Bitcoin Forum

Alternate cryptocurrencies => Altcoin Discussion => Topic started by: zasad@ on August 06, 2020, 09:53:36 PM



Title: DeFi hacks [history]
Post by: zasad@ on August 06, 2020, 09:53:36 PM
DeFi financial system has been compared to the wild west, but that's how a new story begins.
2020
18 February 2020
Arbs Exploit DeFi to Make $900k in Seconds; bZx hack.
https://thedefiant.substack.com/p/arbs-exploit-defi-to-make-900k-in

21 February 2020
Fulcrum had a $2.5M vulnerability over a month ago and still hasn’t told anyone
https://medium.com/@1inch.exchange/yes-we-hacked-bzx-fulcrum-but-one-month-ago-3f7e5c437ee3

19 April 2020
Multicoin Capital-backed DeFi protocol dForce loses ~$25M total locked value in an exploit
https://www.theblockcrypto.com/amp/linked/62346/multicoin-capital-backed-defi-protocol-dforce-loses-25m-total-locked-value-in-an-exploit

21 April 2020
Dforce return $ 25 million back !!!
https://twitter.com/lawmaster/status/1252483198115774464

19 May 2020
BlockFi Experiences Data Breach – Crypto Lending Hack
https://defirate.com/blockfi-hack/

18 Jun 2020
A cryptocurrency bug put $545,000 of DeFi funds at risk
https://decrypt.co/32720/a-cryptocurrency-bug-put-545000-of-defi-funds-at-risk

20 Jun 2020
Balancer hacked ~ $ 500,000
https://medium.com/balancer-protocol/incident-with-non-standard-erc20-deflationary-tokens-95a0f6d46dea

14 Jul 2020
How BZRX Uniswap Listing Made One Trader $550K In 30 Mins
https://cryptopotato.com/how-bzrx-uniswap-listing-made-one-trader-550k-in-30-mins/

5 August 2020
Blatant “bug” led to $370,000 DeFi hack, say experts. Opyn hack.
https://decrypt.co/37671/blatant-bug-led-to-370000-defi-hack-say-expert

7 September 2020
$250k Soft Yearn (SYFI)
https://cointelegraph.com/news/jackpot-user-turns-200-into-250k-thanks-to-a-buggy-defi-protocol

13 September 2020
$8M  bZx protocol
https://www.theblockcrypto.com/post/77656/defi-protocol-bzx-attacked-lost-8-million-faulty-code

14 September 2020
$8M returned  bZx protocol
https://twitter.com/bZxHQ/status/1305496675474006017

29 September 2020
$15 Million  Hackers Drain $15 Million From ‘Unreleased’ Yearn Finance Project
https://bitcointalk.org/index.php?topic=5267124.msg55282297#msg55282297

29 September 2020
$10 Million  $10 Million Ethereum Vulnerability Patched by Whitehat Hacker
https://fullycrypto.com/10-million-ethereum-vulnerability-patched-by-whitehat-hacker

11 October 2020
wLEO Was Hacked on Ethereum. Damage $ 42,000
https://bitcointalk.org/index.php?topic=5267124.msg55365482#msg55365482

26 October 2020
Harvest Finance- 23 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55455370#msg55455370

12 November 2020
Akropolis- 2 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55591391#msg55591391

14 November 2020
Value DeFi 6 million US dollars
https://twitter.com/value_defi/status/1327660571592773632

17 November 2020
Origin Defi Protocol 7 million US dollars
https://news.bitcoin.com/origin-defi-protocol-suffers-massive-flash-loan-attack-ousd-stablecoin-value-plunges-85/

22 November 2020
DeFi Protocol Pickle Finance 20 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55653413#msg55653413

14 December 2020
Nexus Mutual  8 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55829590#msg55829590

18 December 2020
Warp Finance 7,7 million US dollars
https://www.theblockcrypto.com/linked/88415/defi-warp-finance-attacked-lost-7-7-million-stablecoins

28 December 2020
DeFi protocol Cover 5 million US dollars
https://www.theblockcrypto.com/post/89368/defi-protocol-cover-exploited-attackers-minted-at-least-40-quintillion-tokens

___

https://decrypt.co/54128/hackers-stole-3-8-billion-in-cryptocurrency-hacks-in-2020
Hackers Stole $3.8 Billion in Cryptocurrency Hacks in 2020

Information disclosure and analysis of major hacks in the DeFe ecosystem
https://github.com/yearn/yearn-security/tree/master/disclosures
__

2021

February 4, 2021
Yearn.finance 9 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56271047#msg56271047

February 14, 2021
Cream Finance 37,5 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56458888#msg56458888

February 28, 2021
Furucombo 14 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56458888#msg56458888

March 4, 2021
Meerkat Finance (Binance Smart Chain) 32 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56490389#msg56490389

March 5, 2021
PAID Network (PAID) 3 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56498767#msg56498767

March 8, 2021
DODO DEX 2 million US dollars, $1.89 million has been recovered
https://bitcointalk.org/index.php?topic=5267124.msg56530098#msg56530098

March 15, 2021
Roll 3000 ETH
https://cryptoslate.com/hackers-steal-3000-eth-from-roll-causing-massive-price-dumps-of-nearly-100/

March 17, 2021
Iron Finance $170,000  
https://bitcointalk.org/index.php?topic=5267124.msg56605708#msg56605708

March 20, 2021
TurtleDex  9000 BNB =2.4M $  
https://bitcointalk.org/index.php?topic=5267124.msg56617046#msg56617046

April 4, 2021
Force DAO - $367 000
https://bitcointalk.org/index.php?topic=5267124.msg56864596#msg56864596

April 19, 2021
EasyFi DeFi protocol - 6M $
https://bitcointalk.org/index.php?topic=5267124.msg56835129#msg56835129

May 2, 2021
Spartan Protocol -30M
https://bitcointalk.org/index.php?topic=5267124.msg56919497#msg56919497

May 9, 2021
Rari Capital  -10M
https://bitcointalk.org/index.php?topic=5267124.msg57018020#msg57018020

May 12, 2021
(DeFi) protocol xToken  -24.5M
https://bitcointalk.org/index.php?topic=5267124.msg56997287#msg56997287

May 20, 2021
Pancake Bunny  -200M
https://bitcointalk.org/index.php?topic=5267124.msg57050581#msg57050581

May 20, 2021
Venus Incident Report
https://bitcointalk.org/index.php?topic=5267124.msg57054439#msg57054439

May 27, 2021
Wild Credit $ 637K.  All funds were returned to the protocol.
https://bitcointalk.org/index.php?topic=5267124.msg57106288#msg57106288

May 28, 2021
DeFi project BurgerSwap - $ 7.2M
https://bitcointalk.org/index.php?topic=5267124.msg57106299#msg57106299

May 30, 2021
DeFi project Belt Finance - $ 6.2M
https://bitcointalk.org/index.php?topic=5267124.msg57120256#msg57120256

Jyne 21, 2021
DeFi project Impossible finance - $ 0.5M
https://bitcointalk.org/index.php?topic=5267124.msg57284357#msg57284357

Jyne 28, 2021
Safe Dollar - $ 0.25M
https://bitcointalk.org/index.php?topic=5267124.msg57340075#msg57340075

July 1, 2021
WhaleFarm- $ 2M
https://bitcointalk.org/index.php?topic=5267124.msg57367513#msg57367513

July 11, 2021
ChainSwap - $8M
https://bitcointalk.org/index.php?topic=5267124.msg57439162#msg57439162

July 15, 2021
Bondly Finance - Token Price Tanks
https://bitcointalk.org/index.php?topic=5267124.msg57473981#msg57473981

July 16, 2021
THORChain -2500 ETH
https://bitcointalk.org/index.php?topic=5267124.msg57471971#msg57471971

August 4, 2021
Popsicle Finance -25M
https://bitcointalk.org/index.php?topic=5267124.msg57613393#msg57613393

August 10, 2021
PolyNetwork -600M
https://bitcointalk.org/index.php?topic=5267124.msg57662150#msg57662150

August 12, 2021
Poly Network Hacker Returns $342 Million
https://bitcointalk.org/index.php?topic=5267124.msg57677686#msg57677686

August 13, 2021
Maze Protocol -4M
https://bitcointalk.org/index.php?topic=5267124.msg57691964#msg57691964

August 14, 2021
DAO Maker -7M
https://bitcointalk.org/index.php?topic=5267124.msg57677718#msg57677718

August 19, 2021
Ethereum DEX Avoids $350M DeFi Hack
https://bitcointalk.org/index.php?topic=5267124.msg57731551#msg57731551

August 29, 2021
xToken- 4,5M
https://bitcointalk.org/index.php?topic=5267124.msg57820934#msg57820934

August 30, 2021
Cream Finance-19M
https://bitcointalk.org/index.php?topic=5267124.msg57820934#msg57820934

August 31, 2021
Aurory Project-0,5M
https://bitcointalk.org/index.php?topic=5267124.msg57835544#msg57835544

September 4, 2021
DAO Maker-4M
https://bitcointalk.org/index.php?topic=5267124.msg57857298#msg57857298

September 10, 2021
AFKSystems -12M
https://bitcointalk.org/index.php?topic=5267124.msg57910886#msg57910886

September 12, 2021
Zabu Finance -3,2M
https://bitcointalk.org/index.php?topic=5267124.msg57923560#msg57923560     !

September 17, 2021
MISO IDO platform (Hack and return of coins) -865 ETH (3M)
https://bitcointalk.org/index.php?topic=5267124.msg57957934#msg57957934  

September 20, 2021
pNetwork Protocol -$12M
https://bitcointalk.org/index.php?topic=5267124.msg57980467#msg57980467  

September 21, 2021
Vee.Finance  -$35M
https://bitcointalk.org/index.php?topic=5267124.msg57995378#msg57995378

September 30, 2021
Compound bug  -$80M
https://bitcointalk.org/index.php?topic=5267124.msg58062585#msg58062585

October 15, 2021
Indexed Finance -$16M
https://bitcointalk.org/index.php?topic=5267124.msg58188360#msg58188360

October 20, 2021
PancakeHunny -$1,9M
https://bitcointalk.org/index.php?topic=5267124.msg58236768#msg58236768

October 27, 2021
Cream Finance -$130M
https://bitcointalk.org/index.php?topic=5267124.msg58283286#msg58283286

November 5, 2021
bZx -$55M
https://bitcointalk.org/index.php?topic=5267124.msg58355796#msg58355796

November 30, 2021
MonoXFinance $31 M
https://bitcointalk.org/index.php?topic=5267124.msg58586607#msg58586607

December 1, 2021
BadgerDAO $100 M
https://bitcointalk.org/index.php?topic=5267124.msg58599650#msg58599650

December 4, 2021
Polygon  801,601 MATIC tokens worth more than $2 million
https://bitcointalk.org/index.php?topic=5267124.msg58857717#msg58857717

December 8, 2021
8IGHT FINANCE- $1.75M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 11, 2021
Gelato-$26M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 13, 2021
Vulcan Forged-$140M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 21, 2021
Grim Finance  $30M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 22, 2021
Visor Finance -$8.8M
https://bitcointalk.org/index.php?topic=5267124.msg58808603#msg58808603

December 27, 2021
Metaswap Gas (MGAS) 1,100 BNB
https://bitcointalk.org/index.php?topic=5267124.msg58909773#msg58909773

December 27, 2021
METADAO 800 Ether
https://bitcointalk.org/index.php?topic=5267124.msg58909773#msg58909773

____
Reports  2021 Hack
https://bitcointalk.org/index.php?topic=5267124.msg59405892#msg59405892


2022

January 1,2022
Tinyman -  the amount of hacking is unknown
https://bitcointalk.org/index.php?topic=5267124.msg58909773#msg58909773

January 11,2022
Lympo NFT platform-  $18.7 million
https://bitcointalk.org/index.php?topic=5267124.msg58968153#msg58968153

January 28,2022
Qubit Finance,  X-Bridge  $80M
https://bitcointalk.org/index.php?topic=5267124.msg59097768#msg59097768

February 2,2022
Wormhole   $326 M
https://bitcointalk.org/index.php?topic=5267124.msg59144112#msg59144112

February 4,2022
KLAYswap   $1,83 M
https://bitcointalk.org/index.php?topic=5267124.msg59153910#msg59153910

February 8,2022
DeFi Meter   $4,3 M
https://bitcointalk.org/index.php?topic=5267124.msg59189702#msg59189702

February 8,2022
DeFi QiDao Protocol  $13 M
https://bitcointalk.org/index.php?topic=5267124.msg59191163#msg59191163

February 11,2022
Dego  damage is assessed
https://bitcointalk.org/index.php?topic=5267124.msg59218259#msg59218259

March 03,2022
Treasure DAO $1,44 M
https://bitcointalk.org/index.php?topic=5267124.msg59412238#msg59412238

March 10,2022
Fantasm Finance $2.6 M
https://bitcointalk.org/index.php?topic=5267124.msg59484103#msg59484103

March 16,2022
DeFi Agave и Hundred Finance $11 M
https://bitcointalk.org/index.php?topic=5267124.msg59484103#msg59484103

March 18,2022
Rare Bears $800K
https://bitcointalk.org/index.php?topic=5267124.msg59705205#msg59705205

March 21,2022
Li Finance $600K
https://bitcointalk.org/index.php?topic=5267124.msg59594924#msg59594924

March 22,2022
OneRing Finance $2M
https://bitcointalk.org/index.php?topic=5267124.msg59615100#msg59615100

March 23,2022
Ronin sidechain $622M
https://bitcointalk.org/index.php?topic=5267124.msg59705205#msg59705205

April 1,2022
Bored Ape Yacht Club $0,549M
https://bitcointalk.org/index.php?topic=5267124.msg59717956#msg59717956

April 2,2022
Inverse Finance $15,6M
https://bitcointalk.org/index.php?topic=5267124.msg59738961#msg59738961

April 7,2022
WonderHero $320 000
https://bitcointalk.org/index.php?topic=5267124.msg59811006#msg59811006

April 8,2022
Starstream $4M
https://bitcointalk.org/index.php?topic=5267124.msg59827200#msg59827200

April 12,2022
Elephant Money $22M
https://bitcointalk.org/index.php?topic=5267124.msg59849629#msg59849629

April 18,2022
Beanstalk $182M
https://bitcointalk.org/index.php?topic=5267124.msg59913835#msg59913835

April 20,2022
Deus Finance $13.4M
https://bitcointalk.org/index.php?topic=5267124.msg59992176#msg59992176

April 28,2022
DEFI Lender Rari Capital $80M
https://bitcointalk.org/index.php?topic=5267124.msg60014661#msg60014661

May 31,2022
Mirror Protocol   $2M
https://bitcointalk.org/index.php?topic=5267124.msg60269928#msg60269928

May 4,2022
Yacht Club (BAYC)   $0,36M
https://bitcointalk.org/index.php?topic=5267124.msg60292687#msg60292687

June 7,2022
Maiar DEX $1,65M
https://bitcointalk.org/index.php?topic=5267124.msg60309763#msg60309763

June 8 ,2022
Interlayer Snafu   $20M
https://bitcointalk.org/index.php?topic=5267124.msg60320761#msg60320761

June 16 ,2022
Inverse Finance   $1,2M
https://bitcointalk.org/index.php?topic=5267124.msg60377788#msg60377788

June 24 ,2022
Harmony   $100M
https://bitcointalk.org/index.php?topic=5267124.msg60431403#msg60431403

June 30 ,2022
NFT marketplace Quixotic $0,1M
https://bitcointalk.org/index.php?topic=5267124.msg60485134#msg60485134

July 3 ,2022
Crema Finance $6M
https://bitcointalk.org/index.php?topic=5267124.msg60500284#msg60500284
refund
https://bitcointalk.org/index.php?topic=5267124.msg60525793#msg60525793

July 3 ,2022
OMNI protocol 1300 ETH
https://bitcointalk.org/index.php?topic=5267124.msg60550807#msg60550807

July 12 ,2022
Ethereum in Massive Phishing Attack $8M
https://bitcointalk.org/index.php?topic=5267124.msg60559895#msg60559895

July 19 ,2022
PREMINT $0,4M
https://bitcointalk.org/index.php?topic=5267124.msg60597872#msg60597872

July  24 ,2022
Audius $1,1M
https://bitcointalk.org/index.php?topic=5267124.msg60639264#msg60639264

July 28 ,2022
Nirvana $3,5M
https://bitcointalk.org/index.php?topic=5267124.msg60647575#msg60647575

August 2 ,2022
Nomad Bridge $150M
https://bitcointalk.org/index.php?topic=5267124.msg60676431#msg60676431

Over $36 Million Bacк
https://bitcointalk.org/index.php?topic=5267124.msg60727075#msg60727075

August 9 ,2022
Protocol Curve $0,57M
https://bitcointalk.org/index.php?topic=5267124.msg60727075#msg60727075

August 30 ,2022
OptiFi $0,661M
https://bitcointalk.org/index.php?topic=5267124.msg60898572#msg60898572


September 1 ,2022
Kyber Network $0,265M
https://bitcointalk.org/index.php?topic=5267124.msg60859039#msg60859039

September 7 ,2022
Nereus Finance $0,37M
https://bitcointalk.org/index.php?topic=5267124.msg60898716#msg60898716

September 8 ,2022
New Free DAO $1,25M
https://bitcointalk.org/index.php?topic=5267124.msg60936613#msg60936613

September 20 ,2022
Wintermute $160M
https://bitcointalk.org/index.php?topic=5267124.msg60974088#msg60974088

September 27 ,2022
address exploit $0,95M
https://bitcointalk.org/index.php?topic=5267124.msg61024467#msg61024467

October 02 ,2022
Transit Swap $21M and return $18.9M
https://bitcointalk.org/index.php?topic=5267124.msg61066552#msg61066552

