{"id":40971,"date":"2022-11-22T16:55:16","date_gmt":"2022-11-22T20:55:16","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=40971"},"modified":"2022-11-22T16:56:21","modified_gmt":"2022-11-22T20:56:21","slug":"mango-markets-hacker-feigns-curve-short-attack-to-exploit-aave","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/mango-markets-hacker-feigns-curve-short-attack-to-exploit-aave\/","title":{"rendered":"Mango Markets hacker feigns Curve short attack to exploit Aave"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-it-appears-that-shorting-of-crv-tokens-was-a-distraction-shot-to-exploit-a-sophisticated-loophole-on-defi-platform-aave\">It appears that shorting of CRV <a href=\"https:\/\/coinscreed.com\/staging\/ftx-hacker-swaps-millions-in-eth-for-renbtc-tokens.html\" target=\"_blank\" rel=\"noreferrer noopener\">tokens<\/a> was a distraction shot to exploit a sophisticated loophole on DeFi platform Aave.<\/h5>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/11\/jpg_20221122_214306_0000-1024x576.jpg\" alt=\"Mango Markets hacker feigns Curve short attack to exploit Aave\" class=\"wp-image-40973\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/11\/jpg_20221122_214306_0000-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/11\/jpg_20221122_214306_0000-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/11\/jpg_20221122_214306_0000-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/11\/jpg_20221122_214306_0000-150x84.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/11\/jpg_20221122_214306_0000-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/11\/jpg_20221122_214306_0000-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/11\/jpg_20221122_214306_0000.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Mango Markets hacker feigns Curve short attack to exploit Aave<\/figcaption><\/figure>\n\n\n\n<p>Tokens of decentralized exchange Curve Finance (CRV) appear to have experienced a significant short-seller attack, as stated by analysts at Lookonchain on Nov. 22. According to Lookonchain, Avraham Eisenberg's Mango Markets exploiter ponzishorter.eth swapped 40 million USD Coin (USDC) into the <a href=\"https:\/\/coinscreed.com\/staging\/how-to-discover-defi-tokens-with-potential.html\" target=\"_blank\" rel=\"noreferrer noopener\">decentralized finance<\/a> protocol Aave on November 13 in order to borrow CRV for selling.<\/p>\n\n\n\n<p>According to reports, the incident caused the price of CRV to drop over the week from $0.625 to $0.464. In the present, <a href=\"https:\/\/coinscreed.com\/staging\/asx-scraps-blockchain-plans-leaving-170m-hole.html\" target=\"_blank\" rel=\"noreferrer noopener\">blockchain <\/a>data reveals that ponzishorter.eth transferred 30 million CRV ($14.85 million) in additional debt to OKEx for sale through two transactions.<\/p>\n\n\n\n<p> Lookonchain's team made the assumption that the trade was made to lower the token price &#8220;so many people using CRV as collateral will face liquidation.&#8221;20 million extra CRV were added as collateral in a wallet connected to Curve's founder as a result of the intense selling activity. <\/p>\n\n\n\n<p>At the time of publication, the <a href=\"https:\/\/coinscreed.com\/staging\/defi-platform-oasis-will-block-wallet-addresses-deemed-vulnerable.html\" target=\"_blank\" rel=\"noreferrer noopener\">wallet addresses<\/a> on Ave had a health factor of 1.65, which denotes an excess of collateral against borrowed assets. The trades &#8220;may just be bait,&#8221; according to blockchain analytics company Arkham, with Aave being the main target. <\/p>\n\n\n\n<p>According to Arkham, Eisenberg amassed a position worth over $100 million on Aave for a complex trading strategy.It starts with a distraction short of CRV tokens on Aave, which are crucial to the <a href=\"https:\/\/coinscreed.com\/staging\/skyward-finance-exploit-results-in-3m-loss.html\" target=\"_blank\" rel=\"noreferrer noopener\">exploit<\/a> because they are illiquid on the platform and have very low margin requirements.<\/p>\n\n\n\n<p> Users would buy the dip in large quantities to protect the price of CRV in response to the subsequent attention, and others would try to pressure the short-seller into covering their position for a loss.<\/p>\n\n\n\n<p>The platform allegedly lacks the liquidity to buy back more than 20% of the short, so the real plot appears to be preying on the possibility that Aave cannot cover Eisenberg's CRV short positions. The price fall of Aave's native token would then favor bets against it:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>&#8220;The real target here was AAVE's vulnerable looping system, which Avi mentioned last month. Using $40 million to borrow almost $50 million of CRV could leave AAVE with severe bad debt.&#8221;<\/p>\n<\/blockquote>\n\n\n\n<p>To liquidate Avi's position, Aave <a href=\"https:\/\/www.google.com\/search?q=Mango+Markets+hacker+feigns+Curve+short+attack+to+exploit+Aave&oq=Mango+Markets+hacker+feigns+Curve+short+attack+to+exploit+Aave&aqs=chrome..69i57j69i61.568j0j7&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">liquidators<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> will have no way to buy back all the CRV he borrowed. AAVE will have to sell significant amounts of tokens from the safety module to cover this loss,&#8221; wrote Arkham. A screenshot of a swap quote provided by the firm shows an 89.8% potential swap impact between USDT and CRV for the estimated $100M position.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/twitter.com\/napgener\/status\/1594898794256146432\n<\/div><\/figure>\n\n\n\n<p>At the time of publication, CRV is up 15.47% to $0.5742 in the past 24 hours, while the price of Aave has declined by 6.33% to $53.54 during the same period. On Oct. 11, Eisenberg drained $117 million from the <a href=\"https:\/\/coinscreed.com\/staging\/hacker-steals-117-million-from-mango-markets.html\" target=\"_blank\" rel=\"noreferrer noopener\">Mango Markets <\/a>protocol and kept $47 million as bug bounty before returning the rest, calling it a &#8220;highly profitable trading strategy.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It appears that shorting of CRV tokens was a distraction shot to exploit a sophisticated loophole on DeFi platform Aave. Tokens of decentralized exchange Curve Finance (CRV) appear to have experienced a significant short-seller attack, as stated by analysts at Lookonchain on Nov. 22. According to Lookonchain, Avraham Eisenberg&#8217;s Mango Markets exploiter ponzishorter.eth swapped 40 [&hellip;]<\/p>\n","protected":false},"author":43,"featured_media":40973,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[1104,11067,197],"class_list":["post-40971","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-aave","tag-curve-finance","tag-defi"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/11\/jpg_20221122_214306_0000.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/40971","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/43"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=40971"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/40971\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/40973"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=40971"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=40971"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=40971"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}