{"id":59744,"date":"2023-09-20T05:46:23","date_gmt":"2023-09-20T09:46:23","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=59744"},"modified":"2023-09-20T05:47:45","modified_gmt":"2023-09-20T09:47:45","slug":"defi-protocol-balancer-frontend-under-attack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/defi-protocol-balancer-frontend-under-attack\/","title":{"rendered":"DeFi Protocol Balancer Frontend Under Attack"},"content":{"rendered":"\n<p>At 11:49 UTC on September 19, the platform advised its community to refrain from interacting with the protocol Balancer until further notice.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/Balancer-Thumbnail-1024x576.webp\" alt=\"\" class=\"wp-image-59762\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/Balancer-Thumbnail-1024x576.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/Balancer-Thumbnail-300x169.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/Balancer-Thumbnail-768x432.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/Balancer-Thumbnail-18x10.webp 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/Balancer-Thumbnail-750x422.webp 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/Balancer-Thumbnail-1140x641.webp 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/Balancer-Thumbnail.webp 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">DeFi protocol Balancer Frontend Under Attack<\/figcaption><\/figure>\n\n\n\n<p>Balancer, a decentralized finance protocol based on Ethereum, cautions users to avoid its website following an attack on its frontend.<\/p>\n\n\n\n<p>At 11:49 UTC on September 19, the platform notified its community, requesting that users refrain from interacting with the Balancer user interface until further notice.<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\">The balancer frontend is under an attack. The issue is currently under investigation. Please do NOT interact with the balancer UI until further notice!<\/p>&mdash; Balancer (@Balancer) <a href=\"https:\/\/twitter.com\/Balancer\/status\/1704281611326357567?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 19, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p>Balancer stated that the attack's specifics are being investigated. Balancer contributor Cosme Fulanito has reportedly verified that the vault remains &#8220;100% fine&#8221; despite the fact that the company has not commented on whether user funds were affected.<\/p>\n\n\n\n<p>However, at the time of writing, blockchain security firms, including PeckShield and blockchain analyst ZachXBT, estimated that at least $238,000 in cryptocurrency had been plundered.<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/PeckShieldAlert?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#PeckShieldAlert<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/twitter.com\/Balancer?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@Balancer<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> has reported that its frontend under an attack, ~$238k worth of cryptos were stolen <a href=\"https:\/\/t.co\/aAaj0Xqery\" target=\"_blank\">https:\/\/t.co\/aAaj0Xqery<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/YDIjfnNYM4\" target=\"_blank\">pic.twitter.com\/YDIjfnNYM4<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; PeckShieldAlert (@PeckShieldAlert) <a href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1704306602529247294?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 20, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p>Some users have reported that when interacting with the website, they are prompted to accept a malicious contract that consumes their bank accounts other users' funds.<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\">\ud83d\udea8 Risk alert <a href=\"https:\/\/twitter.com\/Balancer?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@Balancer<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> &#039;s domain (<a href=\"https:\/\/t.co\/Ikuh2PEJrv\" target=\"_blank\">https:\/\/t.co\/Ikuh2PEJrv<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>) has been hijacked and its prompting users to approve a malicious contract that will drain your wallet. <br><br>As far as we can tell, protocol funds are safu and the issue is limited to the hijacked front-end. <a href=\"https:\/\/t.co\/KrBUutj5H0\" target=\"_blank\">pic.twitter.com\/KrBUutj5H0<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Exponential DeFi (@ExponentialDeFi) <a href=\"https:\/\/twitter.com\/ExponentialDeFi\/status\/1704278641813729787?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 19, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p>One industry expert described the reported experiences of other users:<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cIf you open the website it asks you to change the chain, where you hold the most amount of money. After that scam transaction is sent, after confirmation money are gone. Don\u2019t open the website!!!\u201d<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n\n\n\n<p><br>Users who seek to access the Balancer website are greeted with the following warning:<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"705\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/cv-1024x705.webp\" alt=\"\" class=\"wp-image-59761\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/cv-1024x705.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/cv-300x207.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/cv-768x529.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/cv-18x12.webp 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/cv-750x517.webp 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/cv-1140x785.webp 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/cv.webp 1224w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Balancer\u2019s website as of Sept. 20 at 1:04 am UTC. Source: Balancer<\/figcaption><\/figure>\n\n\n\n<p>This is the second attack on Balancer in less than a month after the company warned of a critical vulnerability on August 22 and suffered an estimated $2 million exploit days later.<\/p>\n\n\n\n<p>\u201cBalancer is aware of an exploit related to the vulnerability below,\u201d\u00a0 the protocol's team posted on X (previously Twitter) on August 27, adding that while recent mitigation measures had considerably reduced risks, affected pools could not be paused.<\/p>\n\n\n\n<p>\u201cTo prevent further exploits, users must withdraw from affected LPs,\u201d the advisory stated.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>At 11:49 UTC on September 19, the platform advised its community to refrain from interacting with the protocol Balancer until further notice. Balancer, a decentralized finance protocol based on Ethereum, cautions users to avoid its website following an attack on its frontend. At 11:49 UTC on September 19, the platform notified its community, requesting that [&hellip;]<\/p>\n","protected":false},"author":53,"featured_media":59762,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21,73],"tags":[5443,16491,5643,6370],"class_list":["post-59744","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-defi-news","tag-altcoin-2","tag-balancer-2","tag-defi-2","tag-scams"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/Balancer-Thumbnail.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/59744","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/53"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=59744"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/59744\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/59762"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=59744"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=59744"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=59744"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}