October 07 ,2022
BNB BRIDGE $80M
https://bitcointalk.org/index.php?topic=5267124.msg61079836#msg61079836

October 11 ,2022
DeFi Service Mango $100M
https://bitcointalk.org/index.php?topic=5267124.msg61107825#msg61107825
Mango exploiter (Avraham Eisenberg) arrested
https://bitcointalk.org/index.php?topic=5267124.msg61508069#msg61508069

October 12 ,2022
TempleDAO $2,3M
https://bitcointalk.org/index.php?topic=5267124.msg61107825#msg61107825

October 18 ,2022
Celo Protocol Moola Market $10M recovered over 93% funds
https://bitcointalk.org/index.php?topic=5267124.msg61148417#msg61148417

October 26 ,2022
Decentralized exchange QuickSwap exploited for $220K
https://bitcointalk.org/index.php?topic=5267124.msg61188392#msg61188392

October 28 ,2022
Team Finance DeFi protocol  $15.8 million
https://bitcointalk.org/index.php?topic=5267124.msg61199142#msg61199142

November 02 ,2022
decentralized Rubic exchange $1.2 million
https://bitcointalk.org/index.php?topic=5267124.msg61226574#msg61226574

November 02 ,2022
Deribit crypto exchange $28M
https://bitcointalk.org/index.php?topic=5267124.msg61226602#msg61226602

November 04 ,2022
DeFi Protocol Solend  $1.26M
https://bitcointalk.org/index.php?topic=5267124.msg61238487#msg61238487

November 15 ,2022
DFX Finance Hacked $4M
https://bitcointalk.org/index.php?topic=5267124.msg61301029#msg61301029

November 15 ,2022
DeFi project Flare on hacked. $17.9 million
https://bitcointalk.org/index.php?topic=5267124.msg61301029#msg61301029

December 02 ,2022
Ankr DeFi protocol  $15 million
https://bitcointalk.org/index.php?topic=5267124.msg61381777#msg61381777

December 11 ,2022
lodestar finance $7M
https://bitcointalk.org/index.php?topic=5267124.msg61426658#msg61426658

December 17 ,2022
Solana DeFi Exchange Raydium $2M
https://bitcointalk.org/index.php?topic=5267124.msg61457362#msg61457362

December 25 ,2022
Rubic DEX $1.4M
https://bitcointalk.org/index.php?topic=5267124.msg61510118#msg61510118

December 26 ,2022
Defrost Finance  hack & returned $12M
https://bitcointalk.org/index.php?topic=5267124.msg61510118#msg61510118

_______________________________________________________________

2023 DeFi hacks. Continuation
https://bitcointalk.org/index.php?topic=5267124.msg61709519#msg61709519

_______________________________________________________________

Report for 4 months 2022
https://bitcointalk.org/index.php?topic=5267124.msg60045276#msg60045276

https://cryptosec.info/defi-hacks/
https://rekt.news/
https://hacked.slowmist.io/

Funds Stolen from Crypto Platforms 2016-2023
https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2024/

Russian
https://bitcointalk.org/index.php?topic=5227888.0


Title: Re: DeFi hacks [history]
Post by: FinneysTrueVision on August 06, 2020, 09:57:09 PM
This one happened just a couple days ago.
https://decrypt.co/37671/blatant-bug-led-to-370000-defi-hack-say-experts


Title: Re: DeFi hacks [history]
Post by: cryptoaddictchie on August 07, 2020, 05:38:22 AM
Ive read before the issue on Uniswap when BZRX launches their IDO but as Ive read the article the author explained how the guy made 500k usd but not in the form of hack but incorporate a defi trading bot. As far as Ive known, using bots on trading is common its just happened that we can see now the cons of smart contract where it can be easily penetraded by the likes of this. Im not sure whether this included or considered as hack history. Actually the guy is smart. Does he violate any rule on dex? Not sure but this could be raise on authority as one of the example of threats on defi business.

14 Jul 2020
How BZRX Uniswap Listing Made One Trader $550K In 30 Mins
https://cryptopotato.com/how-bzrx-uniswap-listing-made-one-trader-550k-in-30-mins/


Title: Re: DeFi hacks [history]
Post by: foxy on August 07, 2020, 09:00:21 AM
In a short period, a lot of DeFi projects got hacked. I invested in BAL kinda at a peak and as soon as news about hack broke price fell sharply but, now thanks to binance listing and BTC price surge I was able to break even on my investment. Got lucky i guess.


Title: Re: DeFi hacks [history]
Post by: hrunya102 on August 07, 2020, 09:51:39 AM
Decentralized Finance in the event of a hack, you have no one to complain to, and this is probably the main reason why I do not use DEFI to the full.


Title: Re: DeFi hacks [history]
Post by: r32godzilla on August 07, 2020, 10:21:19 AM
Thanks! It is very important to give people real information. People think that decentralized finances do not have any risks! But it is absolutely vice versa. It is a new industry, new code, no one tested it for a long time, so be careful and invest only what you can afford.


Title: Re: DeFi hacks [history]
Post by: wmaurik on August 07, 2020, 12:40:57 PM
Good thread, and it seems like this can make people who want to invest in DeFi to increase their knowledge so they don't regret after buying DeFi coin, in addition to hacking cases there are actually also frequent exit scams like this $100 DeFi coin which can drop to $9 less in one week.


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 07, 2020, 01:08:33 PM
If you look at the losses, this is a small amount compared to what was stolen from crypto exchanges.
I use defi for exchange, hedging, but I do not recommend newcomers to invest in pools. You can make a profit as well as incur a loss if someone makes a successful arbitration.

https://furucombo.app/
I will recommend an interesting project to get acquainted with defi. It allows almost any user to experience the defi ecosystem without having enough knowledge and coins.


Title: Re: DeFi hacks [history]
Post by: foxy on August 08, 2020, 07:12:38 AM
If you look at the losses, this is a small amount compared to what was stolen from crypto exchanges.
I use defi for exchange, hedging, but I do not recommend newcomers to invest in pools. You can make a profit as well as incur a loss if someone makes a successful arbitration.

https://furucombo.app/
I will recommend an interesting project to get acquainted with defi. It allows almost any user to experience the defi ecosystem without having enough knowledge and coins.

@zasad this is a really impressive project before I had to go to different DeFi sites to complete an arbitrage trade but, here it's all simple and from one site. This will also save me from some price slippage if I am correct.
Bookmarked and thanks :)


Title: Re: DeFi hacks [history]
Post by: dondonk on August 08, 2020, 09:09:03 AM
It's amazing that in just 1 year there have been 9 attacks on decentralized finance. it is a challenge for developers to fix the system to cover the loopholes that could be harmful. also to realize a new and better security system.


Title: Re: DeFi hacks [history]
Post by: seven.71 on August 08, 2020, 03:53:21 PM
too overhype DEFI even there are a lot of attack events that occur, the average attack is by manipulating smart contracts, and it's done repeatedly as if they understand the weaknesses that exist,
and it's been just a few terrible days 

.
https://decrypt.co/37671/blatant-bug-led-to-370000-defi-hack-say-experts


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 08, 2020, 08:53:03 PM
If you look at the losses, this is a small amount compared to what was stolen from crypto exchanges.
I use defi for exchange, hedging, but I do not recommend newcomers to invest in pools. You can make a profit as well as incur a loss if someone makes a successful arbitration.

https://furucombo.app/
I will recommend an interesting project to get acquainted with defi. It allows almost any user to experience the defi ecosystem without having enough knowledge and coins.

@zasad this is a really impressive project before I had to go to different DeFi sites to complete an arbitrage trade but, here it's all simple and from one site. This will also save me from some price slippage if I am correct.
Bookmarked and thanks :)
The project is excellent, but finding an arbitration opportunity to earn money is a very difficult process.
In practice, I myself constantly face the problem of large commissions, when when exchanging tokens or stablecoins for 1000 dollars, I have to pay 30-50 dollars in commission. At such a cost, this system cannot compete with centralized exchanges.
And by the launch of the 2nd phase of ETH 2.0, it is possible that user-friendly interfaces for many projects will be made, and then a new milestone in the world of cryptocurrencies will come.


Title: Re: DeFi hacks [history]
Post by: royalfestus on August 08, 2020, 10:06:15 PM
I think the pump in price of ethereum is also instrumental in the dump of other DEFI, if after any long sideway price move of ethereum we dont see some come back of the DEFI then I might probably have a rethink on them. Actually I dont expect a 100% success of every DEFI coin because the team and community defers in capacity of project development and financial strength. Some still believe it is a good way to pull back the market to start the bull run.


Title: Re: DeFi hacks [history]
Post by: hatshepsut93 on August 09, 2020, 03:37:17 AM
If you look at the losses, this is a small amount compared to what was stolen from crypto exchanges.
I use defi for exchange, hedging, but I do not recommend newcomers to invest in pools. You can make a profit as well as incur a loss if someone makes a successful arbitration.

https://furucombo.app/
I will recommend an interesting project to get acquainted with defi. It allows almost any user to experience the defi ecosystem without having enough knowledge and coins.

The amount is small because the amount of funds in DeFi is also small. If you want to compare the two, you should use percentages of total funds. In DeFi the losses are pretty big, like a half of the funds or all of the funds. With exchanges, they generally don't lose all their money if it's no an exit scam. Their how wallets is just a fraction of the coins that they hold.

And if you take this year, it's clear that there was more of the DeFi hacks than exchange hacks. So, thinks kinda look not good for DeFi, though it seem to have no effect on hype for now.


Title: Re: DeFi hacks [history]
Post by: cryptomaniac_xxx on August 09, 2020, 11:15:52 AM
I also created a similar thread: List of Defi Hacks (https://bitcointalk.org/index.php?topic=5266973.0).


Title: Re: DeFi hacks [history]
Post by: jacafbiz on August 10, 2020, 12:07:34 PM
All these hacks are bound to happen with DEFI space just getting the attention recently hacker are bound to look for vulnerabilities in the system and exploit it but the main question is if the team would learn from mistakes and make the space better


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on August 14, 2020, 05:02:56 AM
There were 2 more Defi smart contracts that had bugs that were exploited again. Where did these developers come from? I reckon some of them might be the unqualified developers who were rejected or will be rejected by legitimate tech companies.

I am sorry. I do not want to call them bad, however, investors are losing money because of their incompetence.



DeFi meme coin YAM has succumbed to a bug within its rebase function, meaning the coin has lost control of its on-chain governance feature.

All of the roughly $750,000 Curve tokens stored in the project's treasury are lost as well, according to a Medium blog from the team.


Source https://www.coindesk.com/defi-meme-coin-yam-succumbs-to-fatal-rebase-bug



The CRV token officially, yet unexpectedly, launched at 6:25 PM EST today after an anonymous user, apparently unilaterally, deployed the open-source CRV token and CurveDAO contracts on the Ethereum mainnet earlier in the day.

Source https://decrypt.co/38708/anonymous-defi-user-deploys-curve-crv-token-early


Title: Re: DeFi hacks [history]
Post by: cryptoaddictchie on August 14, 2020, 07:22:57 AM
however, investors are losing money because of their incompetence.
Aside from the bugs and developer's incompetence. I dont think we should shift the blame on them alone. There is also some problem on the side of investors. They just keep jumping off any defi projects that they will saw without much any knowledge on the tech and its function. Im sure 2 of these defi projects have been bought by fomo squads. Definitely when they already on rekt mode, they will spat scam on these. Typical but thats how the cycle rolls and curve will likely be a hot token for being listed on Binance.


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on August 15, 2020, 05:07:45 AM
@cryptoaddictchie. I am not talking about the scams on the market and how we are manipulated to lose our investments. This thread is about hacks and exploits because of developer incompetence.

Is this really the future of finance? This is the comedy of the cryptospace.


Title: Re: DeFi hacks [history]
Post by: cryptoaddictchie on August 15, 2020, 05:20:20 AM
@cryptoaddictchie. I am not talking about the scams on the market and how we are manipulated to lose our investments.
Im aware dude. I just given emphasize on the quoted part. But thanks for sharing the info about the incident especially on yam's case. Though that incident doesnt really can be called hacked but like what you said lack of competence and failure to accomplish its goal.


Is this really the future of finance? This is the comedy of the cryptospace.
Well in fairness some agree to that. But seriously,  in my opinion only few of them makes that comedy. Not all are shit but some have good ideals too.


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on August 16, 2020, 03:46:09 AM
@cryptoaddictchie. Many of them are comedies. Look at the list.

Also, I am not telling everyone that the concept of Defi is comedy. I am only telling everyone that the implementations of Defi are weak, buggy and exploitable. Is this the future of finance?



In any case, everyone should also remember that Defi needs a centralized organization to act as an oracle. This is the same type of trust that you are putting on financial institutions and companies and without the government to protect you and make the people behind the Defi project accountable.

This is a very bad situation for the user.

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 09, 2020, 09:29:34 AM
Soft Yearn (SYFI)
https://cointelegraph.com/news/jackpot-user-turns-200-into-250k-thanks-to-a-buggy-defi-protocol
"An anonymous user managed to net a profit of $250k from a $200 outlay due to a flaw in a DeFi protocol clone’s rebase code.
An anonymous user has revealed how he made $250k in profits from a minor investment in a cloned version of Yearn.finance called Soft Yearn (SYFI)."
https://twitter.com/A_mplify/status/1302852245059330048


Title: Re: DeFi hacks [history]
Post by: Bossfidelity on September 09, 2020, 10:12:25 AM
Defi hacks is gaining more popularity over time and it feels like the more we hear of hacks and dumps, the more Defi projects that are being established and pumped. I'm personally scared of investing in Defi projects however lucrative they may be, due to the fear of losses which may arise as Defi seems like a bubble
to me.


Title: Re: DeFi hacks [history]
Post by: kolap on September 09, 2020, 10:13:47 AM
What about that Sushi DiFi hack, or I would say scam?


Title: Re: DeFi hacks [history]
Post by: princecharles on September 09, 2020, 10:57:45 AM
The hacks of Defi projects is the new normal. Most times we see Defi projects as a gold mine, but in real fact its a risk trap that has ensnared many. The prevalence of the hacks on Defi projects should be an indicator of the weakness of the projects and that should be taking into consideration when one making investment decisions.


Title: Re: DeFi hacks [history]
Post by: Yaunfitda on September 14, 2020, 08:48:44 AM
Maybe you need to update it with the latest bZx hacked?

https://i.imgur.com/Z4U8jHO.png

https://twitter.com/MarcThalen/status/1305354469354303488

You can also read more about the incident here: https://bzx.network/blog/incident


Title: Re: DeFi hacks [history]
Post by: wanted sliter on September 14, 2020, 09:17:33 AM
The majority of hacks happen on the Ethereum platform. Is it the programmer's fault or the platform?
I am waiting for a hack on the Tronix platform.
Recently the hacks are related to the Rebased token bug. It happens on projects with anonymous teams.


Title: Re: DeFi hacks [history]
Post by: Malam90 on September 14, 2020, 09:25:12 AM
Thanks! It is very important to give people real information. People think that decentralized finances do not have any risks! But it is absolutely vice versa. It is a new industry, new code, no one tested it for a long time, so be careful and invest only what you can afford.

Right, many people think it is risk free but it is also risky either from hackers or price dump. Price is not a factor but security is must concern here and from this useful post, it is clear that DeFi projects aren't free from risky. As it is new system, new codes should be developed regularly to be more secured otherwise it will be cause of damage to the investors.


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 14, 2020, 09:57:08 AM
https://www.theblockcrypto.com/post/77656/defi-protocol-bzx-attacked-lost-8-million-faulty-code
DeFi protocol bZx attacked once again, lost $8 million due to a faulty code

"Quick Take
DeFi lending protocol bZx was attacked once again last night and lost $8 million due to a faulty code.
bZx co-founder Kyle Kistner told The Block that “it’s difficult to say” how this “critical” bug went unidentified by the protocol’s two audit firms Peckshield and Certik."

iToken Duplication Incident Report
https://bzx.network/blog/incident


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on September 15, 2020, 02:30:57 AM
@zasad@. bZx was attacked 3 times according to an article from Cryptoslate cryptocoin news outlet. This forces you question the qualifications of the development teams behind those Defi projects. Did they get a coding degree from codecademy.com hehehe?


Title: Re: DeFi hacks [history]
Post by: cryptomaniac_xxx on September 15, 2020, 09:51:43 AM
@zasad@. bZx was attacked 3 times according to an article from Cryptoslate cryptocoin news outlet. This forces you question the qualifications of the development teams behind those Defi projects. Did they get a coding degree from codecademy.com hehehe?
The thing is that it has been audited by a third party, but didn't capture the bugs itself. So obviously, the blame should be on both the developers and that independent 3rd party. Although my take is that it's really hard to do simulation or create all the test cases because this is fairly new 'technology'.


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 16, 2020, 09:24:03 AM
https://twitter.com/bZxHQ/status/1305496675474006017
"We are relieved to announce that the missing funds are now restored. More information will follow.

Stay tuned!"

The stolen funds have been returned.

According to rumors, the hacker was found because he sent money from his wallets to centralized exchanges. His identity has been established.


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on September 21, 2020, 02:38:37 AM
@zasad@. Someone should teach the hacker about cryptonote coins hehe.

In any case, this is not a Defi hack article, however, this is also very questionable. It promises that its token's price floor only rises because of the magic of their taxation event.

I reckon paycoin had also a similar promise. The scam did not end very well for them.


Price floor: The price floor increases with every taxation event. This is the lowest possible price the contract will exchange TRIB for mUSD. The mUSD is sent to mStable’s saving contract where it continuously generates interest. As more and more sellers and buyers transact with the protocol, the price floor perpetually moves up. As long as there is buying and selling to the contract, it is impossible for the price floor not to go up over time. While many tokens out there can (and probably will) go to zero, that will be impossible with TRIB — it will have interest bearing capital permanently locked into the protocol.

