• About Us
  • Privacy Policy
  • Contact Us
Newsletter
Cryptoddy
Advertisement
  • Home
  • Bitcoin
  • Ethereum
  • Cryptocurrency
    • Altcoin
    • Litecoin
  • Regulation
  • Blockchain
  • Market
  • Prices
  • ICO
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Cryptocurrency
    • Altcoin
    • Litecoin
  • Regulation
  • Blockchain
  • Market
  • Prices
  • ICO
No Result
View All Result
Cryptoddy
No Result
View All Result
Home Ethereum

How This Ethereum Platform Was Attacked And Made A Deal With The Hacker

June 27, 2022
0
Hackers Steal $80 Million From DeFi Platforms Fei Protocol And Rari Capital
Share on FacebookShare on Twitter


Ethereum lending platform XCarnival confirmed a bad actor stole $3.8 million or 3,087 ETH. According to a report from on-chain security firm Peck Shield, a hacker exploited a vulnerability on the protocol’s smart contract by borrowing ETH and creating “multiple pledge orders to pledge BAYC (Bored Ape Yacht Club NFTs) many times”.

Related Reading | Morgan Creek Said To Be In Bid To Secure $250-M To Counter FTX BlockFi Bailout

XCarnival operates as a non-fungible token (NFT) lending pool. The platform enables NFT holders to deposit their assets in exchange for liquidity. This process involves three smart contracts: an NFT manager, a P2Controller to manage lending restrictions, and fund storage, as stated by another security firm Go+ Security.

The hacker bought item 5110 from the popular Bored Ape Yacht Club NFT collection on OpenSea. Later, he deposited this asset on XCarnival and conducted an attack to “use the same NFT for borrowing”.

In other words, the attacker was able to pledge the NFT, borrowed ETH, and then remove the NFT without paying back the loan. The bad actor completed this process several times until the pool was drained.

Go+ Security explained that the hacker created a Master smart contract and several “slaves” smart contracts to conduct the attack:

Then Slave 5338 withdrew the NFT and sent it back to Master, who then repeated this process with other Slaves. In this way they created many orderIDs, which can later be used as lending credentials. But bugged xNFT contract didn’t revoke the credential after withdrawing.

XCarnival’s operated with a vulnerability on its smart contracts, mentioned above, which enable the attack if the user stays within a certain. Go+ Security added on the attack and the smart contract vulnerability: “Collateral is still valid after withdrawing. This is a very simple & naive bug in contract implementation.”

In light of the successful attack, the Ethereum-based NFT lending protocol decided to offer the hacker a deal.

Ethereum Platform Makes Deals With Its Attacker

According to its official Twitter account, the XCarnival offered the hacker a 1,500 ETH or $1.8 million bounty. Half the stolen funds. The attacker only needed to return the other half and they got to keep the money and suffer no legal consequences.

The team behind the platform confirmed that the hacker agreed to the terms. Half the stolen funds were returned to the pool. The Ethereum lending platform claims “security agencies have tentatively determined the hacker’s geographic location”.

This statement seems to hint at possible legal consequences for the attacker, but the team behind this project is yet to provide more information.

7/8 Funds returnedhttps://t.co/oRwSsGgT6U pic.twitter.com/YgXZ9DTj03

— Tal Be’ery (@TalBeerySec) June 27, 2022

This is not the first time a hacker agrees to return a portion or the full amount of the stolen funds. Some hackers attack decentralized finance (DeFi) platforms and often held the money hostage until they receive payment for what they considered to be a “service”. Other projects are less lucky and pay the ultimate price.

Related Reading | Harmony Dangles $1M Reward For Return Of $100M Stolen Funds – Is It Enough?

At the time of writing, Ethereum (ETH) trades at $1,180 with a 3% loss in the last 24 hours.

ETH moving sideways on the 4-hour chart. Source: ETHUSD Tradingview





Source link

Related articles

MakerDAO Set To Convert USDC Funds To ETH, Is This A Good Idea?

MakerDAO Set To Convert USDC Funds To ETH, Is This A Good Idea?

August 15, 2022
Ethereum Energy Consumption Sees Sharp Decline As Mining Profitability Drops

Why Justin Sun Was Blocked From This Ethereum DeFi Protocol

August 13, 2022
Tags: AttackedDealEthereumHackerPlatform
Share76Tweet47

Related Posts

MakerDAO Set To Convert USDC Funds To ETH, Is This A Good Idea?

MakerDAO Set To Convert USDC Funds To ETH, Is This A Good Idea?

August 15, 2022
0

The crypto community has been on alert since the crash of LUNA, ETH, and USDT. Investors depend on stablecoins...

Ethereum Energy Consumption Sees Sharp Decline As Mining Profitability Drops

Why Justin Sun Was Blocked From This Ethereum DeFi Protocol

August 13, 2022
0

Diplomat and founder of the TRON network, Justin Sun, confirmed that one of his addresses was blocked from using...

Crypto Reacts: Arrest Of The Alleged Tornado Cash Developer, A Watershed Moment

Crypto Reacts: Arrest Of The Alleged Tornado Cash Developer, A Watershed Moment

August 13, 2022
0

What’s the story around Tornado Cash? The U.S. Department of the Treasury made its case in a press release,...

Merge Effects Continue As Ethereum Futures Prices Fall To All-Time Lows

Merge Effects Continue As Ethereum Futures Prices Fall To All-Time Lows

August 11, 2022
0

The effects of the upcoming Ethereum Merge on the crypto market have been very obvious. It has affected not...

Proposed ETHPoW Fork Poses An Existential Threat To Ethereum. Can It Succeed?

Proposed ETHPoW Fork Poses An Existential Threat To Ethereum. Can It Succeed?

August 10, 2022
0

The ETHPoW fork proposal comes from the miners. It’s only logical that they want to keep Ethereum as a...

Load More
Press Release

Become a Stakeholder in the First Web3 Social Booking Platform FEEV

August 15, 2022
0

FEEV, the first web3 social booking platform, has announced their NFT launch, together with the launch of the iOS and...

Read more
BTC Not Quite Ready to Stay Above $25K

BTC Not Quite Ready to Stay Above $25K

August 15, 2022
YouHodler Now Accepting Apple Pay For Crypto Payments

YouHodler Now Accepting Apple Pay For Crypto Payments

August 15, 2022
MakerDAO Set To Convert USDC Funds To ETH, Is This A Good Idea?

MakerDAO Set To Convert USDC Funds To ETH, Is This A Good Idea?

August 15, 2022
Fondos de inversión cripto registran egresos mínimos y ponen fin a racha de entradas

Fondos de inversión cripto registran egresos mínimos y ponen fin a racha de entradas

August 15, 2022
Cryptoddy

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Litecoin
  • Market
  • Press Release
  • Regulation
  • Uncategorized
  • About Us
  • Privacy Policy
  • Contact Us

© 2020 cryptoddy.com

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Cryptocurrency
    • Altcoin
    • Litecoin
  • Regulation
  • Blockchain
  • Market
  • Prices
  • ICO

© 2020 cryptoddy.com

  • bitcoinBitcoin (BTC) $ 24,032.00
  • ethereumEthereum (ETH) $ 1,899.21
  • tetherTether (USDT) $ 0.999671
  • usd-coinUSD Coin (USDC) $ 0.999532
  • bnbBNB (BNB) $ 317.82
  • cardanoCardano (ADA) $ 0.556197
  • xrpXRP (XRP) $ 0.374841
  • binance-usdBinance USD (BUSD) $ 0.999507
  • solanaSolana (SOL) $ 43.91
  • dogecoinDogecoin (DOGE) $ 0.077109