{"id":8176,"date":"2021-08-18T12:08:18","date_gmt":"2021-08-18T11:08:18","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=8176"},"modified":"2021-08-18T12:08:28","modified_gmt":"2021-08-18T11:08:28","slug":"sushiswap-narrowly-escapes-becoming-the-latest-defi-hack-victim","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/sushiswap-narrowly-escapes-becoming-the-latest-defi-hack-victim\/","title":{"rendered":"SushiSwap  narrowly escapes becoming the latest DeFi hack victim"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">SushiSwap could have lost 109,000 ETH due to a weakness in a <a href=\"https:\/\/coinscreed.com\/staging\/az-alkmaar-a-dutch-football-team-to-retain-btc-and-pay-its-players-in-bitcoin.html\" data-type=\"post\" data-id=\"4823\">Dutch <\/a>auction smart contract discovered by the security researcher.<\/h5>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"791\" height=\"363\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-195.png\" alt=\"SushiSwap  narrowly escapes becoming the latest DeFi hack victim\" class=\"wp-image-8182\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-195.png 791w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-195-300x138.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-195-768x352.png 768w\" sizes=\"(max-width: 791px) 100vw, 791px\" \/><\/figure>\n\n\n\n<p>Thanks to the help of a white hat hacker, the <a href=\"https:\/\/www.google.com\/search?q=SushiSwap+narrowly+escapes+becoming+the+latest+DeFi+hack+victim&oq=SushiSwap++narrowly+escapes+becoming+the+latest+DeFi+hack+victim&aqs=chrome..69i57j35i39i362l8...8.357j0j7&sourceid=chrome&ie=UTF-8\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=SushiSwap+narrowly+escapes+becoming+the+latest+DeFi+hack+victim&oq=SushiSwap++narrowly+escapes+becoming+the+latest+DeFi+hack+victim&aqs=chrome..69i57j35i39i362l8...8.357j0j7&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\">SushiSwap <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>decentralised exchange narrowly escaped becoming the latest DeFi breach victim.<\/p>\n\n\n\n<p><a href=\"https:\/\/coinscreed.com\/staging\/sushiswap-cto-explains-why-the-project-isnt-scaling-on-optimism-anytime-soon.html\" data-type=\"post\" data-id=\"7754\">SushiSwap <\/a>and its MISO platform were saved from a potential loss of up to 109,000 ETH thanks to a security researcher from venture capital company Paradigm identified on Twitter as &#8220;samczsun.&#8221;<\/p>\n\n\n\n<p>The programmer revealed how he began investigating the smart contract code for the BitDAO token sale at SushiSwap's token launchpad platform, MISO, in a blog post published on Aug. 17.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Just pulled off maybe the biggest whitehat rescue ever. Story time soon<\/p><cite>\u2014 samczsun (@samczsun)\u00a0August 17, 2021<\/cite><\/blockquote>\n\n\n\n<p>He discovered a weakness in the MISO Dutch auction contract, where several of the functions lacked access controls, upon closer study.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cI didn\u2019t really expect this to be a vulnerability though, since I didn\u2019t expect the Sushi team to make such an obvious misstep.\u201d<\/p><\/blockquote>\n\n\n\n<p>The white hat uncovered a vulnerability that, if abused, could lead to a bad actor draining all of the crypto assets in the token auction contract. An attacker might \u201cbid in the auction for free\u201d by repeatedly using the same <a href=\"https:\/\/coinscreed.com\/staging\/1inch-reveals-deployment-to-the-optimistic-ethereum-network.html\" data-type=\"post\" data-id=\"8104\">ETH <\/a>to batch several calls to the contract.<\/p>\n\n\n\n<p>Before notifying colleagues Georgios Konstantopoulos and Dan Robinson, Samczsun tested the vulnerability with a successful exploit. He also revealed that a hacker may steal the contract's cash by triggering a refund by sending more ETH than the auction's hard cap.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cSuddenly, my little vulnerability just got a lot bigger. I wasn\u2019t dealing with a bug that would let you outbid other participants. I was looking at a 350 million dollar bug.\u201d<\/p><\/blockquote>\n\n\n\n<p>Before the exploit was detected in the wild, it was time to contact <a href=\"https:\/\/coinscreed.com\/staging\/harmony-blockchain-partners-with-sushiswap-to-deploy-a-full-suite-of-sushi-products.html\" data-type=\"post\" data-id=\"4535\">SushiSwap <\/a>CTO Joseph Delong to devise a rescue strategy. The BitDAO team in charge of the token sale opted to manually conclude the auction by purchasing the remaining allotment and completing the procedure and retrieving the cash.<\/p>\n\n\n\n<p>SushiSwap stated that no cash were lost during the recovery process, but that company will halt the use of its MISO Dutch auction structure until the smart contract is upgraded. \u201cDC Investor,\u201d a member of the crypto community, commented:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cEveryone knows Paradigm has big UNI \/ Uniswap bags, but Sam from their team just helped save SushiSwap (an ostensible competitor) from a critical bug. This is the ethos of the space among the best actors.\u201d<\/p><\/blockquote>\n\n\n\n<p>According to a tweet from the protocol on Aug. 17, the BitDAO token sale went ahead without a hitch, earning more than 112,000 ETH (approximately $336 million) from over 9,200 participants.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cThe entire industry basically without exception banded together to fight this [&#8230;] Yes, this bill is a threat, but more important [&#8230;] was how effectively the industry was able to rally and defend itself in D.C.\u201d&nbsp;<\/p><\/blockquote>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SushiSwap could have lost 109,000 ETH due to a weakness in a Dutch auction smart contract discovered by the security researcher. Thanks to the help of a white hat hacker, the SushiSwap decentralised exchange narrowly escaped becoming the latest DeFi breach victim. SushiSwap and its MISO platform were saved from a potential loss of up [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":8182,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[153,853,591,973],"class_list":["post-8176","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-eth","tag-sushiswap","tag-tokens","tag-uniswap"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-195.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/8176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=8176"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/8176\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/8182"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=8176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=8176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=8176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}