Source https://medium.com/@defisatoshi2.0/introducing-a-new-paradigm-in-defi-the-pooled-interest-savings-token-171e02691ab9


Title: Re: DeFi hacks [history]
Post by: Zazzu on September 21, 2020, 05:34:46 AM
please add UNI leakage from metamask wallets , I don't think metamask is a right place to keep money, that is not the first time such a thing happens with metamask , I really don't like it , I would rather trust wallet .


Title: Re: DeFi hacks [history]
Post by: maxreish on September 21, 2020, 12:09:51 PM
See? There's a lot more coming on the list. It just indicates that DEFI hype projects were being targetted by the scammers. Thus, many investors were already been tricked with this hype. I'm not saying "all defi" but we can just count few of them that are really created for financial decentralized protocols for the enhancement of system and to sustain the sincere innovation.


Title: Re: DeFi hacks [history]
Post by: giammangiato on September 21, 2020, 12:17:39 PM
I can definitely say that DEFI looks more scam than a good project. This is because behind some projects there aren't good teams, the team makes the 80% of the value of the coin, after there is the project. There are good projects with bad teams that will go only in one direction, down


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 29, 2020, 07:51:51 AM
https://decrypt.co/43203/hackers-drain-15-million-from-unreleased-yearn-finance-project
Hackers Drain $15 Million From ‘Unreleased’ Yearn Finance Project
"A smart contract vulnerability allowed hackers to mint unlimited tokens and sell those for millions of dollars—before returning half the funds to Yearn founder Andre Cronje.

In brief
Hackers targeted a smart contract vulnerability in an upcoming project by Yearn founder Andre Cronje.
They managed to steal over $15 million; but returned $8 million to a wallet owned by Cronje.
The "test in prod" approach proved costly, as Cronje alleged received threats after the hack. "


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on September 30, 2020, 04:49:29 AM
@zasad@. The skeptical me thinks that this is the beginning of the Defi exit scams. He tweeted about his not completed and unaudited smart contract and then suddenly from his deployer account, an attacker deposited $8 million?



Title: Re: DeFi hacks [history]
Post by: zasad@ on October 01, 2020, 12:47:39 PM
I try to keep track of all defi hacks in this thread. Considering that this topic has become popular in 2020, we can conclude that the number of hacks is not so much,
the amount of stolen funds is much less than the centralized exchanges lose.

Fresh good news
$10 Million Ethereum Vulnerability Patched by Whitehat Hacker
https://fullycrypto.com/10-million-ethereum-vulnerability-patched-by-whitehat-hacker


Title: Re: DeFi hacks [history]
Post by: AmoreJaz on October 01, 2020, 01:41:10 PM
@zasad@. The skeptical me thinks that this is the beginning of the Defi exit scams. He tweeted about his not completed and unaudited smart contract and then suddenly from his deployer account, an attacker deposited $8 million?


can we say some of them are inside job? and i do agree most of these defis will one by one disappear in no time. as they collect their share from the market, the people behind the project are thinking of ways how to get away from their scheme.
 and ive seen that some hacks are due to the bug in their system. i believe a lot of these DeFis are not yet ready to deploy their network, however, owed to the ambitious goal of taking advantage of the hype, they situated themselves to vulnerability attack. guess, we will be seeing more projects in the list. or is there a list already for all the defi exit scams?


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on October 02, 2020, 11:41:57 PM
I try to keep track of all defi hacks in this thread. Considering that this topic has become popular in 2020, we can conclude that the number of hacks is not so much,
the amount of stolen funds is much less than the centralized exchanges lose.

Fresh good news
$10 Million Ethereum Vulnerability Patched by Whitehat Hacker
https://fullycrypto.com/10-million-ethereum-vulnerability-patched-by-whitehat-hacker

Hehe the skeptical me is thinking that the whitehat hacker might also be someone from their development team trying to make it appear a 3rd party has audited their code and make the project appear more trustworthy.


Title: Re: DeFi hacks [history]
Post by: bobyhodob on October 02, 2020, 11:57:21 PM
I try to keep track of all defi hacks in this thread. Considering that this topic has become popular in 2020, we can conclude that the number of hacks is not so much,
the amount of stolen funds is much less than the centralized exchanges lose.

Fresh good news
$10 Million Ethereum Vulnerability Patched by Whitehat Hacker
https://fullycrypto.com/10-million-ethereum-vulnerability-patched-by-whitehat-hacker

Hehe the skeptical me is thinking that the whitehat hacker might also be someone from their development team trying to make it appear a 3rd party has audited their code and make the project appear more trustworthy.
the possibility could happen because I don't think it's possible if they did the hack with a very high security system it would just make me think maybe someone in development was involved in this hack.


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 12, 2020, 04:06:12 PM
https://leofinance.io/hive-167922/@leofinance/wleo-was-hacked-on-ethereum-or-thank-you-everyone-for-the-amazing-support

"You've probably heard the news by now. The wLEO contract was exposed to a hack earlier today on Ethereum which led to a massive drain on the pool.

Fortunately, many users were quick to realize that these were false transactions and they removed liquidity from the pool as soon as they found out. This reduced the hackers ability to steal ETH from the pool.

Earlier today, we managed to shut down the contract and withdraw the remaining liquidity from the pool (about 114 ETH).

It will take us some time to snapshot the balances before the hack and figure out who had withdrawn liquidity vs. who was still in the pool at the time of the hack, but we will continually work on it and keep you posted on the distribution of this ETH back to LPs.

From what I keep hearing, this has happened to many other pools on Uniswap. The token issuing contract/address gets exposed and then someone takes advantage of it to mint infinite tokens and rug pull the Uniswap pool to steal the Ethereum."

Damage $ 42,000


Title: Re: DeFi hacks [history]
Post by: ololajulo on October 12, 2020, 04:12:33 PM
Most of the hack in the list did have that uproar and discussion in most cryptocurrency social media platform. Is not that is not important, it is just that the market sentiment had changed. Most people that endured the bear market have not recovered from the long down trend in the market and dont trust the movement of the price in the market but the whales are more active and wont allow such bad news to spoil the market. they will sustain the traded volume for most of the defi though there could be time to take few profit.


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 26, 2020, 09:57:04 AM
Harvest Finance- 23 million US dollars


https://www.coindesk.com/defi-platform-harvest-finance-exploit

https://twitter.com/WuBlockchain/status/1320589547747512320

"Wu learned that the y pool on the curve was attacked by hackers, with a total loss of more than 23 million US dollars. The main victim is the Chinese project Harvest Finance, which said it is still investigating and security agencies are also participating."


https://twitter.com/harvest_finance/status/1320604294190608385
"We are working actively on the issue of mitigating the economic attack on the Stablecoin and BTC pools, and will update in this thread in realtime as soon as additional details are available"


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on October 27, 2020, 01:46:56 AM
@zasad@. Other mainstream news media outlets reported that the hacker returned some if the stolen coins. I reckon that this might be evidence that the hacker was their own developer.

Does everyone expect the hacker to return some of the stolen coins from the goodness of his heart hehehe?



Hacker returned $2.5 million while Harvest Finance authors put out a $100,000 reward for anyone who can return the rest of the funds.

Source https://www.zdnet.com/article/hacker-steals-24-million-from-cryptocurrency-service-harvest-finance/



This statement tweeted by Jesse Powell, Kraken's CEO.

It appears Kraken might become the hackers paradise for stolen Defi tokens and ETH hehe.

However, if the hackers were smart, they should convert their coins to Monero only through Bisq.



It asked eight major exchanges to blacklist Bitcoin addresses used by the hacker, which at least one exchange was reluctant to do. Subtweeting the protocol, Kraken founder Jesse Powell wrote: “Stop fucking up your bullshit DeFi scams and expecting exchanges to bail you out. I will not accept your attempt at externalizing the cost of your hasty, reckless rollout.”

Source https://decrypt.co/46679/harvest-finance-offers-1-million-get-stolen-34-million-back

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 14, 2020, 01:34:35 PM
https://akropolis.substack.com/p/delphi-savings-pool-exploit

"At ~14:36 GMT we noticed a discrepancy in the APYs of our stablecoin pools and identified that ~2.0mn DAI had been drained out of the yCurve and sUSD pools.

These pools had been audited by two independent firms, however, the attack vectors used in the exploit were not identified in either audit. The essence of the exploit in question is a combination of a re-entrancy attack with dYdX flash loan origination.

The Akropolis team is currently working through a number of security procedures. The majority of funds on Akropolis are safe. Here is the current status:

Affected Pools:

YCurve and sUSD pools were drained of ~DAI 2.0mn

The stolen funds are currently held in this wallet: https://etherscan.io/address/0x9f26ae5cd245bfeeb5926d61497550f79d9c6c1c"


https://twitter.com/akropolisio/status/1326962438365966356


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on November 17, 2020, 05:05:48 AM
The development teams from these Defi projects might not know how to cashout from their creation without making it appear that they are dumping. It would not be surprising if the hacks and the thefts on their projects were done by themselves as a form of exit scam.

In any case, another one was hacked.



Origin Protocol co-founder Matthew Liu on Monday night confirmed an attack on the Origin Dollar (OUSD) vault.

"The team is all-hands on deck attempting to figure out what vulnerability was exploited and how the hacker was able to access users’ deposits," he wrote.

Though the exact exploit—some form of flash attack—isn't yet known, the Origin team estimated $7 million—a combination of ETH and DAI stablecoin—had been taken


Source https://decrypt.co/48478/ethereum-based-origin-dollar-hacked-for-estimated-7-million


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 22, 2020, 08:37:04 AM
https://decrypt.co/49149/pickle-finance-hack
"DeFi Protocol Pickle Finance Hacked For $20 MillionSomeone drained the DeFi protocol’s cDAI jar.

Pickle Finance, a DeFi protocol, was hacked to the tune of almost $20 million.
The hackers’ approach is still unknown, though some analysts are saying it doesn’t resemble a typical flash loan attack."


https://twitter.com/emilianobonassi/status/1330239233538318339

"The coffers of Pickle Finance, a decentralized finance (DeFi) protocol with a native token that looks suspiciously like Pickle Rick, of Rick and Morty fame, were drained today of $20 million in what appears to be a hack.

Pickle Finance shifts investors’ money around different DeFi protocols to maximise returns, a little like a traditional robo-advisor. "


Title: Re: DeFi hacks [history]
Post by: SistaFista on November 22, 2020, 03:17:11 PM
I like that Dforce was returning the hacked money back to the investors because $25 Million is very big loss indeed.
However, as long as the hacking events exists in crypto, im afraid people will be more reluctant to spend their money on crypto.
That being said, some new real DeFi projects should be created so we can show them that cryptocurrency really brings profit for investors.


Title: Re: DeFi hacks [history]
Post by: puremage111 on November 22, 2020, 03:30:15 PM
Most of these are mainly flash loan hack which is on price manipulation

Pickle got exploit today too
However it is not because of price manipulation but contract code exploit
Tbh Defi still had a long way to go because since everything is decentralized, it can't be reverse/pause, which is a heaven for hackers/exploiter
Because if they are capable, they can just take everything

Thus if you invested in similar project, kindly be careful with your funds


Title: Re: DeFi hacks [history]
Post by: RokokGudangGaram on November 22, 2020, 03:37:50 PM
This is why I'm skeptical to DeFi projects even though not all DeFi projects are scam still a lot of them turns out to be a scam one. Until now I'm not sure which project I should invest and which one I should avoid.


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 14, 2020, 08:24:12 PM
The CEO of decentralized finance (DeFi) insurer Nexus Mutual has lost the equivalent to over $8 million in a targeted attack, the firm disclosed Monday.
https://www.coindesk.com/ceo-of-defi-insurer-nexus-mutual-hacked-for-8m-in-nxm-tokens

"A total of 370,000 of the project’s native NXM tokens were drained from Hugh Karp’s address to one owned by the attacker at 09:40 am UTC, according to data source etherscan.io. The transaction cost 0.00429472 ETH (ETH, -0.72%), or $2.49.

Some of the stolen funds have been transferred via decentralized exchange aggregator 1inch.exchange. “We welcome any assistance to stop the funds, which will likely move quickly,” Nexus said.
"

https://etherscan.io/tx/0x4ddcc21c6de13b3cf472c8d4cdafd80593e0fc286c67ea144a76dbeddb7f3629



Title: Re: DeFi hacks [history]
Post by: bbc.reporter on December 21, 2020, 02:43:18 AM
How can we know if the developers of Defi are not the same group of people?

@zasad@. Another one for your list hehe. You should add all the losses from the Defi hacks and post how much the total losses are for 2020. We can compare 2020's total with next year's total.



Decentralized finance (DeFi) lending protocol Warp Finance has experienced a flash loan attack that resulted in a loss of $7.7 million worth of stablecoins.

Warp said the attack essentially allowed one user to borrow more funds than their collateral value, resulting in a loss for other users or lenders. Flash loans allow users to borrow funds without collateralization, provided the funds are repaid within a single blockchain transaction.


Source https://www.theblockcrypto.com/linked/88415/defi-warp-finance-attacked-lost-7-7-million-stablecoins


Title: Re: DeFi hacks [history]
Post by: Shallow on December 21, 2020, 07:57:08 AM
Just in one year and all these DeFi projects has been hacked, is this the future or revolution they promised? Is there a big flaw on Defi concept? Or it is right to say, some of these developers do not have the appropriate skills and experience to develop and manage a Defi project, meaning they just leveraged the hype to create their own projects and make money. To be frank, when I see or hear people saying they can't hold new tokens for a long term, I don't really blame them, because it is clear a very good number of new project's team are not ready for any kind of revolutionary development, but to make money.
On a more serious note, with the high number of DeFi hacks, which doesn't look like it is slowing down anytime soon, one need to be careful of the type of funds in invests in them; who even knows what will happen to most of them next year or as time goes on.


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on December 22, 2020, 01:12:07 AM
@Shallow. This might be either be the developers of Defi are incompetent fools or they are themselves the hackers of their own Defi projects. After what we have witnessed here in the cryptospace, it would not be shocking if hacking own project is the new for of exit scam.


Title: Re: DeFi hacks [history]
Post by: TheGreatPython on December 24, 2020, 09:30:29 AM
The rate at which platforms are getting hacked in crypto is quite alarming, and this happens especially when there are types of products being released, if it’s not hack then it’s going to be scammers.

These are serious problems and will be discouraging a lot of people, although the market still seems to be growing despite everything, but that doesn’t mean that all these things that has been happening should be neglected. They shouldn’t be neglected at all, I think that the new devs should always learn a lesson from those that came before them and look into how they can create something more secure, but they never do, it seems like their interest is more on the money.


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 24, 2020, 11:38:45 AM
How can we know if the developers of Defi are not the same group of people?

@zasad@. Another one for your list hehe. You should add all the losses from the Defi hacks and post how much the total losses are for 2020. We can compare 2020's total with next year's total.



Decentralized finance (DeFi) lending protocol Warp Finance has experienced a flash loan attack that resulted in a loss of $7.7 million worth of stablecoins.

Warp said the attack essentially allowed one user to borrow more funds than their collateral value, resulting in a loss for other users or lenders. Flash loans allow users to borrow funds without collateralization, provided the funds are repaid within a single blockchain transaction.


Source https://www.theblockcrypto.com/linked/88415/defi-warp-finance-attacked-lost-7-7-million-stablecoins
Thank you. I updated the first post.

the hacker returned 75% of the coins
https://twitter.com/warpfinance/status/1340484565090119683?

"On December 20th, 2020 at 0216 UTC we successfully recovered the loan collateral from the exploit, in the form of ETH/DAI-LP tokens. The value is approximately $5.85m, which is ~75% of the $7.76m lost funds."
I do not think that developers are hacking their projects


Title: Re: DeFi hacks [history]
Post by: Bitbtc8 on December 24, 2020, 11:54:49 AM
Decentralized Finance in the event of a hack, you have no one to complain to, and this is probably the main reason why I do not use DEFI to the full.
Well said, it's the perfect place for scammers to roam about without any fear of getting caught in the process, it's why I feel unreliable on any DeFi projects, I invested in few strong ones like ChainLink but most new DeFi projects are not safe


Title: Re: DeFi hacks [history]
Post by: sgenuine on December 27, 2020, 07:56:24 PM
The very appearance of DEFI inspired people to really hope for development. But as it is now clear, there is a huge field of activity for scammers, you can create a site very quickly, where it is difficult to find the team composition and contacts. Because of this hype, many do not even pay attention to it and blindly give their money. It turns out that one working project immediately appears a bunch of scammers.


Title: Re: DeFi hacks [history]
Post by: casperBGD on December 28, 2020, 02:15:22 PM
https://www.theblockcrypto.com/post/89368/defi-protocol-cover-exploited-attackers-minted-at-least-40-quintillion-tokens

there is another one, Cover smart contract is exploited for $40 quintillion tokens, and attacker already cashed-out $5 million from the protocol, Binance stopped deposit and price is down 76% at the moment
https://www.coingecko.com/en/coins/cover-protocol

Cover merged with YFI earlier, but Yearn.Finance does not seem under pressure due to exploit, it is flat at the moment
https://www.coingecko.com/en/coins/yearn-finance
https://medium.com/iearn/yearn-cover-merger-651142828c45


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 28, 2020, 03:34:40 PM
casperBGD, thanks, you got me on, the first post was updated. To be honest, I thought that the last hacked  Defi project in 2020 would be Warp Finance.
But I was wrong and we still have 3 days :)
I will keep an eye on the hacking of Defi projects next year, I hope there will be less bad news.


Title: Re: DeFi hacks [history]
Post by: skarais on December 28, 2020, 05:53:02 PM
To be honest, I thought that the last hacked  Defi project in 2010 would be Warp Finance.
I think you made a typo, what do you mean 2020 ? :V

But I was wrong and we still have 3 days :)
I will keep an eye on the hacking of Defi projects next year, I hope there will be less bad news.
Considering the list on the OP, it is too much to know for the fact that the defi project is simply not safe from hacking cases. Of course it will be very detrimental and i also hope that next year the case can go down.


