first<\/h2>\n\n\n\n<p>This isn't the first time that a <a href=\"https:\/\/coinscreed.com\/staging\/crypto-theft-defiance-capital-founder-loses-1-6-million-worth-of-nft-in-hot-wallet-hack.html\" data-type=\"post\" data-id=\"21458\" target=\"_blank\" rel=\"noreferrer noopener\">DeFi <\/a><a href=\"https:\/\/coinscreed.com\/staging\/crypto-theft-defiance-capital-founder-loses-1-6-million-worth-of-nft-in-hot-wallet-hack.html\" data-type=\"URL\" data-id=\"https:\/\/coinscreed.com\/staging\/crypto-theft-defiance-capital-founder-loses-1-6-million-worth-of-nft-in-hot-wallet-hack.html\" target=\"_blank\" rel=\"noreferrer noopener\">protocol has been plundered<\/a> for millions of dollars thanks to a &#8220;infinite mint&#8221; bug.<\/p>\n\n\n\n<p>A group of DeFi engineers used a similar vulnerability on the DeFi insurance project Cover in December 2020, generating bogus tokens to supply liquidity to Balancer.<\/p>\n\n\n\n<p>The attackers then exchanged the staked tokens for COVER tokens, which they sold repeatedly on exchanges.<\/p>\n\n\n\n<p>The overall loss from the hack was $3 million, which was reportedly returned in full, along with a letter reading, &#8220;Next time, take care of your own shit.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Next time, take care of your own shit.<a href=\"https:\/\/twitter.com\/CoverProtocol?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@CoverProtocol<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> @chefcoverage <a href=\"https:\/\/t.co\/ks94ucdoRQ\" target=\"_blank\">https:\/\/t.co\/ks94ucdoRQ<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><br><br>1. No gains.<br>2. The Obtained Funds from LP has been returned to COVER.<\/p>&mdash; Grap.finance (@GrapFinance) <a href=\"https:\/\/twitter.com\/GrapFinance\/status\/1343555258316804101?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 28, 2020<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>A similar story happened to SafeDollar last summer after hackers stole around $250,000 worth of stablecoins from the platform's liquidity pools, driving the price of SafeDollar's eponymous dollar-pegged stablecoin to zero, and then fenced the stolen coins on PolyDex.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attackers exploited an &#8220;unlimited mint bug&#8221; to rob Cashio, a Solana-based stablecoin project, off millions of dollars. After an &#8220;unlimited mint flaw&#8221; allowed attackers to manufacture tokens without providing collateral, the price of Cashio&#8217;s dollar-pegged stablecoin CASH dropped drastically from $1 to $0.00005. oxGhostChain, a Cashio developer, took to Twitter to offer a warning &#8220;&#8221;We [&hellip;]<\/p>\n","protected":false},"author":34,"featured_media":21665,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[8284,8285,275],"class_list":["post-21656","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-cashio","tag-defi-hack","tag-solana"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/images-2022-03-23T173743.677.jpeg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/21656","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=21656"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/21656\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/21665"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=21656"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=21656"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=21656"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}