{"id":54208,"date":"2023-07-10T06:44:38","date_gmt":"2023-07-10T10:44:38","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=54208"},"modified":"2023-07-10T06:44:40","modified_gmt":"2023-07-10T10:44:40","slug":"arcadia-finance-faces-hack-on-ethereum-optimism-for-455k","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/arcadia-finance-faces-hack-on-ethereum-optimism-for-455k\/","title":{"rendered":"Arcadia Finance Faces Hack on Ethereum, Optimism for $455K"},"content":{"rendered":"\n<p><a href=\"https:\/\/coinscreed.com\/staging\/defi-protocol-sturdy-finance-sees-800k-hack.html\" target=\"_blank\" rel=\"noreferrer noopener\">Decentralized finance (DeFi) protocol<\/a> Arcadia Finance was hacked using a code vulnerability that allowed the hacker to drain funds worth roughly $455,000 from its Ethereum and Optimism vaults.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/III.jpg\" alt=\"Arcadia Finance Faces Hack on Ethereum, Optimism for $455K\" class=\"wp-image-54212\" width=\"988\" height=\"549\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/III.jpg 800w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/III-300x167.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/III-768x426.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/III-750x416.jpg 750w\" sizes=\"(max-width: 988px) 100vw, 988px\" \/><figcaption class=\"wp-element-caption\">Arcadia Finance Faces Hack on Ethereum, Optimism for $455K<\/figcaption><\/figure>\n\n\n\n<p>PeckShield, a blockchain investigator, notified Arcadia Finance of a hack and identified the cause as &#8220;the lack of untrusted input validation.&#8221; Supposedly, the code lacked a mechanism to cross-check unverified inputs. This vulnerability allowed the intruder to steal approximately $455k from the Ethereum (darcWETH) and Optimism (darcUSDC) vaults.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-8-1024x371.png\" alt=\"\" class=\"wp-image-54211\" width=\"722\" height=\"262\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-8-1024x371.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-8-300x109.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-8-768x278.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-8-750x272.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-8.png 1099w\" sizes=\"(max-width: 722px) 100vw, 722px\" \/><figcaption class=\"wp-element-caption\"><em>Arcadia Finance code required no validation of untrusted input. Source: PeckShield<\/em><\/figcaption><\/figure>\n\n\n\n<p>\u00a0The team stated, however, that the fundamental cause identified by <a href=\"https:\/\/m.peckshield.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">PeckShield <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>needs to be corrected.<\/p>\n\n\n\n<p>Two hours after PeckShield's notification, Arcadia Finance verified the hack and halted the contracts to prevent further loss of funds.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">We are aware of a potential exploit in our protocol. <br>We have paused the contracts and are investigating the root-cause with security experts as we speak. More info will follow as it comes available.<\/p>&mdash; Arcadia Finance (@ArcadiaFi) <a href=\"https:\/\/twitter.com\/ArcadiaFi\/status\/1678285634727706625?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">July 10, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>While investigations are ongoing, Arcadia's code contains an additional vulnerability that, if exploited, could prove catastrophic for the protocol. As stated by PeckShield:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cIn addition, there is a lack of reentrancy protection, which allows for the instant liquidation to bypass the internal vault health check.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>Most of the misappropriated funds, approximately 180 Ether, originated from Optimism and were cleansed with <a href=\"https:\/\/coinscreed.com\/staging\/exploited-nomad-bridge-wallet-transfers-1-5m-to-tornado-cash.html\" target=\"_blank\" rel=\"noreferrer noopener\">Tornado Cash<\/a>. However, the misappropriated Ethereum tokens, valued at over $103,000 when writing, remain at the suspect wallet address.<\/p>\n\n\n\n<p>In the second quarter of 2023, breaches and exploits in the crypto space caused a more than $300 million loss.<\/p>\n\n\n\n<p>According to a blockchain security company CertiK report, 212 security incidents were recorded during the quarter, culminating in a loss of $313,566,528 from Web3 protocols.<\/p>\n\n\n\n<p>Compared to Q2 data from the previous year, CertiK discovered that crypto breaches decreased by 58%. The BNB Smart Chain had the highest number of incidents, with 119 resulting in $70,711,385 in losses.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Decentralized finance (DeFi) protocol Arcadia Finance was hacked using a code vulnerability that allowed the hacker to drain funds worth roughly $455,000 from its Ethereum and Optimism vaults. PeckShield, a blockchain investigator, notified Arcadia Finance of a hack and identified the cause as &#8220;the lack of untrusted input validation.&#8221; Supposedly, the code lacked a mechanism [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":54212,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[15193,11230,128,1496,4490],"class_list":["post-54208","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-arcadia-finance","tag-defi-protocol","tag-ethereum","tag-hack","tag-optimism"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/III.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/54208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=54208"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/54208\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/54212"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=54208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=54208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=54208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}