Title: Re: DeFi hacks [history]
Post by: perla on December 28, 2020, 06:48:49 PM
This really makes me decide if I'm going to invest to DeFi projects by just looking at the list you will really know how DeFi projects can scam participants.
Well this list really helps me a lot not to look more into DeFi projects.


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 28, 2020, 08:06:00 PM
To be honest, I thought that the last hacked  Defi project in 2010 would be Warp Finance.
I think you made a typo, what do you mean 2020 ? :V

But I was wrong and we still have 3 days :)
I will keep an eye on the hacking of Defi projects next year, I hope there will be less bad news.
Considering the list on the OP, it is too much to know for the fact that the defi project is simply not safe from hacking cases. Of course it will be very detrimental and i also hope that next year the case can go down.

thanks, I corrected the typo.

Dforce return $ 25 million back !!!
https://twitter.com/lawmaster/status/1252483198115774464?

Hack Prevention
https://decrypt.co/32720/a-cryptocurrency-bug-put-545000-of-defi-funds-at-risk

bZx protocol. Refund 8,000,000 $
https://twitter.com/bZxHQ/status/1305496675474006017

$ 10 Million Ethereum Vulnerability Patched by Whitehat Hacker
https://fullycrypto.com/10-million-ethereum-vulnerability-patched-by-whitehat-hacker

Warp Finance 75% refunded.
https://forklog.com/razrabotchiki-warp-finance-vernuli-75-iz-ukradennyh-7-7-mln/

The defi ecosystem is much better than the management system of centralized exchanges. Everything is clear and transparent here.


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on February 05, 2021, 03:46:47 AM
@zasad@. Another the first Defi hack of the year for you to tally for 2021 hehehe. You have to assume that the development teams have fixed all the bugs from their systems. However, no. The hackings continue.



Yearn developer banteg, one of the administrators of the DeFi project's website, followed with a few more details: "Yearn DAI v1 vault got exploited, the attacker got away with $2.8m, the vault lost $11m. Deposits into strategies disabled for v1 DAI, TUSD, USDC, USDT vaults while we investigate."

Source https://decrypt.co/56659/14-million-gone-in-yearn-finance-exploit


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 05, 2021, 08:40:16 PM
The hardest exploit
https://etherscan.io/tx/0xb094d168dd90fcd0946016b19494a966d3d2c348f57b890410c51425d89166e8
Transaction Fee:3.37117716 Ether and 1M profit (8 out of 9 million were lost in a transaction)

https://cointelegraph.com/news/after-yearn-exploit-attacker-funds-frozen-and-reimbursement-plans-developing
After Yearn exploit, attacker funds frozen and reimbursement plans developing
Seized funds bring the damage down to $9 million as multiple communities ponder the next step in reimbursing user funds


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on February 06, 2021, 05:01:38 AM
@zasad@. You should add the grand total of the hacked amount of coins in total no. of coins itself for 2020 and compare this with the grand total of hacked coins for 2021 during the end of this year hehe.

The future of Defi or any idea in the cryptospace will depend on security.


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 06, 2021, 01:13:27 PM
@zasad@. You should add the grand total of the hacked amount of coins in total no. of coins itself for 2020 and compare this with the grand total of hacked coins for 2021 during the end of this year hehe.

The future of Defi or any idea in the cryptospace will depend on security.

I am constantly monitoring updates.
There is a very good report on hacker attacks for 2020

https://decrypt.co/54128/hackers-stole-3-8-billion-in-cryptocurrency-hacks-in-2020
Hackers Stole $3.8 Billion in Cryptocurrency Hacks in 2020
"Cybercriminals stole nearly $3.8 billion worth of different cryptocurrencies in 122 attacks in 2020, but the overall number of attacks is on decline

Dapps, or decentralized apps, running on Ethereum had 47 attacks with a current value of $436.36 million, followed by cryptocurrency exchanges that had 28 attacks ($300.15 million in losses).

Crypto wallets had 27 attacks and were the most lucrative target for the hackers, with $3.03 billion in losses. They also had the biggest average value of stolen assets - 112 million per attack compared to approximately $10 million per attack on dapps or exchanges ($9.28 million and $10.72 million respectively).

There were 12 successful attacks on blockchains themselves last year, bringing the hackers $5.91 million or $492,517 per breach. The most well-known example is probably the series of 51% attacks on the Ethereum Classic network.

There were only a few attacks on dapps based on the Tron and EOS blockchains; each saw just three dapps getting breached. Still, those attacks amounted to $10 million, or around $3.33 million per hack, in case of Tron, and $2.85 million, or $949,416 on average, for an EOS-linked breach.

The values in the study are overinflated though, since monetary losses were calculated based on the January 12, 2021 conversation rates, with Bitcoin changing hands around $34,000 that day. This is compared to how much the cryptocurrencies were worth when they were stolen."

Statistics show that defi projects are not much inferior in security to centralized exchanges. But keep in mind that in 2020, many defi projects have just gained popularity, and centralized exchanges have been operating for many years.


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on February 07, 2021, 05:06:12 AM
@zasad@. I might be better to tally the hacked and stolen amounts in no. of coins instead in dollars. The value of those coins might be more than double than their value on the day of the hack or less than double 2 years after the hack.

In any case, what is your speculation for hacked Defi projects for 2021? Will 2021 be more than the hacked amount of 2020 or less hehe?


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 15, 2021, 04:05:04 PM
I think 2021 will be more fun!

The dark arts of DeFi are the most profitable.
~$37.5M stolen from @AlphaFinanceLabs in a tale of fake magic, confusion and accusation.
https://twitter.com/RektHQ/status/1360736931693404160
https://rekt.eth.link/alpha-finance-rekt/


Title: Re: DeFi hacks [history]
Post by: GreekCoiner on February 15, 2021, 06:44:58 PM
The so called DeFis are such scams. I can't understand how people keep putting their money in such buggy smart contracts which most of them are copy/paste of other smart contracts without any audit and no insurance fund.

Almost all of these defi shitcoins created only for speculation. They won't solve any problem. Guys just avoid locking your saving there. These high APY returns don't worth the risk.


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 28, 2021, 02:00:20 PM
The 14th of February
Hacker withdrew $ 37.5 million tokens from Cream Finance's DeFi protocol
https://forklog.com/haker-vyvel-tokeny-na-37-5-mln-iz-defi-protokola-cream-finance/
https://twitter.com/CreamdotFinance/status/1360497502881865729?

https://twitter.com/FrankResearcher/status/1360513422689984512?
"IronBank ($CREAM) was exploited on $37.5M, let’s take a quick look at what happened.

1/ Attacker used Alpha Homora for borrowing sUSD from IronBank.
Each time they borrow twice as much as in the previous one."

The 28th of February

https://twitter.com/furucombo/status/1365743632460910593?
"Today at 4:47 PM UTC the Furucombo proxy was compromised by an attacker. We have deauthorized the relevant components and believe the vulnerability to be patched but we recommend users remove approvals out of an abundance of caution."

DeFi project Furucombo hacked for $ 14 million
https://forklog.com/defi-proekt-furucombo-vzlomali-na-14-mln/

"So what happened to Furucombo"
https://twitter.com/FrankResearcher/status/1365740713334493192



Meerkat Finance  (Binance Smart Chain)
Hackers withdrew from the Meerkat Finance protocol based on the Binance Smart Chain cryptoassets worth ~ $ 32 million (13.96 million BUSD and 73 635 BNB)
https://forklog.com/defi-proekt-meerkat-finance-na-baze-binance-smart-chain-zapodozrili-v-ekzit-skame/

https://twitter.com/WuBlockchain/status/1367410125443493891
"BSC project Meerkat Finance is suspected of being rug, taking away 13.96 million BUSD, and the other 73,635 BNB. MKAT claimed to be hacked and stole all resources. Currently the project website cannot be opened. This may be the largest fraud project on the binance smart chain."



PAID Network (PAID)
$ 3 million
https://www.coingecko.com/en/coins/paid-network

Network data shows that just over 2,000 ETH -- worth roughly $3 million at press time -- was obtained by the attacker after some of the 59.7 million minted PAID tokens were traded on the decentralized exchange service Uniswap. Roughly 2.5 million PAID tokens were sold over the course of 13 transactions, according to Etherscan data.
https://www.theblockcrypto.com/linked/97411/paid-network-token-minting-exploit-eth

PAID Network exploiter nets $3 million in infinite mint attack
https://cointelegraph.com/news/paid-network-exploiter-nets-3-million-in-infinite-mint-attack

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Twinkledoe on March 05, 2021, 11:28:49 PM
The so called DeFis are such scams. I can't understand how people keep putting their money in such buggy smart contracts which most of them are copy/paste of other smart contracts without any audit and no insurance fund.

Almost all of these defi shitcoins created only for speculation. They won't solve any problem. Guys just avoid locking your saving there. These high APY returns don't worth the risk.

And I believe most of these hacking incidents are inside job. A gentle way to abandon the project along with the investors' money. Seems that the list is going to be longer than centralized crypto-exchanges hacking incidents.

Won't trust my savings to defi platform, unless, it is a very reputable one in the community. The high APY is usually the bait here, but you will never get that profit because they will be dead not even a year of existence.

And thanks for the OP for consolidating this list. Please keep this updated so people here will be reminded about these cases in DeFi and be more vigilant in this industry.


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 10, 2021, 09:50:05 AM
DODO DEX
$ 2 million

https://twitter.com/BreederDodo/status/1369098897008648192
"PSA Regarding Recent Exploit on DODO

On March 8, Several DODO V2 Crowdpools were attacked. WSZO, WCRES, ETHA, and FUSI pools were impacted, while AC pool funds have been fully recovered.

Funds in all other pools, including all V1 pools and all non-Crowdpool V2 pools, are safe."

https://twitter.com/BreederDodo/status/1369335145732268033
"UPDATE: $1.89 million has been recovered and our team is in the process of returning these funds to the affected parties.

~1,139,456.20 USDT and 411.05965 ETH have been recovered (see below for the txs)."

https://etherscan.io/tx/0x6e743db045f3738b24c6dedc90bae62c6429f2f7fe8a086394b05a68b8f5867a
https://etherscan.io/tx/0xa0c522f3122ce89f4d20c0c4592574284db841abeabdf3c28d87771fdfe87b91




https://twitter.com/PancakeSwap/status/1371471934999777281

PancakeSwap has DNS hacked
"This is now confirmed.

DO NOT go to the Pancakeswap site until we confirm it is all clear.

NEVER EVER input your seed phrase or private keys on a website.

We are working on recovery now.

Sorry for the trouble."

https://twitter.com/PancakeSwap/status/1371470368058183687

"There is a chance we have been DNS hijacked, the same as @CreamdotFinance.

Until we are able to confirm this is not the case, do not use the site.

We will confirm ASAP.

In the meantime, better safe than sorry.

Please retweet for visibility!

https://twitter.com/creamdotfinance/status/1371448627663491088?s=21"



https://twitter.com/PancakeSwap/status/1371492312681902080
"We have regained access to the DNS.

Some users might still be affected, depending on their DNS resolution as some propagation time may be needed.

Will send another update shortly.

Thanks for waiting."

https://twitter.com/artofyourmind/status/1371494055465472002
"Financial advise: Anyone who had written their seed phrase should create a new account in Trust Wallet and transfer current holdings to the new account (means new seed phrases). Also unstake and send those LPs out to the new account."



$170,000  Iron Finance

Iron Finance DeFi Exploit Explained in Post Mortem
https://beincrypto.com/iron-finance-defi-exploit-explained-post-mortem/
"The latest decentralized finance protocol to get exploited is Iron Finance. The platform lost $170,000 from its liquidity pools following erroneous actions by the team.

Iron Finance is a partially collateralized stablecoin platform based on the Binance Smart Chain (BSC).

It reported that on March 16, two Iron Finance vFarm pools were “subject to an incident”. This ordeal resulted in the loss of user deposits.

It claims that an attacker managed to exploit the system and drain the pools. The bad actor(s) made off with $170,000 worth of its native SIL tokens. These were then sold for BUSD (Binance’s stablecoin) on the markets."



TurtleDex 9000 BNB =2.4M $

Binance Smart Chain Hit By $2.4 Million TurtleDex Exit Scam
"And guess what? There’s no sign of TurtleDex anywhere.
In brief
TurtleDex have exited with 9000 BNB tokens raised from a presale days ago.
The project's online presence has gone dark.
Frequent vanishing acts indicate that the growing DeFi space is still risky business."

https://decrypt.co/62204/binance-smart-chain-hit-by-2-4-million-turtledex-exit-scam



EasyFi DeFi protocol - 6M $
"The founder of the EasyFi DeFi protocol, Ankitt Gaur, published a blog post on April 20 in which he talked about how hackers managed to get to the liquidity pools and withdraw $ 6 million from them."
https://beincrypto.ru/u-defi-protokola-easyfi-ukrali-6-mln-vot-kak-eto-vyshlo/

https://twitter.com/AnkittGaur/status/1384253351492087819
"On Monday, 19th April 2021 our team members reported the transfer of a large amount of EASY and protocol funds from designated contracts & wallets. initial investigation revealed the possibility of compromise of mnemonic phrase."

EasyFi Security Incident. Pre-Post Mortem
https://medium.com/easify-network/easyfi-security-incident-pre-post-mortem-33f2942016e9



Force DAO-$367 000
https://forklog.com/defi-proekt-force-dao-podvergsya-atake-posle-zapuska/
"Force DAO DeFi Project Attacked After Launch
On Sunday, April 4, Force DAO's DeFi Protocol reported a hacker attack a few hours after launch. The FORCE project token has depreciated by 90%.
According to the developers, attackers took advantage of a vulnerability in a smart contract. The team estimated the damage at 183 ETH (~ $ 367,000)."
https://twitter.com/force_dao/status/1378764435553198087?
https://twitter.com/FrankResearcher/status/1378633819599818754



Spartan Protocol -30M
https://twitter.com/SpartanProtocol/status/1388669192228929539
"Spartan Protocol
@SpartanProtocol
What we know so far -
*Attacker used $61m in BNB to overcome the pools via a as yet unknown economic exploit path to remove roughly $30m in funds from the pools.

Reach out if you can help identify and analyse the exploit."
https://bscscan.com/tx/0xb64ae25b0d836c25d115a9368319902c972a0215bd108ae17b1b9617dfb93af8



https://www.coindesk.com/defi-protocol-xtoken-suffers-24-5m-exploit

DeFi Protocol xToken Suffers $24.5M Exploit
The protocol said minting has been paused on all contracts while an investigation takes place.

Decentralized finance (DeFi) protocol xToken said it suffered an exploit Wednesday by an attacker who used flash loans to take $24.5 million.
https://twitter.com/xtokenmarket/status/1392490733588946948?

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Dump3er on May 12, 2021, 11:31:18 PM
https://www.coindesk.com/defi-protocol-xtoken-suffers-24-5m-exploit

DeFi Protocol xToken Suffers $24.5M Exploit
The protocol said minting has been paused on all contracts while an investigation takes place.

Decentralized finance (DeFi) protocol xToken said it suffered an exploit Wednesday by an attacker who used flash loans to take $24.5 million.
https://twitter.com/xtokenmarket/status/1392490733588946948?

The list you are providing here is quite shocking, also because I have never heard of many of the hacks. So many projects say they have some certificate from an audit company. It would be interesting to see how many of the DeFi projects listed here had such an audit certificate. Maybe I'll find the time and provide some info on that.


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 13, 2021, 02:31:51 PM
https://www.coindesk.com/defi-protocol-xtoken-suffers-24-5m-exploit

DeFi Protocol xToken Suffers $24.5M Exploit
The protocol said minting has been paused on all contracts while an investigation takes place.

Decentralized finance (DeFi) protocol xToken said it suffered an exploit Wednesday by an attacker who used flash loans to take $24.5 million.
https://twitter.com/xtokenmarket/status/1392490733588946948?

The list you are providing here is quite shocking, also because I have never heard of many of the hacks. So many projects say they have some certificate from an audit company. It would be interesting to see how many of the DeFi projects listed here had such an audit certificate. Maybe I'll find the time and provide some info on that.
I have come across projects that have been audited by large audit companies and have been hacked. Don't waste your time on this.

https://decrypt.co/70690/defi-hacks-2021-ciphertrace-report
$156 Million Stolen in DeFi Hacks This Year: CipherTrace
"That’s more than was stolen from DeFi protocols in all of 2020.
In brief
$156 million was stolen from DeFi-related hacks between January and April, according to CipherTrace.
That number has risen along with the total amount of money locked up in DeFi."



Rari Capital Reports Exploit in ETH Pool; $15M Taken
https://www.coindesk.com/rari-capital-reports-exploit-in-eth-pool
According to Etherscan, $15 million worth of ether was taken.
https://etherscan.io/address/0xcb36b1ee0af68dce5578a487ff2da81282512233

https://nipunp.medium.com/5-8-21-rari-capital-exploit-timeline-analysis-8beda31cbc1a
Rari Exploiter address (same address as Value Defi exploiter on BSC): https://etherscan.io/address/0xcb36b1ee0af68dce5578a487ff2da81282512233
Exploiter net gain: ~2600 ETH (~$10M)

Rari Capital Plans to Refund Stolen $10.6M in Ethereum From Dev Fund
The attack exploited Rari Capital’s integration with Alpha Finance Labs’ ibETH token.
https://www.coindesk.com/rari-capital-loses-ethereum-to-theft


[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Dump3er on May 16, 2021, 07:00:16 PM
https://www.coindesk.com/defi-protocol-xtoken-suffers-24-5m-exploit

DeFi Protocol xToken Suffers $24.5M Exploit
The protocol said minting has been paused on all contracts while an investigation takes place.

