{"id":77871,"date":"2024-05-02T09:16:13","date_gmt":"2024-05-02T13:16:13","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=77871"},"modified":"2024-05-02T09:16:17","modified_gmt":"2024-05-02T13:16:17","slug":"hundred-finance-hacker-transfers-stolen-assets-after-one-year","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/hundred-finance-hacker-transfers-stolen-assets-after-one-year\/","title":{"rendered":"Hundred Finance Hacker Transfers Stolen Assets After One Year"},"content":{"rendered":"\n<p>After a year of inactivity, the hacker who stole $7.4 million from the <a href=\"https:\/\/coinscreed.com\/staging\/aave-labs-unveils-v4-protocol-overhaul.html\" target=\"_blank\" rel=\"noreferrer noopener\">decentralized Finance (DeFi) protocol<\/a> Hundred Finance has begun transferring the crypto assets.\u00a0\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"590\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-2-1024x590.png\" alt=\"Hundred Finance Hacker Transfers Stolen Assets After One Year\" class=\"wp-image-77891\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-2-1024x590.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-2-300x173.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-2-768x443.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-2-750x432.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-2.png 1069w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Hundred Finance Hacker Transfers Stolen Assets After One Year<\/figcaption><\/figure>\n\n\n\n<p>The infiltrator removed approximately $800,000 worth of Ether and Tether from Curve's decentralized exchange (DEX) on May 1, more than a year after supplying liquidity on the platform.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"421\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-1-750x421.png\" alt=\"Token transactions made by the Hundred Finance hacker. Source: Etherscan\" class=\"wp-image-77880\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-1-750x421.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-1-300x169.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-1-768x432.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-1.png 945w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">Token transactions made by the Hundred Finance hacker. Source:\u00a0Etherscan<\/figcaption><\/figure>\n\n\n\n<p>Upon completion of the withdrawal process, the infiltrator converted USDT and additional cryptocurrencies to ETH. This resulted in an over $1 million increase in the exploiter's ETH.&nbsp;<\/p>\n\n\n\n<p>The compromised wallet currently contains an assortment of crypto assets worth $4.3 million, including Dai, Wrapped Ether, Frax, and Wrapped Bitcoin.&nbsp;<\/p>\n\n\n\n<p>The DeFi protocol disclosed a security vulnerability on the layer-2 network Optimism on April 15, 2023.&nbsp;<\/p>\n\n\n\n<p>According to the <a href=\"https:\/\/www.certik.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">blockchain security firm CertiK<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, the perpetrator manipulated the hTOKENS-ERC-20 token exchange rate. Consequently, they were capable of withdrawing an excess of tokens deposited.\u00a0<\/p>\n\n\n\n<p>Flash loan attacks are a prevalent name for this in the DeFi community. Typically, this category of attack vector entails obtaining substantial sums of money through an unsecured loan from a lending platform.&nbsp;<\/p>\n\n\n\n<p>The assailant then manipulates the price of cryptocurrencies on DeFi platforms using the assets. The Hundred Finance breach resulted in fraud using an exchange rate to obtain substantial loans.&nbsp;<\/p>\n\n\n\n<p>Hundred Finance was also at risk of a Gnosis Chain vulnerability in 2022. A reentrancy attack depleted the liquidity of the protocol, leading to a financial loss of $6 million.&nbsp;<\/p>\n\n\n\n<p>In April 2024, there was a notable decline in the financial losses caused by flash loan attacks, a category of hacking that has caused considerable disruption in recent years.&nbsp;<\/p>\n\n\n\n<p>A report by CertiK indicates that the mere $129,000 in losses incurred in April were attributable to flash loan attacks. Its most significant incident of the month resulted in a mere $55,000 in damages. Since February 2022, this was the smallest amount lost to flash loan attacks, according to the report by CertiK.&nbsp;<\/p>\n\n\n\n<p>Moreover, overall <a href=\"https:\/\/coinscreed.com\/staging\/north-korean-hackers-allegedly-stole-700m-crypto-in-2023.html\" target=\"_blank\" rel=\"noreferrer noopener\">crypto hacking losses<\/a> decreased during April. According to security firm PeckShield, hacking caused the loss of a mere $60 million during the month. This signifies a substantial decrease compared to the losses of $360 million and $187 million incurred in February and March, respectively.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After a year of inactivity, the hacker who stole $7.4 million from the decentralized Finance (DeFi) protocol Hundred Finance has begun transferring the crypto assets.\u00a0\u00a0 The infiltrator removed approximately $800,000 worth of Ether and Tether from Curve&#8217;s decentralized exchange (DEX) on May 1, more than a year after supplying liquidity on the platform.&nbsp; Upon completion [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":77891,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[5680,11230,2118,8152],"class_list":["post-77871","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-dex-2","tag-defi-protocol","tag-hacker","tag-hundred-finance"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-2.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/77871","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=77871"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/77871\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/77891"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=77871"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=77871"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=77871"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}