{"id":74493,"date":"2024-03-26T07:41:23","date_gmt":"2024-03-26T11:41:23","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=74493"},"modified":"2024-03-26T07:41:26","modified_gmt":"2024-03-26T11:41:26","slug":"curio-smart-contract-platform-faces-16m-digital-assets-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/curio-smart-contract-platform-faces-16m-digital-assets-exploit\/","title":{"rendered":"Curio Smart Contract Platform Faces $16M Digital Assets Exploit"},"content":{"rendered":"\n<p>A hacker was able to steal $16 million worth of digital assets from<a href=\"https:\/\/coinscreed.com\/staging\/dot-eyes-7-as-web3-foundation-invests-in-real-world-assets.html\" target=\"_blank\" rel=\"noreferrer noopener\"> real-world asset<\/a> (RWA) liquidity firm Curio due to a smart contract exploit involving a critical vulnerability associated with voting power privileges.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"958\" height=\"560\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-111.png\" alt=\"Curio Smart Contract Platform Faces $16M Digital Assets Exploit\" class=\"wp-image-74504\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-111.png 958w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-111-300x175.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-111-768x449.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-111-750x438.png 750w\" sizes=\"(max-width: 958px) 100vw, 958px\" \/><figcaption class=\"wp-element-caption\">Curio Smart Contract Platform Faces $16M Digital Assets Exploit<\/figcaption><\/figure>\n\n\n\n<p>Curio notified its community regarding the vulnerability and emphasized its efforts to rectify the situation. An organization stated that a smart contract built on MakerDAO and utilized by Curio had been compromised.<\/p>\n\n\n\n<p>Nevertheless, the organization guaranteed its clientele that the vulnerability solely impacted the Ethereum component and that every Polkadot and Curio Chain transaction remained secure.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/coinscreed.com\/staging\/diving-deep-specialized-roles-in-web3-and-how-to-prepare-for-them.html\" target=\"_blank\" rel=\"noreferrer noopener\">Web3 security firm<\/a> Cyvers has estimated that the exploit has caused approximately $16 million in damages. According to the security firm, the exploit exploited a &#8220;permission access logic vulnerability.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"507\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-110-750x507.png\" alt=\"\" class=\"wp-image-74500\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-110-750x507.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-110-300x203.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-110-768x519.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-110.png 947w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\"><em>Source:\u00a0<a href=\"https:\/\/twitter.com\/CyversAlerts\/status\/1772216818645565673\" target=\"_blank\" rel=\"noreferrer noopener\">Cyvers<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>\u00a0<a href=\"https:\/\/twitter.com\/CyversAlerts\/status\/1772216818645565673\" target=\"_blank\" rel=\"noreferrer noopener\">Alerts<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/em><\/figcaption><\/figure>\n\n\n\n<p>A compensation plan for afflicted users and a post-mortem of the exploit were both published by Curio on March 25. Curio emphasized in the report that the issue was attributable to a deficiency in the privilege access control for voting power.<\/p>\n\n\n\n<p>By doing so, the assailant obtained a limited quantity of <a href=\"https:\/\/www.binance.com\/en-NG\/how-to-buy\/curio-governance\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Curio Governance (CGT) tokens<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, which granted them entry and enhanced their ability to vote on the smart contract for the project.<\/p>\n\n\n\n<p>The adversary executed a sequence of operations made possible by the elevated voting authority, which ultimately enabled the implementation of arbitrary actions within the Curio DAO contract. The consequence was the illicit production of one billion CGT.<\/p>\n\n\n\n<p>Curio stated in the report that every penny lost due to the exploit will be refunded. CGT 2.0 is the name of the new token that the group announced it would issue. The group pledged to fully return all CGT holders' funds using the new token.<\/p>\n\n\n\n<p>Curio has declared that it will implement a fund compensation program for liquidity providers. According to the team, the payment schedule consists of four 90-day stages. This may imply that completing the payment process could take up to a year. They penned:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cThe compensation program will consist of 4 consecutive stages, each lasting for 90 days. During each stage: compensation will be paid in USDC\/USDT, amounting to 25% of the losses incurred by the second token in the liquidity pools.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>Additionally, the organization declared that it would compensate white hat hackers who assist in the recovery of the lost funds. According to the team, in the initial phase of fund recovery, hackers may be eligible to receive a reward equal to 10% of the funds recovered.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A hacker was able to steal $16 million worth of digital assets from real-world asset (RWA) liquidity firm Curio due to a smart contract exploit involving a critical vulnerability associated with voting power privileges. Curio notified its community regarding the vulnerability and emphasized its efforts to rectify the situation. An organization stated that a smart [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":74504,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[5817,18931,1058,18914],"class_list":["post-74493","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-hack-2","tag-curio","tag-digital-asset","tag-smart-contract-exploit"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/03\/image-111.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/74493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=74493"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/74493\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/74504"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=74493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=74493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=74493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}