Decentralized finance (DeFi) protocol xToken said it suffered an exploit Wednesday by an attacker who used flash loans to take $24.5 million.
https://twitter.com/xtokenmarket/status/1392490733588946948?

The list you are providing here is quite shocking, also because I have never heard of many of the hacks. So many projects say they have some certificate from an audit company. It would be interesting to see how many of the DeFi projects listed here had such an audit certificate. Maybe I'll find the time and provide some info on that.
I have come across projects that have been audited by large audit companies and have been hacked. Don't waste your time on this.

https://decrypt.co/70690/defi-hacks-2021-ciphertrace-report
$156 Million Stolen in DeFi Hacks This Year: CipherTrace
"That’s more than was stolen from DeFi protocols in all of 2020.
In brief
$156 million was stolen from DeFi-related hacks between January and April, according to CipherTrace.
That number has risen along with the total amount of money locked up in DeFi."

Then what are those audit certificates worth? It could even be an insider of the audit services provider. Imagine you detect a loophole in the code, you'd be better off hacking that thing than fixing it. I thought I also heard that they provide insurance after they did their audit. Don't which company it was, but given the size of the security breach they'd be out of business with just a single breach anyway.


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 20, 2021, 10:02:04 AM
The simplest audit costs from 10 thousand dollars, but the prices for services can reach 100,000 dollars and more.

Pancake Bunny -200 M

https://coinfomania.com/pancake-bunny-1-billion-defi-hack/
"By Wilfred MichaelMAY 20, 2021BREAKING: BSC-based DeFi Project Pancake BUNNY Suffers $1 Billion ExploitDeFi Fulcrum ETH Hacked
Pancake Bunny, a DeFi yield optimizer project built on Binance Smart Chain, has supposedly suffered an exploit that resulted in roughly $1 billion being drained from its smart contracts. The token price has dropped more than 97% in the aftermath while the community awaits an update from the team."
https://twitter.com/PancakeBunnyFin/status/1395173093333680136?





Title: Re: DeFi hacks [history]
Post by: Ucy on May 20, 2021, 11:00:20 AM
It seems they encourage people to take big risk on the so called DeFi(Decentralized Finance). You can't build a project today without proper/thorough testing before allowing the public to invest what they likely can't afford to risk/lose.
I have previously suggested opening up the DeFi platform to the public so anyone can help review projects based on list of Rules/Standards/Principles that have to be followed before a project is allowed for serious usage. Hope they don't prefer the platform to be takeover and regulated by central authorities.
Bitcoin didn't start with founders requesting people to invest huge amount of money or stake to be part of the network, help secure and keep it decentralized ... it instead paid participants... so that they risk less during its early stage and people probably began to put in money above sensible limits over time as security improves


Title: Re: DeFi hacks [history]
Post by: Lordhermes on May 20, 2021, 12:06:53 PM
You can't build a project today without proper/thorough testing before allowing the public to invest what they likely can't afford to risk/lose.
The problem is not really about the testing before going public, but how strong your developers are, a good development teams and site management is a very important factor to consider before embarking on a crypto journey, this should be taken care of thoroughly to avoid hacks and theft on their platform.

Weekly routine check or as the case may be is a good thing to constantly do on a regular to detect any technical fault by following the respective Standard Operating Procedure (SOP).


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 20, 2021, 08:44:41 PM
It seems they encourage people to take big risk on the so called DeFi(Decentralized Finance). You can't build a project today without proper/thorough testing before allowing the public to invest what they likely can't afford to risk/lose.
I have previously suggested opening up the DeFi platform to the public so anyone can help review projects based on list of Rules/Standards/Principles that have to be followed before a project is allowed for serious usage. Hope they don't prefer the platform to be takeover and regulated by central authorities.
Bitcoin didn't start with founders requesting people to invest huge amount of money or stake to be part of the network, help secure and keep it decentralized ... it instead paid participants... so that they risk less during its early stage and people probably began to put in money above sensible limits over time as security improves
Explore this report
Hackers Stole $3.8 Billion in Cryptocurrency Hacks in 2020
https://decrypt.co/54128/hackers-stole-3-8-billion-in-cryptocurrency-hacks-in-2020
"Crypto wallets had 27 attacks and were the most lucrative target for the hackers, with $3.03 billion in losses."

__
With the market correcting, the volume of liquidations in Venus' Binance Smart Chain (BSC) -based Venus DeFi Landing Protocol reached $ 200 million.
https://forklog.com/v-protokole-venus-na-baze-binance-smart-chain-proizoshli-likvidatsii-na-200/

Venus Incident Report — XVS Liquidations
https://blog.venus.io/venus-incident-report-xvs-liquidations-451be68bb08f

https://twitter.com/FrankResearcher/status/1394900186435096578?

"Today we have witnessed the manipulation of XVS price —  the governance token of Venus Protocol on BSC.

This incident resulted in $200M+ DeFi liquidations and a $100M+ of protocol bad debt.

As usual, let’s analyze this situation below👇"


Title: Re: DeFi hacks [history]
Post by: alchak77 on May 20, 2021, 08:47:08 PM
you will really know how DeFi projects can scam participants.


Title: Re: DeFi hacks [history]
Post by: Princeofpoetry on May 20, 2021, 10:20:03 PM
Since DeFi was booming last year, there have been a lot of DeFi cases being hacked. Why have so many DeFi projects been hacked? is it because of a weak security system? or clever hackers who attacked the DeFi project?


Title: Re: DeFi hacks [history]
Post by: apityeh71 on May 21, 2021, 04:52:15 AM
What about new project called HAPI? they want to solve this problem. I think currently only HAPI that have purpose to solve it. We should support this project to minimize the risk of crypto investment.


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 26, 2021, 04:45:57 PM
Analysts found serious bugs in the DeFi project SafeMoon
https://whattonews.ru/analitiki-nashli-sereznye-bagi-u-defi-proekta-safemoon/

"During the audit, HashEx specialists identified 12 vulnerabilities in the smart contracts of the DeFi project SafeMoon. The bugs found allow the withdrawal of assets worth $ 20 million and block transactions, analysts said."

https://twitter.com/stoolpresidente/status/1394379356487757834?
Dave Portnoy
My shitcoin announcement.   Invest at your own risk.    I have no idea how this works

https://twitter.com/TheCryptoLark/status/1384664238371704832?

Lark Davis
"Bitconnect was for a brief moment a top 10 #crypto, the people making money did not want to accept it was a ponzi, they made every excuse to justify it, and attacked anyone who stated the obvious.

Then it rug pulled and everyone lost big time.

#safemoon is no different."




The BNT - ETH pool of the Wild Credit protocol was devastated by an economic exploit.

$ 637K was withdrawn from the pool, but with the help of specialists from the analytical services vfat.tools and Nansen.ai, the funds were returned to the protocol.

https://twitter.com/WildCredit/status/1397848487593603072

All funds were returned to the protocol:
https://etherscan.io/tx/0xb4fffa0e824034a10af2807f1504ac247ae1dd6f2bcfed8085989bbfda434542

https://t.me/Defiscamcheck/1852

https://bitcointalk.org/index.php?topic=5227888.msg57100531#msg57100531





DeFi project BurgerSwap - $ 7.2M

https://twitter.com/burger_swap/status/1398088748563369988?

"BurgerSwap just experienced Flash Loan attack.

We have suspended Swap and BURGER generation to avoid further loss.

Our tech team is working on the issue and will publish the solution later.

More details will be published soon. Thanks for your patience."

https://twitter.com/burger_swap/status/1398163112335863811?

"What was stolen:
- 4.4k WBNB ($1.6M)
- 22k BUSD ($22k)
- 2.5 ETH ($6.8k)
- 1.4M USDT ($1.4M)
- 432k BURGER ($3.2M)
 -142k xBURGER ($1M)
- 95k ROCKS"



Belt Finance-  $6,2M

https://twitter.com/FrankResearcher/status/1398772580602060804?
"New weekend - a new attack on BSC DeFi protocol.

Today $6.2M in BUSD was stolen from Belt Finance in 8 transactions.

Below is what happened"

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: slaman29 on May 30, 2021, 03:06:17 PM
Safemoon is not the first coin to use the word safe and trust and whatever, they're all the same. They have some kind of audit for smart contract but I still feel 99% of devs in defi aren't as smart as the hackers OR are a group of people themselves all behind the scenes of these rug pulls. The law will catch up one day hopefully.


Title: Re: DeFi hacks [history]
Post by: Wingsbtc on May 30, 2021, 04:26:06 PM
Come to think of it, defi projects are the sweetest spot for scamming and hacking because there is no way the law will hunt this project down, I believe not a this hacks are real hack, since no one can complain if anything goes wrong even the team can hack themselves, who knows? 🤦


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on May 31, 2021, 04:32:56 AM
It seems they encourage people to take big risk on the so called DeFi(Decentralized Finance). You can't build a project today without proper/thorough testing before allowing the public to invest what they likely can't afford to risk/lose.
I have previously suggested opening up the DeFi platform to the public so anyone can help review projects based on list of Rules/Standards/Principles that have to be followed before a project is allowed for serious usage. Hope they don't prefer the platform to be takeover and regulated by central authorities.
Bitcoin didn't start with founders requesting people to invest huge amount of money or stake to be part of the network, help secure and keep it decentralized ... it instead paid participants... so that they risk less during its early stage and people probably began to put in money above sensible limits over time as security improves
Explore this report
Hackers Stole $3.8 Billion in Cryptocurrency Hacks in 2020
https://decrypt.co/54128/hackers-stole-3-8-billion-in-cryptocurrency-hacks-in-2020
"Crypto wallets had 27 attacks and were the most lucrative target for the hackers, with $3.03 billion in losses."

__
With the market correcting, the volume of liquidations in Venus' Binance Smart Chain (BSC) -based Venus DeFi Landing Protocol reached $ 200 million.
https://forklog.com/v-protokole-venus-na-baze-binance-smart-chain-proizoshli-likvidatsii-na-200/

Venus Incident Report — XVS Liquidations
https://blog.venus.io/venus-incident-report-xvs-liquidations-451be68bb08f

https://twitter.com/FrankResearcher/status/1394900186435096578?

"Today we have witnessed the manipulation of XVS price —  the governance token of Venus Protocol on BSC.

This incident resulted in $200M+ DeFi liquidations and a $100M+ of protocol bad debt.

As usual, let’s analyze this situation below👇"

It also appears that the manipulation on Venus and the flash loan attack was an inside job according to this article.



In this article below I will provide evidence from the blockchain that the Venus/Swipe team are directly linked to the Cannon Ignition Sale incident and the blockchain wallet responsible for causing the recent XVS account liquidations.

Source https://medium.com/@venus.insider/venus-io-disclosure-an-inside-job-f8ef195fe78d



Also, all of the other attacks are targetted towards Binance smart chain only. The skeptical me thinks that someone might be playing dirty. Solana to top 3 in coinmarketcap.com might prove this hehehehe.


Title: Re: DeFi hacks [history]
Post by: slaman29 on May 31, 2021, 07:44:14 AM
Also, all of the other attacks are targetted towards Binance smart chain only. The skeptical me thinks that someone might be playing dirty. Solana to top 3 in coinmarketcap.com might prove this hehehehe.

I really hope someone goes and collects all this evidence and then tries to pin down these guys. My personal belief is that they aren't hackers but all are inside job developers with malicious intent, possibly installing loopholes made known the attackers. And then rugpulling at will. Binance Smart Chain only makes me think this for sure. Crime pays in crypto because enforcement doesn't come and catch them.


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on June 01, 2021, 05:32:44 AM
@slaman29. All 8 flashloan attacks? I disagree. These are not rugpulls. It appears to be a well organized group exploiting weaknesses in copy/paste projects deployed in Binance smartchain.

Also, I was wrong in my assumption that Binance smartchain would be the Ethereum killer hehe. However, Solana might be the Binance smartchain killer hehehehe.


Title: Re: DeFi hacks [history]
Post by: slaman29 on June 01, 2021, 08:54:24 AM
@slaman29. All 8 flashloan attacks? I disagree. These are not rugpulls. It appears to be a well organized group exploiting weaknesses in copy/paste projects deployed in Binance smartchain.

Also, I was wrong in my assumption that Binance smartchain would be the Ethereum killer hehe. However, Solana might be the Binance smartchain killer hehehehe.

Ah sorry, I always assumed all kinds of attacks are called rug pulls in Defi. Just read it up now and rugpulls are when the project owners take out all the liquidty from the pool so yes, different mode of attack but in my book, still the same scummy people and like you said, probably all the same groups of people in the end.

Solana BSC killer? SOL starter looks almost sold out:)


Title: Re: DeFi hacks [history]
Post by: Daltonik on June 17, 2021, 08:54:36 AM
Iron Finance announced on Twitter, addressing users about the need to withdraw all liquidity from all pools, the details promise to report later, apparently the Poligon network was subjected to a ddos attack, as a result of which the price of the Titan token fell from $60 to 0. https://twitter.com/IronFinance/status/1405320650202419202

https://i.ibb.co/bz3fYqD/2021-06-17-135145.jpg (https://twitter.com/IronFinance/status/1405320650202419202)



Title: Re: DeFi hacks [history]
Post by: bbc.reporter on June 18, 2021, 05:39:41 AM
@Daltonik. I am skeptical that ddos was the cause. How can a ddos attack cause a token to pump to $60 then dump to $0? I reckon that it might be some mechanism in these dollar pegged stablecoins that when whales dump IRON, it also triggers to mint TITAN and removes liquidity to keep the peg of IRON to $1.00.


Title: Re: DeFi hacks [history]
Post by: Daltonik on June 19, 2021, 08:52:02 AM
@Daltonik. I am skeptical that ddos was the cause. How can a ddos attack cause a token to pump to $60 then dump to $0? I reckon that it might be some mechanism in these dollar pegged stablecoins that when whales dump IRON, it also triggers to mint TITAN and removes liquidity to keep the peg of IRON to $1.00.

Yes, you are right, of course, everything can happen here, while there is no data on this case, what it was specifically, I think after some time there will be an analysis, it also happens that initially smart contracts of projects involve fraud schemes, such as the recent case with Beetsfarm Finance.  https://twitter.com/RugDocIO/status/1405673057381978113


Title: Re: DeFi hacks [history]
Post by: zasad@ on June 21, 2021, 02:56:23 PM
Impossible finance-  $500 000

https://decrypt.co/74105/binance-smart-chain-defi-project-impossible-finance-hacked
Binance Smart Chain DeFi Project Impossible Finance Hacked
Yet another DeFi project on the Binance Smart Chain has been exploited. This time, attackers nabbed $500,000 from Impossible Finance in a flash loan attack.

https://twitter.com/Mudit__Gupta/status/1406878176509194246?
Impossible finance got exploited today for $500k.

Impossible Finance exploit root cause analysis
https://watchpug.medium.com/impossible-finance-exploit-root-cause-analysis-ba0ed7c151e4


Title: Re: DeFi hacks [history]
Post by: kenelmark on June 21, 2021, 06:46:19 PM
~

Why Defi hack is so easy to do compared to others. I think there is something wrong with the Defi platform security system. We need to be careful with new and untested platforms. Hackers are always trying to attack new platforms, and they often succeed. As happened in BSC recently.


Title: Re: DeFi hacks [history]
Post by: zasad@ on June 28, 2021, 09:12:46 PM
~

Why Defi hack is so easy to do compared to others. I think there is something wrong with the Defi platform security system. We need to be careful with new and untested platforms. Hackers are always trying to attack new platforms, and they often succeed. As happened in BSC recently.
https://decrypt.co/54128/hackers-stole-3-8-billion-in-cryptocurrency-hacks-in-2020
Hackers Stole $3.8 Billion in Cryptocurrency Hacks in 2020
Check out the statistics. Hackers hack anything they can hack: exchanges, wallets, projects. Defi projects are not on the 1st place in this list.
You need to be careful everywhere

___

Safe Dollar - $250 000

https://t.me/safedollarannouncements/42
SafeDollar has been under attack. We have paused activities on SafeDollar and investigating the matter.

https://twitter.com/RugDocIO/status/1409365551630090243?

SafeDollar may have been exploited for $250k in USDC and USDT‼️
Here is the exploiting contract :
https://polygonscan.com/address/0xc44e71debf89d414a262edadc44797eba093c6b0#tokentxns




ChainSwap-  - $8M

https://cryptobriefing.com/8-million-lost-major-chainswap-exploit/

$8 Million Lost in Major ChainSwap Exploit
Chris Williams(C)

"Several tokens have plummeted after ChainSwap suffered its second exploit in eight days. The losses amount to roughly $8 million.

Key Takeaways
ChainSwap suffered an exploit last night, resulting in $8 million worth of losses.
The attacker sold several tokens available on the protocol through decentralized exchanges, meaning they tanked in value.
ChainSwap has paused its Ethereum to Binance Smart Chain bridge and pledged to airdrop new ASAP tokens to holders."

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Daltonik on July 16, 2021, 07:27:13 AM
THORChain lost, according to preliminary estimates 4,000 ETH about $8 million as a result of a hacker attack. Originally reported loss of 13,000 ETH. https://www.runebase.org/news/thorchain-suffers-exploit

They promise to inform the affected users about the details and compensation in the near future. https://twitter.com/THORChain/status/1415813696857591813

UPD: Official update from the THORChain team in the telegram channel https://t.me/thorchain_org

MCCN Exploit Update

Loss:
Approx ~$4.9mm USD was taken in the exploit, far less than the intitial figures posted earlier. A granular breakdown is being developed by the community.

Method:
ETH Bifrost was tricked using a custom wrapper to read a deposit amount of 200 when it was actually zero. More details will be provided in the upcoming post mortem blog.

