{"id":51850,"date":"2023-06-12T07:32:14","date_gmt":"2023-06-12T11:32:14","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=51850"},"modified":"2023-06-12T07:32:16","modified_gmt":"2023-06-12T11:32:16","slug":"defi-protocol-sturdy-finance-sees-800k-hack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/defi-protocol-sturdy-finance-sees-800k-hack\/","title":{"rendered":"DeFi Protocol Sturdy Finance Sees $800K Hack"},"content":{"rendered":"\n<p><a href=\"https:\/\/coinscreed.com\/staging\/optimism-integrates-chainlink-automation-for-defi.html\">Decentralized finance<\/a> (DeFi) protocol Sturdy Finance lost 442 Ether worth nearly $800,000 due to a vulnerability that ultimately allowed the exploiter to manipulate a flawed price oracle and drain funds from the protocol.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/06\/hjj.png\" alt=\"DeFi Protocol Sturdy Finance Sees $800K Hack\" class=\"wp-image-51868\" width=\"845\" height=\"477\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/06\/hjj.png 500w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/06\/hjj-300x169.png 300w\" sizes=\"(max-width: 845px) 100vw, 845px\" \/><figcaption class=\"wp-element-caption\">DeFi Protocol Sturdy Finance Sees $800K Hack<\/figcaption><\/figure>\n\n\n\n<p>PeckShield, a blockchain security company, alerted Sturdy Finance on June 12 about a transaction that appeared to be related to price manipulation. Almost an hour later, the DeFi protocol acknowledged the vulnerability, halted all of its markets, and assured its users that no additional funds were at risk.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">We are aware of the reported exploit of the Sturdy protocol. All markets have been paused; no additional funds are at risk and no user actions are required at this time.<br><br>We will be sharing more information as soon as we have it.<\/p>&mdash; Sturdy \ud83e\uddf1 (@SturdyFinance) <a href=\"https:\/\/twitter.com\/SturdyFinance\/status\/1668080627030315009?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">June 12, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>PeckShield confirmed that the attacker could transmit nearly $800,000 in ETH to the <a href=\"https:\/\/coinscreed.com\/staging\/cryptocurrency-mixer-tornado-cash-open-sources-ui-code.html\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency mixer Tornado Cash<\/a>, despite a prompt response from the DeFi lending platform. The security firm also noted that a flawed price oracle was the &#8220;root cause&#8221; of the vulnerability.<\/p>\n\n\n\n<p>In addition, the blockchain security firm BlockSec emphasized that the breach was carried out using a reentrancy attack, a standard method hackers use to withdraw funds from DeFi protocols.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">1\/ <a href=\"https:\/\/twitter.com\/SturdyFinance?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@SturdyFinance<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> was attacked and the loss is ~442 ETH. The root cause is due to the typical Balancer&#39;s read-only reentrancy, while the price of B-stETH-STABLE was manipulated! <a href=\"https:\/\/t.co\/5l9mVfhpQN\" target=\"_blank\">pic.twitter.com\/5l9mVfhpQN<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; BlockSec (@BlockSecTeam) <a href=\"https:\/\/twitter.com\/BlockSecTeam\/status\/1668084629654638592?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">June 12, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Using this technique, hackers can repeatedly call a function in a single transaction before the initial function call is complete. This allows hackers to extract an excessive amount of funds.&nbsp;<\/p>\n\n\n\n<p>Scammers seized control of eight prominent crypto community members' Twitter accounts and used them to promote crypto scams. <\/p>\n\n\n\n<p>According to blockchain detective ZachXBT, fraudsters took nearly $1 million in cryptocurrency after gaining access to the accounts of well-known DJ Steve Aoki, Pudgy Penguins founder Cole Villemain, and even crypto skeptic Peter Schiff.<\/p>\n\n\n\n<p>In other news, the <a href=\"https:\/\/www.justice.gov\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">United States Department of Justice<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> has recently charged two men with involvement in the Mt. Gox breach. According to the department, Alexey Bilyuchenko, 43, and Aleksey Verner, 29, are accused of stealing and conspiring to launder 647,000 Bitcoin.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Decentralized finance (DeFi) protocol Sturdy Finance lost 442 Ether worth nearly $800,000 due to a vulnerability that ultimately allowed the exploiter to manipulate a flawed price oracle and drain funds from the protocol.\u00a0 PeckShield, a blockchain security company, alerted Sturdy Finance on June 12 about a transaction that appeared to be related to price manipulation. [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":51868,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[73],"tags":[],"class_list":["post-51850","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defi-news"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/06\/hjj.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/51850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=51850"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/51850\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/51868"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=51850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=51850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=51850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}