{"id":42012,"date":"2022-12-12T16:24:14","date_gmt":"2022-12-12T20:24:14","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=42012"},"modified":"2022-12-12T16:24:17","modified_gmt":"2022-12-12T20:24:17","slug":"hackers-use-mango-markets-attackers-methods-to-exploit-lodestar","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/hackers-use-mango-markets-attackers-methods-to-exploit-lodestar\/","title":{"rendered":"Hackers use Mango Markets attacker\u2019s methods to exploit Lodestar"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-according-to-a-post-mortem-analysis-provided-by-certik-of-the-5-8-million-lodestar-finance-exploit-that-occurred-on-dec-10\">According to a <a href=\"https:\/\/coinscreed.com\/staging\/crypto-scammers-use-black-market-identities-for-fraud-certik.html\" target=\"_blank\" rel=\"noreferrer noopener\">post-mortem analysis provided by CertiK<\/a> of the $5.8 million Lodestar Finance exploit that occurred on Dec. 10<\/h5>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221212_205734_0000-1024x576.jpg\" alt=\"Hackers use Mango Markets attacker\u2019s methods to exploit Lodestar\" class=\"wp-image-42014\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221212_205734_0000-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221212_205734_0000-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221212_205734_0000-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221212_205734_0000-150x84.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221212_205734_0000-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221212_205734_0000-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221212_205734_0000.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Hackers use Mango Markets attacker\u2019s methods to exploit Lodestar<\/figcaption><\/figure>\n\n\n\n<p>A post-mortem examination of the $5.8 million Lodestar Finance vulnerability that happened on December 10 has been released by blockchain security firm CertiK:<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">3. They cashed out what they could but our collateralization ratio mechanism prevented them from fully cashing out the plvGLP. <br><br>4. After the hack several plvGLP holders also took advantage of the opportunity and also cashed out at 1.83 glp per plvGLP.<\/p>&mdash; Lodestar Finance \ud83c\udf1f (@LodestarFinance) <a href=\"https:\/\/twitter.com\/LodestarFinance\/status\/1601687154014715904?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 10, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>In a similar instance, CertiK said that Lodestar Finance hackers \u201cartificially pumped the price of an illiquid collateral asset which they then borrow against, leaving the protocol with irretrievable debt.\u201d<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cDespite some of the losses being potentially recoverable, the protocol is functionally insolvent right now, and users are being urged not to repay any loans they have taken out.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>The <a href=\"https:\/\/coinscreed.com\/staging\/japans-financial-group-to-issue-soulbound-token-to-explore-web3.html\" target=\"_blank\" rel=\"noreferrer noopener\">PlutusDAO's plvGLP token<\/a> on Lodestar has a vulnerability that allowed the attack to take place. The lending platform &#8220;uses confirmed, secure Chainlink price feeds for every asset it sells with the exception of plvGLP,&#8221; according to its documentation. <\/p>\n\n\n\n<p>Instead, the ratio of total assets to total supply on Lodestar was used to determine the exchange rate of plvGLP to GLP. According to CertiK, the exploiter started their wallet on December 8 with 1,500 Ether (ETH $1,254) before taking out<a href=\"https:\/\/www.google.com\/search?q=Hackers+use+Mango+Markets+attacker%E2%80%99s+methods+to+exploit+Lodestar&oq=Hackers+use+Mango+Markets+attacker%E2%80%99s+methods+to+exploit+Lodestar&aqs=chrome..69i57.680j0j7&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\"> eight flash loans<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> two days later for a total of almost $70 million in USD Coin (USDC $1.00), wrapped Ether (wETH), and Dai (DAI $1.00).<\/p>\n\n\n\n<p>As a result, the plvGLP\/GLP exchange rate increased to 1.00:1.83, allowing the exploiter to take out more loans from the protocol's assets. As a result of the borrowings, the <a href=\"https:\/\/coinscreed.com\/staging\/temasek-works-with-ftx-in-liquidity-crisis.html\" target=\"_blank\" rel=\"noreferrer noopener\">platform's liquidity was quickly depleted<\/a>, forcing the hacker to move the money out of Lodestar and leaving customers with bad debt. The attack vector is thought to have brought in a total profit of $6.9 million for the exploiter.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cWhile Lodestar is reaching out to the exploiter in an attempt to negotiate a bug bounty ex post facto, the funds are likely to be mostly unrecoverable. In the absence of an insurance fund that can cover the losses, users of the platform bear the cost of the exploit.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>CertiK warned that the attack \u201cis the result of flaws in the protocol\u2019s design rather than a bug in its smart contract code.\u201dFurther highlighting that Lodestar debuted without an audit and, thus, without a third party reviewing its protocol architecture, the blockchain security company.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to a post-mortem analysis provided by CertiK of the $5.8 million Lodestar Finance exploit that occurred on Dec. 10 A post-mortem examination of the $5.8 million Lodestar Finance vulnerability that happened on December 10 has been released by blockchain security firm CertiK: In a similar instance, CertiK said that Lodestar Finance hackers \u201cartificially pumped [&hellip;]<\/p>\n","protected":false},"author":43,"featured_media":42014,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[197,12002,12618],"class_list":["post-42012","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-defi","tag-hacks","tag-lodestar"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221212_205734_0000.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/42012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/43"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=42012"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/42012\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/42014"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=42012"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=42012"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=42012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}