Discovery:
The issue was discovered by a community dev and anonymous nodes voluntarily used make halt command to stop their nodes. Once more than 1/3rd nodes had been halted, the network itself was halted. This was a decentralized action taken by node operators to protect the network.

Recovery:
1. Release the patch & restart the network > block pending outbounds > restore solvency.
2. Donate funds back to the ETH pool to restore lost funds to LPs
3. Release auto-solvency checker as a future preventative measure
4. Continue working with security firms to audit.

This is a disappointing moment for all, but LPs and Nodes should be unaffected after all is recovered (the funds will be restored). The network will be stronger and more resilient.

The THORChain community appreciate the inflow of support. More info to come in due course.


Title: Re: DeFi hacks [history]
Post by: zasad@ on July 16, 2021, 01:07:14 PM
Bondly Finance Suffers Latest DeFi Attack, Token Price Tanks
https://beincrypto.com/bondly-finance-suffers-latest-defi-attack/
“Unfortunately we have been compromised by an unknown party. We would like to take this time to advise you to STOP TRADING BONDLY. Rest assure we have already taken action and will be operating as usual ASAP,”

Around an hour or so before the warning, DeFi Prime posted details of the address involved in the reported exploit.


Title: Re: DeFi hacks [history]
Post by: aditasetia123 on July 16, 2021, 02:58:47 PM
Bondly Finance Suffers Latest DeFi Attack, Token Price Tanks
https://beincrypto.com/bondly-finance-suffers-latest-defi-attack/
“Unfortunately we have been compromised by an unknown party. We would like to take this time to advise you to STOP TRADING BONDLY. Rest assure we have already taken action and will be operating as usual ASAP,”

Around an hour or so before the warning, DeFi Prime posted details of the address involved in the reported exploit.
unfortunately i have some Bondly in my gate.io account , personally i am not hear this news because i am prepare and accept the risk if someday it will be scam or anything else happen. But if i  see the update from developers team  , they have good response to issue policy so investors not worry and even thingking they will run. hopefully new token released soon and everything back to normal again.


Title: Re: DeFi hacks [history]
Post by: ivankoh on July 16, 2021, 03:11:43 PM
THORChain lost, according to preliminary estimates 4,000 ETH about $8 million as a result of a hacker attack. Originally reported loss of 13,000 ETH. https://www.runebase.org/news/thorchain-suffers-exploit

They promise to inform the affected users about the details and compensation in the near future. https://twitter.com/THORChain/status/1415813696857591813

UPD: Official update from the THORChain team in the telegram channel https://t.me/thorchain_org

MCCN Exploit Update

Loss:
Approx ~$4.9mm USD was taken in the exploit, far less than the intitial figures posted earlier. A granular breakdown is being developed by the community.

Method:
ETH Bifrost was tricked using a custom wrapper to read a deposit amount of 200 when it was actually zero. More details will be provided in the upcoming post mortem blog.

Discovery:
The issue was discovered by a community dev and anonymous nodes voluntarily used make halt command to stop their nodes. Once more than 1/3rd nodes had been halted, the network itself was halted. This was a decentralized action taken by node operators to protect the network.

Recovery:
1. Release the patch & restart the network > block pending outbounds > restore solvency.
2. Donate funds back to the ETH pool to restore lost funds to LPs
3. Release auto-solvency checker as a future preventative measure
4. Continue working with security firms to audit.

This is a disappointing moment for all, but LPs and Nodes should be unaffected after all is recovered (the funds will be restored). The network will be stronger and more resilient.

The THORChain community appreciate the inflow of support. More info to come in due course.
Yes, exactly it happened and was officially announced from their team. Their big response.
This is unfortunate because not only does it cause loss to investors and the project's confidence, but it also covers this negativity on the entire market, which is already in a bad state.
Quote
Safe Dollar - $250 000

https://t.me/safedollarannouncements/42
SafeDollar has been under attack. We have paused activities on SafeDollar and investigating the matter.
I still haven't forgotten the crazy moment with Titan, even though they later announced their mistake but it did a lot of damage. I've given up on polygons for now.


Title: Re: DeFi hacks [history]
Post by: Daltonik on July 23, 2021, 08:58:42 AM
A new hacker attack, already the second in a week, on THORChain today led to a loss of $8 million, as the developers explained, the hacker said that he could have spent more( ETH,BTC,LYC, BNB and other BEP20s tokens), but eventually requested a reward of 10% of the amount of assets under potential threat in exchange for a critical error message.

https://i.ibb.co/7NWRfh9/2021-07-23-135015.jpg (https://twitter.com/THORChain/status/1418360746329608195)

https://i.ibb.co/CHWBht0/2021-07-23-135103.jpg (https://twitter.com/zillaQuest/status/1418368903500242945)


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 04, 2021, 10:08:45 AM
Popsicle Finance- 25M

https://decrypt.co/77620/defi-protocol-popsicle-finance-hacked-25-million
A bug in Popsicle Finance allowed hackers to drain one of the DeFi protocol’s key products for roughly $25 million.
"Popsicle Finance, a multi-chain yield-generating crypto project, has melted under the heat of a new exploit.

The $25 million heist was revealed by security researcher Mudit Gupta, who said “the hack was complex but the bug was simple.” In a Twitter thread, Gupta also explained how he reported a similar bug in another protocol, adding that the error “has been exploited in like a dozen other protocols already.”"

https://twitter.com/Mudit__Gupta/status/1422797923037814786


Title: Re: DeFi hacks [history]
Post by: Karartma1 on August 04, 2021, 10:29:21 AM
During the last few weeks I was wrapping my head around finding all the DeFi hacks happened but google wasn't really helping. I said to myself, jeez why don't I go to the forum  and search there.
Thanks a lot zasad@ this is what I was looking for!
I'll contribute to this thread in case I'll find some more news.  ;)


Title: Re: DeFi hacks [history]
Post by: Daltonik on August 04, 2021, 02:07:28 PM
Popsicle Finance- 25M

https://decrypt.co/77620/defi-protocol-popsicle-finance-hacked-25-million
A bug in Popsicle Finance allowed hackers to drain one of the DeFi protocol’s key products for roughly $25 million.
"Popsicle Finance, a multi-chain yield-generating crypto project, has melted under the heat of a new exploit.

The $25 million heist was revealed by security researcher Mudit Gupta, who said “the hack was complex but the bug was simple.” In a Twitter thread, Gupta also explained how he reported a similar bug in another protocol, adding that the error “has been exploited in like a dozen other protocols already.”"

https://twitter.com/Mudit__Gupta/status/1422797923037814786

The Popsicle Finance team offered the hacker who carried out the attack a reward, or rather a ransom for the return of the stolen funds in the amount of $1,000,000 in any currency at his request, I don't know how much this can help.

Quote
So, now what?
First of all, we would like to address the black hat hacker. Although this may be a long shot we are offering a completely clean $1,000,000 bounty paid in whatever currency he/she likes if funds are returned
.


Title: Re: DeFi hacks [history]
Post by: FinneysTrueVision on August 05, 2021, 02:32:43 AM
Popsicle Finance- 25M

https://decrypt.co/77620/defi-protocol-popsicle-finance-hacked-25-million
A bug in Popsicle Finance allowed hackers to drain one of the DeFi protocol’s key products for roughly $25 million.
"Popsicle Finance, a multi-chain yield-generating crypto project, has melted under the heat of a new exploit.

The $25 million heist was revealed by security researcher Mudit Gupta, who said “the hack was complex but the bug was simple.” In a Twitter thread, Gupta also explained how he reported a similar bug in another protocol, adding that the error “has been exploited in like a dozen other protocols already.”"

https://twitter.com/Mudit__Gupta/status/1422797923037814786

I hadn't heard of this project before but it seems that yield optimizers are a big target for attackers. PancakeBunny suffered one of the biggest losses earlier this year through a flash loan attack and then a few months later they were attacked again on the Polygon version of PancakeBunny. The benefit of using these optimizers is in the extra rewards they give you by going through their platform but the complexity of their contracts makes them more susceptible to exploits.


Title: Re: DeFi hacks [history]
Post by: RussianEnglishTranslation on August 05, 2021, 04:49:24 AM
So far there have been no hacks or exit scams on NEAR protocol, it's a trustworthy community.


Title: Re: DeFi hacks [history]
Post by: rosebrand on August 05, 2021, 09:23:54 PM
It's really unfortunate when projects which struggled hard to reach a certain point got hacked and loose all there  worked for, they are not the only ones affected, investors which believed in such project also loose as well because definitely when a project is hacked the next thing which take place is a rug pull which makes price of the coin dip so badly, well this is more reason projects should choose a blockchain which it's security can't be bridged, e.g polkadot, solana, and the most recommended is Near protocol.


Title: Re: DeFi hacks [history]
Post by: MSN02 on August 05, 2021, 10:29:55 PM
This kind of stuff is sad, people put their trust and hard earned money into projects and hackers take advantage by hacking these projects. Although it’s the fault of the person putting money into non secure projects, it’s still sad. It’s sad that we let these shitty projects have so much power and don’t just shut them down as a whole. Projects like BSC, NEAR, DOT are secure and you won’t get all of your money stolen if you invest in them. There are many others that are secure but there are also many that aren’t so as an investor you have to be careful where you put your money because sadly this is part of the game.


Title: Re: DeFi hacks [history]
Post by: Sollaes on August 08, 2021, 06:32:39 AM
Personally I was a victim of one defi hack. I lost about 100$. It was a farm on Polygon called Polyyeld. I invested in a pool USDC-YELD and at first everything was ok and I wish I had taken my money away when I was in profit. But then I lost and decided to hodl. And some time later they launched a layer 2, as a result a vulnerability appeared there. Then it was a hack and somebody made up a huge amount of native tokens.


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 10, 2021, 02:33:13 PM
https://decrypt.co/78163/polynetwork-suffers-record-breaking-600-3m-hack
PolyNetwork Suffers Record-Breaking $600.3 Million Hack
"PolyNetwork has suffered an exploit today. The attacker has made off with at least $600.3 million in stolen funds.

Multi-chain interoperability protocol Poly Network fell victim to an exploit today, resulting in the loss of roughly $600 million worth of various cryptocurrencies, the platform's developers revealed."
https://twitter.com/PolyNetwork2/status/1425073987164381196?


Title: Re: DeFi hacks [history]
Post by: Ucy on August 10, 2021, 03:21:53 PM
https://decrypt.co/78163/polynetwork-suffers-record-breaking-600-3m-hack
PolyNetwork Suffers Record-Breaking $600.3 Million Hack
"PolyNetwork has suffered an exploit today. The attacker has made off with at least $600.3 million in stolen funds.

Multi-chain interoperability protocol Poly Network fell victim to an exploit today, resulting in the loss of roughly $600 million worth of various cryptocurrencies, the platform's developers revealed."
https://twitter.com/PolyNetwork2/status/1425073987164381196?



I read it is one of the largest hack, if not the largest so far.
People should be careful how they invest in  projects. In Crypto space, only put your funds in well decentralized, well tested and secured projects. It's a space that depends on the security of decentralization in place of traditional governments... You should demand true decentralization or don't invest atall.

Invest but don't gamble. 
  Will continue to emphasize on the importance of sticking to crypto ideals when you are in Crypto space, so we don't have too many regrets


Title: Re: DeFi hacks [history]
Post by: Daltonik on August 11, 2021, 08:40:03 AM
Yes, keeping funds in the pools of Defi projects using them for passive income becomes quite dangerous, the hacker left a message that he could withdraw much more, but did not do it and saved the project https://etherscan.io/tx/0x552bc0322d78c5648c5efa21d2daa2d0f14901ad4b15531f1ab5bbe5674de34f , another message from him that he was ready to return the stolen. https://etherscan.io/tx/0x7b6009ea08c868d7c5c336bf1bc30c33b87a0eedd59dac8c26e6a8551b20b68a

https://i.ibb.co/HYydTSy/2021-08-11-134129.jpg (https://ibb.co/MpH6kvH)  https://i.ibb.co/9ZrjjMX/2021-08-11-133437.jpg (https://ibb.co/FHDttPv)


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 11, 2021, 07:23:58 PM
https://decrypt.co/78270/poly-network-hacker-repays-2-1-million-says-ready-return-fund

Poly Network Hacker Repays Millions, Says ‘Ready to Return the Fund’
"The unknown Poly Network hacker has begun returning funds stolen from yesterday’s record-breaking exploit.

The attacker responsible for yesterday’s $600 million hack of decentralized finance (DeFi) interoperability protocol Poly Network sent nearly $5 million worth of crypto back to the project."


Title: Re: DeFi hacks [history]
Post by: TomArayaSlaya on August 11, 2021, 08:14:52 PM
I just remembered some of these stupid hacks but kucoin was the one that hurts me the most As this mostly happens smart contracts have to be completely changed and team really super it the most and then sometimes or even all the time coins dumps like hell and investors take serious hit...I really hope there is a way for addressing refund or locking user account


Title: Re: DeFi hacks [history]
Post by: eaLiTy on August 11, 2021, 09:44:15 PM
Poly Network Hacker Repays Millions, Says ‘Ready to Return the Fund’
"The unknown Poly Network hacker has begun returning funds stolen from yesterday’s record-breaking exploit.

The attacker responsible for yesterday’s $600 million hack of decentralized finance (DeFi) interoperability protocol Poly Network sent nearly $5 million worth of crypto back to the project."
I heard about these comments about the hackers returning the coins, but is it really true that they will be refunding all the coins that they hacked. I really doubt that, if the hackers wanted to help the network they would have done that and asked for a bounty to save the network for good and now the reputation of Poly Network is down the drains and what is the point of all this other than showing off if they really return all the funds.


Title: Re: DeFi hacks [history]
Post by: Helpme_please on August 11, 2021, 09:59:33 PM
Poly Network Hacker Repays Millions, Says ‘Ready to Return the Fund’
"The unknown Poly Network hacker has begun returning funds stolen from yesterday’s record-breaking exploit.

The attacker responsible for yesterday’s $600 million hack of decentralized finance (DeFi) interoperability protocol Poly Network sent nearly $5 million worth of crypto back to the project."
I heard about these comments about the hackers returning the coins, but is it really true that they will be refunding all the coins that they hacked. I really doubt that, if the hackers wanted to help the network they would have done that and asked for a bounty to save the network for good and now the reputation of Poly Network is down the drains and what is the point of all this other than showing off if they really return all the funds.
hopefully they will did it , but with hundred millions someone will tempted with money. since the beginning hacker goals want to take money from network vulnerability that exposed and they have communication with developerst team. this is will make doubt they will send money back. actually with this skills , these hacker could earn  money from several project. they just need to exploit and report it so will get money legall.


Title: Re: DeFi hacks [history]
Post by: FinneysTrueVision on August 12, 2021, 12:01:30 AM
https://decrypt.co/78270/poly-network-hacker-repays-2-1-million-says-ready-return-fund

Poly Network Hacker Repays Millions, Says ‘Ready to Return the Fund’
"The unknown Poly Network hacker has begun returning funds stolen from yesterday’s record-breaking exploit.

The attacker responsible for yesterday’s $600 million hack of decentralized finance (DeFi) interoperability protocol Poly Network sent nearly $5 million worth of crypto back to the project."


It was mentioned that the hacker's IP address and other information had been uncovered and maybe this is what scared them into returning those funds. Every centralized exchange will be monitoring their addresses and it would be difficult for them to cash out into fiat.

The hack probably destroys any confidence in Poly Network but at least investors have a chance to recover what they lost.


Title: Re: DeFi hacks [history]
Post by: Kemarit on August 12, 2021, 12:23:49 AM
https://decrypt.co/78270/poly-network-hacker-repays-2-1-million-says-ready-return-fund

Poly Network Hacker Repays Millions, Says ‘Ready to Return the Fund’
"The unknown Poly Network hacker has begun returning funds stolen from yesterday’s record-breaking exploit.

The attacker responsible for yesterday’s $600 million hack of decentralized finance (DeFi) interoperability protocol Poly Network sent nearly $5 million worth of crypto back to the project."


It was mentioned that the hacker's IP address and other information had been uncovered and maybe this is what scared them into returning those funds. Every centralized exchange will be monitoring their addresses and it would be difficult for them to cash out into fiat.

The hack probably destroys any confidence in Poly Network but at least investors have a chance to recover what they lost.

And the $3 million was frozen by Tether already.

Yeah, I do agree that it destroys Poloy Network face value because of this attack, so it might be hard for their platform to bounce back.

Anyhow, let's hope that the hackers will send back more, if there IP address is exposed, then sooner or later they can be track and identified and arrested.


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 12, 2021, 02:09:47 PM
https://decrypt.co/78355/poly-network-hacker-returns-million

Poly Network Hacker Returns $342 Million
The largest crypto hack in history might have a happy ending after all as Poly Network sees more than half of the stolen funds returned.

https://decrypt.co/78364/poly-network-hacker-says-exploit-was-just-for-fun
Poly Network Hacker Says Exploit Was Just ‘For Fun’
The Poly Network hacker denies evil intent and says they wanted to teach the project a lesson.



New hack, new post!

DAO Maker Statement — Thursday, 12th of August
https://medium.com/daomaker/dao-maker-statement-thursday-12th-of-august-2c3bb0d1bb69

"The cybercriminal, after tentatively testing this exploit and managing to steal 10,000 USDC, then proceeded to quietly make 15 more transactions.
In this manner, the hacker was able to siphon approximately $7M, until our security team was able to trace, contain and stop the drain of funds. A total of 5251 users were affected, losing $1250 USD on average per user."

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: aioc on August 12, 2021, 02:19:33 PM
https://decrypt.co/78355/poly-network-hacker-returns-million

Poly Network Hacker Returns $342 Million
The largest crypto hack in history might have a happy ending after all as Poly Network sees more than half of the stolen funds returned.

https://decrypt.co/78364/poly-network-hacker-says-exploit-was-just-for-fun
Poly Network Hacker Says Exploit Was Just ‘For Fun’
The Poly Network hacker denies evil intent and says they wanted to teach the project a lesson.

I guess they are already rich or they are not really criminals because they cannot pull out this kind of deed, it saves the market from dipping, this kind of news is what makes the market dip and what makes the market grow, I hope criminals will learn from this one, that the whole community will go after them and make them pay if they continue these activities.


Title: Re: DeFi hacks [history]
Post by: otundebis on August 12, 2021, 02:37:28 PM
The issue of defi hack is becoming one too many,  people are likely going to desist from participating in defi investment.  But another angle to all these issues is the lessons that must be learned through all these events.  I expect the defi space to be stronger and better as we experiment this laudable idea of decentralized finance!


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 14, 2021, 10:32:26 AM
Maze Protocol -  4 million US dollars

"The BSC project Maze Protocol was attacked by hackers, and more than 4 million US dollars were suspected to be stolen. Certik also audited and issued a report."

https://twitter.com/WuBlockchain/status/1425970290660544515

"Maze Protocol:The hacker exploited a leak that allowed borrowing assets based on users’ collateral and sending funds directly to the attacker’s address.
The asset pools have been frozen to prevent more attacks. The remaining funds are safe. The website is temporarily shut down."
https://twitter.com/WuBlockchain/status/1425970973900083204




DAO Maker Statement — Thursday, 12th of August
https://medium.com/daomaker/dao-maker-statement-thursday-12th-of-august-2c3bb0d1bb69

https://medium.com/daomaker/dao-maker-compensation-plan-b7a76a312c30
DAO Maker Compensation Plan

"
Phase 1: The SHO Must Go On
500 USDC will be airdropped to all affected users’ wallets without delay.

Phase 2: Remaining 65% Refund & Liquid IOU Tokens
Given that the net exploited amount was $7M, the amount due (after the $2.5M deposit to users’ escrow) equals $4.5M. This $4.5M will be provided to users in exactly one year’s time in the form of DAO tokens at the future market price.
"




https://decrypt.co/78802/ethereum-dex-avoids-350m-defi-hack-thanks-white-hat-heroics
Ethereum DEX Avoids $350M DeFi Hack Thanks to White Hat Heroics: Report

"In brief
SushiSwap’s MISO token sale platform had an exploit that could have been used to steal $350 million worth of Ethereum.
A crypto researcher from VC firm Paradigm says he discovered the exploit yesterday and worked with SushiSwap to neutralize the threat."



https://decrypt.co/79307/polynetwork-make-affected-users-whole-resume-functionality

PolyNetwork to Make Affected Users Whole, Resume Functionality
"Following the record-breaking hack, the crypto project platform is now returning lost funds to affected users."

https://twitter.com/PolyNetwork2/status/1429738587046563841

"Today’s announcement from PolyNetwork appears to close the chapter on the historic heist. Least until the next hack."

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Daltonik on August 30, 2021, 11:29:58 AM
The hacker managed to withdraw almost $25 million during the latest flash credit exploit of the Cream Finance protocol using the error of re-entering the AMP token contract. https://cointelegraph.com/news/cream-finance-defi-platform-loses-19m-in-a-flash-loan-hack

https://i.ibb.co/k14cWRB/2021-08-30-162712.jpg (https://twitter.com/CreamdotFinance/status/1432249771750686721)


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 30, 2021, 05:33:40 PM
Cream Finance-19M
Cream Finance DeFi platform loses $19M in a flash loan hack
https://cointelegraph.com/news/cream-finance-defi-platform-loses-19m-in-a-flash-loan-hack

https://twitter.com/CreamdotFinance/status/1432249771750686721?
"PeckShield specified that the hacker exploited the Amp token by reborrowing assets during its transfer before updating the first to borrow in 17 separate transactions. Providing an example transaction, the security firm stated, “The hacker makes a flashloan of 500 ETH and deposit the funds as collateral. Then the hacker borrows 19M $AMP and makes use of the reentrancy bug to re-borrow 355 ETH inside $AMP token transfer. Then the hacker self-liquidates the borrow.”"


xToken- 4,5M
"On 29 August at 04:43 UTC, a vulnerability in our xSNX contract was exploited. We estimate the loss to holders at $4.5 million. We are incredibly disappointed in ourselves and deeply sorry to our community."
https://medium.com/xtoken/xsnx-post-mortem-666d35071f38



https://twitter.com/CreamdotFinance/status/1432909465104240641
"At approximately 12pm on 31st August (UTC +8), C.R.E.A.M. Finance was exploited for 462,079,976 in AMP tokens and 2,804.96 ETH tokens.

Stolen tokens will be replaced. We will commit to allocating 20% of all protocol fees toward repayment until this debt is fully paid."

C.R.E.A.M. Finance Post Mortem: AMP Exploit
https://medium.com/cream-finance/c-r-e-a-m-finance-post-mortem-amp-exploit-6ceb20a630c5

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Bitstar_coin on September 01, 2021, 02:23:38 PM
https://decrypt.co/78355/poly-network-hacker-returns-million

Poly Network Hacker Returns $342 Million
The largest crypto hack in history might have a happy ending after all as Poly Network sees more than half of the stolen funds returned.

https://decrypt.co/78364/poly-network-hacker-says-exploit-was-just-for-fun
Poly Network Hacker Says Exploit Was Just ‘For Fun’
The Poly Network hacker denies evil intent and says they wanted to teach the project a lesson.

How convenient to hack platforms for fun, they must not have noticed this is a question of public funds safely and the integrity and trustworthiness of the project in question, it is better they look for other ways of having fun than to mess around with people's investment, I don't see what's funny here especially when the reverse is the case.


Title: Re: DeFi hacks [history]
Post by: Daltonik on September 01, 2021, 03:59:49 PM
A phishing attack on the issue of tokens of the NFT-project Aurory Project on the Solana blockchain allowed the attacker to withdraw from the wallets of the victims of cryptocurrency and NFT, according to various estimates, from $500,000 to $1.1 million. https://cryptonews.net/en/1635083/

https://i.ibb.co/8gFCpbn/2021-09-01-205121.jpg (https://twitter.com/chasedevens/status/1432742408991690753)


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 04, 2021, 12:06:07 PM
DAO Maker -4M
https://twitter.com/TheDaoMaker/status/1433994186446020609

This is the second hack in a month.

https://etherscan.io/address/0x2708cace7b42302af26f1ab896111d87faeff92f#tokentxns


Title: Re: DeFi hacks [history]
Post by: concept2 on September 04, 2021, 02:07:23 PM
DAO Maker -4M
https://twitter.com/TheDaoMaker/status/1433994186446020609

This is the second hack in a month.

https://etherscan.io/address/0x2708cace7b42302af26f1ab896111d87faeff92f#tokentxns
What is wrong with the contract? there must be a solution to avoid such lost. Moreover, it has happened for many times before. I guess they just want to collect investors money without having any responsibility to protect and reserve the funds. Such a disaster. 


Title: Re: DeFi hacks [history]
Post by: 777Jolami on September 04, 2021, 04:29:33 PM
So far, the most unfortunate incidents seem to be Rune and Poly, although after Poly, Tether confirmed the refund but defi seems to have been taught a lesson in security to improve  than.  And I suspect cross-chain bridges are a research point for hackers.


Title: Re: DeFi hacks [history]
Post by: Daltonik on September 08, 2021, 04:43:35 PM
As reported on twitter PeckShield Inc. the hacker behind the attack on Cream Finance returned the funds stolen as a result of the recent attack in the amount of 5152.6 ETH.

https://i.ibb.co/WWWZy26/2021-09-08-213715.jpg (https://twitter.com/peckshield/status/1435495419652583425)

https://i.ibb.co/mbQ6Fyc/2021-09-08-213831.jpg (https://etherscan.io/tx/0xab7b3eb3dd09dc30fe6edb44e50a9542df05b55c6d51a1deebcbfc179c90e19e)


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 11, 2021, 09:04:10 AM
AFKSystems   12M $
https://twitter.com/RugDocIO/status/1436440660517793798?s=20
"AFKSystems rug update: stolen funds were eventually sent to"
https://etherscan.io/address/0x56eb4a5f64fa21e13548b95109f42fa08a644628

https://twitter.com/ObeliskOrg/status/1436493898180931588?s=20
:1/18 AFK System Hard Rug Postmortem thread :"



Zabu Finance $3.2M

https://slowmist.medium.com/?p=44243919ea29
"Brief analysis of Zabu Finance being hacked
According to the intelligence of the SlowMist Zone, on September 12, 2021, the Zabu Finance project on Avalanche suffered flashloan attack."

https://twitter.com/zabufinance/status/1436844923483869184

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Daltonik on September 17, 2021, 09:10:59 AM
The hacker withdrew 864.8 ETH something more than $3 million from the NFT auction)on the MISO IDO platform of the SushiSwap protocol by introducing malicious code into the external interface of MISO and spoofing the auction address. Chief technical officer SushiSwap Joseph Delong reports on Twitter. Hacker's transaction ID: https://etherscan.io/address/0x3ddd8b6d092df917473680d6c41f80f708c45395#internaltx

https://i.ibb.co/6vdtY09/2021-09-17-140837.jpg (https://twitter.com/josephdelong/status/1438712356352274433)


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 17, 2021, 02:26:31 PM
The hacker withdrew 864.8 ETH something more than $3 million from the NFT auction)on the MISO IDO platform of the SushiSwap protocol by introducing malicious code into the external interface of MISO and spoofing the auction address. Chief technical officer SushiSwap Joseph Delong reports on Twitter. Hacker's transaction ID: https://etherscan.io/address/0x3ddd8b6d092df917473680d6c41f80f708c45395#internaltx

https://i.ibb.co/6vdtY09/2021-09-17-140837.jpg (https://twitter.com/josephdelong/status/1438712356352274433)

https://twitter.com/josephdelong/status/1438839165873967107
"100 ETH has been returned to the Sushi multisig. Hoping the attacker sends the rest
https://etherscan.io/tx/0x4bfd68aaaaad03d0dd2d5b9e862e3bc4c7ee90cb85507eb85262e932c8748521"

https://twitter.com/AppletonDave/status/1438854505332764672
https://etherscan.io/tx/0x904e5bcb5ef9cfb19f19afd04849f3b12d17dc347d3e525072fcd139cc08cbdb

https://twitter.com/josephdelong/status/1438861783599652868
"All funds returned"

https://twitter.com/skymoon_gt/status/1438847456377192450
"I think the biggest hackers are the ones taking positions of short in exchanges right at the moment of the incident or right before. Once all funds are returned, check these individuals/groups as well. Probably they make more money that way!"


https://decrypt.co/81120/sushiswaps-token-launchpad-hacked-over-3m-ethereum
SushiSwap’s Token Launchpad Hacked for Over $3M in Ethereum



Title: Re: DeFi hacks [history]
Post by: Raytheon on September 20, 2021, 09:11:33 AM
pNetwork - a cross-chain DeFi platform was attacked on Binance Smart Chain, losing 277 bitcoin (over USD 12 million).

https://i.imgur.com/Loice06.png (https://twitter.com/pNetworkDeFi/status/1439690593211490324)

Right after the attack, pNetwork offered a clean bounty of USD 1.5 million if the hacker returned the funds.

https://i.imgur.com/VjS45eW.png (https://twitter.com/pNetworkDeFi/status/1439690598529765384)


Title: Re: DeFi hacks [history]
Post by: isabellel2 on September 20, 2021, 09:35:24 AM
Uniswap when BZRX launched their IDO but when reading the article the author explained how the guy earned 500k usd but not by hacking but combining defi trading bot. It is very important to give real information people. People think that decentralized finance doesn't have any risks! But it's quite the opposite. It is a new industry, new code, no one has tested for long so be careful. Thank you very much for sharing the important information needed.


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 20, 2021, 12:37:50 PM
pNetwork - a cross-chain DeFi platform was attacked on Binance Smart Chain, losing 277 bitcoin (over USD 12 million).

https://i.imgur.com/Loice06.png (https://twitter.com/pNetworkDeFi/status/1439690593211490324)

Right after the attack, pNetwork offered a clean bounty of USD 1.5 million if the hacker returned the funds.

https://i.imgur.com/VjS45eW.png (https://twitter.com/pNetworkDeFi/status/1439690598529765384)


pNetwork Protocol -$12M
https://decrypt.co/81301/defi-bridging-protocol-pnetwork-suffers-12-million-hack
DeFi Bridging Protocol pNetwork Suffers $12 Million Hack
An unknown hacker has exploited a bug in pNetwork’s codebase to steal 277 Bitcoin from the protocol's bridge on Binance Smart Chain.


Title: Re: DeFi hacks [history]
Post by: Alf_m.h on September 20, 2021, 01:08:24 PM
pNetwork - a cross-chain DeFi platform was attacked on Binance Smart Chain, losing 277 bitcoin (over USD 12 million).

https://i.imgur.com/Loice06.png (https://twitter.com/pNetworkDeFi/status/1439690593211490324)

Right after the attack, pNetwork offered a clean bounty of USD 1.5 million if the hacker returned the funds.

https://i.imgur.com/VjS45eW.png (https://twitter.com/pNetworkDeFi/status/1439690598529765384)


pNetwork Protocol -$12M
https://decrypt.co/81301/defi-bridging-protocol-pnetwork-suffers-12-million-hack
DeFi Bridging Protocol pNetwork Suffers $12 Million Hack
An unknown hacker has exploited a bug in pNetwork’s codebase to steal 277 Bitcoin from the protocol's bridge on Binance Smart Chain.
after this incident, there will be all kinds of security instruments that are carried out, there will even be a mission to report bugs, we will give gifts(reward). as far as made same OP from 2020-2021, it is not impossible before that year will also happen.


Title: Re: DeFi hacks [history]
Post by: Balmain on September 20, 2021, 01:13:44 PM
There is only one defect among them that hurt me, the defi was pancakebunny. I was getting my Yield revenues with bunny, after the hack, the price went down and it hurt me. Defi, I knew that there were too many hacks, there are projects in this list that I have not heard before, a good list has been prepared.


Title: Re: DeFi hacks [history]
Post by: Daltonik on September 21, 2021, 06:39:00 PM
The Vee.Finance landing platform was attacked by an unknown hacker, as a result, the attacker withdrew 8804.7 ETH and 213.93 BTC worth approximately $35 million. https://veefi.medium.com/vee-finance-accident-announcement-5e75ff197da6

https://i.ibb.co/BZ5DvZR/2021-09-21-233737.jpg (https://veefi.medium.com/vee-finance-accident-announcement-5e75ff197da6)

All services were suspended. We are investigating the cause, please follow our official accounts for the latest updates reported on the project's twitter.

https://i.ibb.co/ZX6mNJ4/2021-09-21-233322.jpg (https://twitter.com/certik_io/status/1405899677422268416)


Title: Re: DeFi hacks [history]
Post by: awilliams on September 21, 2021, 06:46:25 PM
Didn’t makerdao get hacked at some point?


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 22, 2021, 09:40:06 AM
The Vee.Finance landing platform was attacked by an unknown hacker, as a result, the attacker withdrew 8804.7 ETH and 213.93 BTC worth approximately $35 million. https://veefi.medium.com/vee-finance-accident-announcement-5e75ff197da6

https://i.ibb.co/BZ5DvZR/2021-09-21-233737.jpg (https://veefi.medium.com/vee-finance-accident-announcement-5e75ff197da6)

All services were suspended. We are investigating the cause, please follow our official accounts for the latest updates reported on the project's twitter.

https://i.ibb.co/ZX6mNJ4/2021-09-21-233322.jpg (https://twitter.com/certik_io/status/1405899677422268416)
Combining link information in 1 post
VEE FINANCE 8804.7 ETH and 213.93 BTC ( $35M)
21 Sep 2021

https://www.rekt.news/veefinance-rekt/
Exploiter ETH Address: 0xeeee458c3a5eaafcfd68681d405fb55ef80595ba

Exploiter AVAX Address: 0xeeeE458C3a5eaAfcFd68681D405FB55Ef80595BA
"The exploiter’s Ethereum address was funded via TornadoCash in three lots of 10 ETH: ONE, TWO, THREE.

The funds were then bridged to Avalanche, where the attacker swapped 26.999006274904347875 WETH.e for 1,369.708 AVAX via Pangolin."


Title: Re: DeFi hacks [history]
Post by: Myleschetty on September 22, 2021, 01:04:04 PM
It seems that most altcoin project devs are only after making money through projects rather than the safety of investors and the project security cause just in a short span the number of DeFi that was hacked is huge.
If this continues DeFi may lose the trust of crypto market finance enthusiasts.



Title: Re: DeFi hacks [history]
Post by: zasad@ on September 30, 2021, 12:10:46 PM
Compound bug leaves $80 million in COMP at risk of being misrewarded
https://www.theblockcrypto.com/linked/119086/compound-bug-comp-risk-misreward
"But a new bug contained in the upgraded Comptroller Contract has mistakenly allowed some users to claim as much as about 168,000 COMP tokens already, worth around $50 million.

Robert Leshner, founder of Compound Labs, said in follow-up tweets that the Comptroller contract address "contains a limited quantity of COMP" while the majority of the reward sits in a different Reservoir contract address.

Hence "the impact is bounded, at worst, 280,000 COMP tokens," Leshner said. That is worth about $80 million as of press time.

The Comptroller contract address now has 112,000 COMP tokens left."


Title: Re: DeFi hacks [history]
Post by: Daltonik on October 01, 2021, 02:26:34 PM
Cream Finance reports that the project managed to recover 5152.6 ETH stolen on August 31, they managed to identify the hacker with the help of the community, the hacker received 10% of the stolen funds.

https://i.ibb.co/8bZmzjX/2021-10-01-183649.jpg (https://twitter.com/CreamdotFinance/status/1443909164443439107)

https://i.ibb.co/x21RBH9/2021-10-01-192341.jpg (https://twitter.com/CreamdotFinance/status/1443909167224213507)

https://i.ibb.co/MfJQ42W/2021-10-01-183820.jpg (https://twitter.com/CreamdotFinance/status/1443909170189668361)




In addition to hacking in Defi, there are also scams, for example, the developer of the NFT project Evolved Apes, hiding under the nickname Evil Ape, deleted the site (https://www.evolvedapes.com/) and account (https://twitter.com/evolvedapesnft), hiding from 797 ETH $2.7 million) of users who were supposed to be used to pay for the work of artists. :(  https://www.vice.com/en/article/y3dyem/investors-spent-millions-on-evolved-apes-nfts-then-they-got-scammed


[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Jaered on October 07, 2021, 11:21:20 AM
Something tells me this list is gonna be more populated before the year runs out. The truth is, the way DeFi is run, it is always easy draining funds from it and nobody can stop those malicious actors. The only way it can be curbed is by regulations, and regulations alone. And crypto as a whole is long overdue for that


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 15, 2021, 02:57:42 PM
Indexed Finance -$16 M
https://ndxfi.medium.com/indexed-attack-post-mortem-b006094f0bdc

"Today Indexed suffered its first hack since its deployment in December, and it was a pretty devastating one. About $16m worth of assets were stolen from the indices DEFI5 and CC10 by 0xba5ed1488be60ba2facc6b66c6d6f0befba22ebe."



Indexed Finance continuation of a story
https://decrypt.co/83681/defi-protocol-indexed-finance-hacked-for-16-million-team-finds-hacker
The project’s members identified the hacker on Friday because he didn't cover his tracks off-chain well enough, Day said. They then gave him an ultimatum: return the funds by midnight on Saturday or else they would contact law enforcement.

https://twitter.com/ndxfi/status/1449373158583279622
"The 10% offer has expired. The attacker has until EOD to return 100% of the stolen funds or his information will be published and law enforcement notified."

https://twitter.com/ndxfi/status/1449594187213680643
"The ultimatum has not been met.
In the minutes before the deadline elapsed,
@ZetaZeroes
made changes to his accounts that have made us realise at the last minute that the attacker is significantly younger than we thought."

https://twitter.com/ZetaZeroes


This address is reported to be involved in a Indexed Finance exploit.
https://etherscan.io/address/0xba5ed1488be60ba2facc6b66c6d6f0befba22ebe

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Daltonik on October 18, 2021, 08:24:07 AM
Indexed Finance continuation of a story
https://decrypt.co/83681/defi-protocol-indexed-finance-hacked-for-16-million-team-finds-hacker
The project’s members identified the hacker on Friday because he didn't cover his tracks off-chain well enough, Day said. They then gave him an ultimatum: return the funds by midnight on Saturday or else they would contact law enforcement.

https://twitter.com/ndxfi/status/1449373158583279622
"The 10% offer has expired. The attacker has until EOD to return 100% of the stolen funds or his information will be published and law enforcement notified."

https://twitter.com/ndxfi/status/1449594187213680643
"The ultimatum has not been met.
In the minutes before the deadline elapsed,
@ZetaZeroes
made changes to his accounts that have made us realise at the last minute that the attacker is significantly younger than we thought."

https://twitter.com/ZetaZeroes


This address is reported to be involved in a Indexed Finance exploit.
https://etherscan.io/address/0xba5ed1488be60ba2facc6b66c6d6f0befba22ebe

It's good that sometimes hackers are too arrogant to stay in the shadows, although the team says that he is quite young, that's why he made these statements, but the bad thing is that project teams do not pay due attention to security in order to avoid situations that harm both the image of the team and damage the community and people simply lose their funds as a result.



PancakeHunny on BSC on October 20 was attacked using a flash loan by a hacker, about $1.9 million was stolen, this is already happening for the second time, the first case of using a flash loan was in the month of June. In a preliminary report, the team assured users that their funds are safe.  https://medium.com/pancakehunny/pancakehunny-incident-report-b5b74557b0ad

https://i.ibb.co/rZ1m9zh/2021-10-21-211219.jpg (https://twitter.com/peckshield/status/1450755242946019334)

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 21, 2021, 07:02:01 PM
PancakeHunny on BSC on October 20 was attacked using a flash loan by a hacker, about $1.9 million was stolen, this is already happening for the second time, the first case of using a flash loan was in the month of June. In a preliminary report, the team assured users that their funds are safe.  https://medium.com/pancakehunny/pancakehunny-incident-report-b5b74557b0ad

https://i.ibb.co/rZ1m9zh/2021-10-21-211219.jpg (https://twitter.com/peckshield/status/1450755242946019334)
PancakeHunny- $1.9M

"What happened?
On 20 October 2021, at 0920 UTC. A smart contract was created to exploit the Hunny TUSD vault. The Contract was subsequently executed 26 times. This is the sequence of events.
Obtained a 53.25 BTC Flashloan from Cream Finance.
Used 53.25 BTC to get a 2,717,107 TUSD Loan from Venus.
Manipulated the price of BNB/TUSD Pool on PancakeSwap.
Used 50 different Wallet Addresses to Deposit 38,250 TUSD into HUNNY TUSD Vault.
Redeemed 2842.16TUSD and Minted 12,020.40 Hunny.
Sold Minted Hunny for 7.78 WBNB.
Steps Repeated for 50 wallets 26 times."
https://medium.com/pancakehunny/pancakehunny-incident-report-b5b74557b0ad
https://twitter.com/peckshield/status/1450801612901937152?



Cream Finance - $130M
https://decrypt.co/84590/cream-finance-suffers-third-hack-losing-over-130-million
Cream Finance Suffers Third Hack, Loses Over $130 Million
Cream Finance, a DeFi lending protocol, has been hacked for over $130 million—marking the third hack suffered by the protocol.

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Anonymous100 on October 27, 2021, 07:40:15 PM
~

There have been a lot of hacks on Defi coins in the last few months, but I see where the weakness lies in the swap platform. They try to hack in various ways, including resembling core tokens. Some even tried to create fake swap platforms. When we give permission to access the wallet, of course they already have control over our wallet. The most dangerous are the platforms with the import private key system.


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 29, 2021, 06:07:38 PM
https://twitter.com/nomorebear/status/1453413216172740609
"Quick explanation of
@CreamdotFinance(C)
 >$100M exploit:

1. Flash mint ~500m DAI to mint curve y Pool to mint ~500m yUSD
2. Use account A to deposit yUSD to CREAM
3. Flash loan ~500k (worth $2B) ETH from AAVE
4. Use account B to deposit ETH to borrow all yUSD and send to A
5. Use account A to deposit yUSD to CREAM
6. Repeat 4, then 5, then 4 again. Now account A has ~1.5B cyYUSD and ~500m yUSD
7. Redeem yUSD
8. Inflate price of yUSD by factor of 2. Now, account B is deeply underwater (bad debt) but account A has double collateral value***
9. Use account A to borrow ETH to return the flash loan.
10. Use the rest collateral power in A to borrow and drain CREAM.
11. Use redeemed yUSD (plus some small amount of DAI from money from 10) to repay DAI flash mint"



Information disclosure and analysis of major hacks in the DeFe ecosystem
https://github.com/yearn/yearn-security/tree/master/disclosures

Very good analysis of the latest CREAM Finance hack.
Incident Disclosure 2021-10-27
https://github.com/yearn/yearn-security/blob/master/disclosures/2021-10-27.md



Crypto Wallets MetaMask, Phantom Targeted in $500K Phishing Attack: Report
Check Point Research has discovered a “massive” phishing campaign that has seen funds stolen from MetaMask and Phantom users.
https://decrypt.co/85253/crypto-wallets-metamask-phantom-targeted-500k-phishing-attack-report
"Check Point Research has discovered a crypto phishing scam that has stolen at least half a million dollars.
Metamask and Pancake websites have both been mimicked in the scam."



bZx -$55M
Ethereum DeFi Project bZx Hacked Again—For a Reported $55 Million
The project says Ethereum contracts and treasury funds are unaffected.
https://decrypt.co/85360/ethereum-defi-project-bzx-hacked-again-reported-55-million
"bZx is a DeFi lending protocol.
It's investigating an exploit of a private key linked to its Binance Smart Chain and Polygon deployments."



https://twitter.com/nomorebear/status/1453413216172740609
"Quick explanation of
@CreamdotFinance(C)
 >$100M exploit:

1. Flash mint ~500m DAI to mint curve y Pool to mint ~500m yUSD
2. Use account A to deposit yUSD to CREAM
3. Flash loan ~500k (worth $2B) ETH from AAVE
4. Use account B to deposit ETH to borrow all yUSD and send to A
5. Use account A to deposit yUSD to CREAM
6. Repeat 4, then 5, then 4 again. Now account A has ~1.5B cyYUSD and ~500m yUSD
7. Redeem yUSD
8. Inflate price of yUSD by factor of 2. Now, account B is deeply underwater (bad debt) but account A has double collateral value***
9. Use account A to borrow ETH to return the flash loan.
10. Use the rest collateral power in A to borrow and drain CREAM.
11. Use redeemed yUSD (plus some small amount of DAI from money from 10) to repay DAI flash mint"
Moving Forward: Post Exploit Next Steps for C.R.E.A.M. Finance
https://creamdotfinance.medium.com/moving-forward-post-exploit-next-steps-for-c-r-e-a-m-finance-1ad05e2066d5
"The Path Forward
We will distribute 1,453,415 CREAM tokens to impacted users. We are utilizing remaining CREAM tokens within the treasury, and removing the project team’s remaining CREAM token allocation. There will be no further CREAM allocations to the team."

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Daltonik on November 19, 2021, 04:03:16 PM
Elliptic analytical company.released a study according to which users have suffered losses in excess of $12 billion since 2020 due to fraud and theft on DeFi platforms, of which $10.5 billion falls in 2021.
 $721 million of the $12 billion was subsequently reimbursed. The most frequent targets of cybercriminals were the Ethereum and BSC blockchains.
The main reasons for attacks on decentralized projects in Elliptic are called errors in the code and architectural flaws.
https://www.elliptic.co/resources/defi-risk-regulation-and-the-rise-of-decrime

https://i.ibb.co/68mSfLk/2021-11-19-205424.jpg (https://imgbb.com/)


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 25, 2021, 08:51:29 AM
DeFi exploits total $680 million so far in 2021
https://www.theblockcrypto.com/post/123030/defi-exploits-total-680-million-so-far-in-2021
"Quick Take
There have been 70 DeFi attacks this year across four blockchain platforms.
Around $1.4 billion was initially stolen but $760 million has been returned."


Title: Re: DeFi hacks [history]
Post by: slaman29 on November 25, 2021, 11:03:08 AM
DeFi exploits total $680 million so far in 2021
https://www.theblockcrypto.com/post/123030/defi-exploits-total-680-million-so-far-in-2021
"Quick Take
There have been 70 DeFi attacks this year across four blockchain platforms.
Around $1.4 billion was initially stolen but $760 million has been returned."

Those that are known anyway. I bet you on BSC and Tron there are loads of small tiny rug pulls that don't make the news or are even talked about but I see a new IDO every few hours, and most of them gonna end up scams. People also who got scammed mostly won't say it (the small losers whine but the big ones keep quiet) and then all this doesn't go reported.


Title: Re: DeFi hacks [history]
Post by: Daltonik on December 01, 2021, 07:39:48 AM
The Polygon based MonoX DeFi platform was hacked, the hacker managed to withdraw crypto assets worth $31 million, the following assets were withdrawn:
 -5.7M MATIC ($10.5M)
- 3.9k WETH ($18.2M)
- 36.1 WBTC ($2M)
- 1.2k LINK ($31k)
- 3.1k GHST ($9.1k)
- 5.1M DUCK ($257k)
- 4.1k MIM ($4.1k)
- 274 IMX ($2k)

https://i.ibb.co/8Dxyrch/2021-12-01-122228.jpg (https://twitter.com/FrankResearcher/status/1465679352448917504)

The developers of MonoX confirmed the fact of hacking and apologized to investors, but the developers also said that the incident is being investigated and measures are being taken to refund funds.
As it turned out during the investigation, the hacking mechanism looked like this: the attacker managed to raise the price of the MONO token to the skies with the help of a swap contract, and then purchase all the other assets in the pool for it.

https://i.ibb.co/kXGdFrs/2021-12-01-123754.jpg (https://twitter.com/MonoXFinance/status/1465694996762226700)



Title: Re: DeFi hacks [history]
Post by: zasad@ on December 01, 2021, 09:35:00 AM
MonoXFinance $31 M

The Polygon based MonoX DeFi platform was hacked, the hacker managed to withdraw crypto assets worth $31 million, the following assets were withdrawn:
 -5.7M MATIC ($10.5M)
- 3.9k WETH ($18.2M)
- 36.1 WBTC ($2M)
- 1.2k LINK ($31k)
- 3.1k GHST ($9.1k)
- 5.1M DUCK ($257k)
- 4.1k MIM ($4.1k)
- 274 IMX ($2k)

https://i.ibb.co/8Dxyrch/2021-12-01-122228.jpg (https://twitter.com/FrankResearcher/status/1465679352448917504)

The developers of MonoX confirmed the fact of hacking and apologized to investors, but the developers also said that the incident is being investigated and measures are being taken to refund funds.
As it turned out during the investigation, the hacking mechanism looked like this: the attacker managed to raise the price of the MONO token to the skies with the help of a swap contract, and then purchase all the other assets in the pool for it.

https://i.ibb.co/kXGdFrs/2021-12-01-123754.jpg (https://twitter.com/MonoXFinance/status/1465694996762226700)



for a link to 1 post.
MonoX Finance Drained of $31M in Latest DeFi Hack
https://cryptobriefing.com/monox-finance-drained-of-31m-in-latest-defi-hack/

"Key Takeaways
A hacker has exploited MonoX Finance's smart contracts, draining $31 million worth of assets.
The MonoX team are attempting to contact the hacker to ask for the funds to be returned.
Despite receiving two independent audits, the vulnerabilities in MonoX's smart contracts were not found."


Title: Re: DeFi hacks [history]
Post by: goldkingcoiner on December 01, 2021, 10:29:56 AM
Amazing list! It worries me that DEFI can be so easily hacked and that it happens so very very often... The thing that bothers me most is the disgusting bounty haggling from Fullcrum. They saved their 2.5 Million dollars and don't even get paid for their efforts. What kind of move is that? Fullcrum? More like Fullscum. I would keep away from doing business with them.

That being said, thanks for this list. Im sure it will be very helpful for future Defi.


Title: Re: DeFi hacks [history]
Post by: BitcoinAccepted on December 01, 2021, 10:53:42 AM
That's really a lot of hacks and very big money involved but we shouldn't forget the small ones and if we sum that up I think they are much more expensive than those on the list. What I mean is something like the rug pull I think the one that happened in Binance before and other rug pulls of different developers that consist of million of $.


Title: Re: DeFi hacks [history]
Post by: Daltonik on December 02, 2021, 08:13:35 AM
BadgerDAO reported unauthorized withdrawal of user funds, engineers BadgerDAO are investigating this issue, the protocol's smart contracts have been temporarily suspended.

https://i.ibb.co/PhQ7vj7/2021-12-02-131002.jpg (https://twitter.com/BadgerDAO/status/1466263899498377218)

One of the victims lost 896 BTC https://etherscan.io/tx/0x951babdddbfbbba81bbbb7991a959d9815e80cc5d9418d10e692f41541029869 , in total about $ 100 million was withdrawn from the project.

https://i.ibb.co/cbj1dCY/2021-12-02-131152.jpg (https://twitter.com/peckshield/status/1466295466241388545)

But whether it was an attack or the funds were simply burned as a result of using a bug in contracts is not yet clear.
https://twitter.com/DefiWhiskey/status/1466271476416454656

https://i.ibb.co/nMbP9rg/2021-12-02-131625.jpg (https://imgbb.com/)


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 02, 2021, 02:37:23 PM
BadgerDAO $100 M

BadgerDAO reported unauthorized withdrawal of user funds, engineers BadgerDAO are investigating this issue, the protocol's smart contracts have been temporarily suspended.

https://i.ibb.co/PhQ7vj7/2021-12-02-131002.jpg (https://twitter.com/BadgerDAO/status/1466263899498377218)

One of the victims lost 896 BTC https://etherscan.io/tx/0x951babdddbfbbba81bbbb7991a959d9815e80cc5d9418d10e692f41541029869 , in total about $ 100 million was withdrawn from the project.

https://i.ibb.co/cbj1dCY/2021-12-02-131152.jpg (https://twitter.com/peckshield/status/1466295466241388545)

But whether it was an attack or the funds were simply burned as a result of using a bug in contracts is not yet clear.
https://twitter.com/DefiWhiskey/status/1466271476416454656

https://i.ibb.co/nMbP9rg/2021-12-02-131625.jpg (https://imgbb.com/)

for a link to 1 post.
https://cryptobriefing.com/120m-lost-badgerdao-defi-hack/
$120M Lost in BadgerDAO DeFi Hack
"Key Takeaways
BadgerDAO has suffered a major frontend attack.
The hacker reportedly compromised Badger's user interface by inserting a malicious script that prompted users to give the hacker permission to spend their funds.
Smart contract auditing firm Peckshield has estimated the value of the stolen funds to around $120 million."


Title: Re: DeFi hacks [history]
Post by: Daltonik on December 11, 2021, 01:21:19 PM
BadgerDAO reveals the details of the hacker attack that allowed the theft of $120 million, everything boils down, in their opinion, to the unauthorized use of API keys of the Cloudflare Workers service.
The full technical analysis from the BadgerDAO team is here: https://badger.com/technical-post-mortem

https://i.ibb.co/zhP1jkh/2021-12-11-181555.jpg (https://twitter.com/BadgerDAO/status/1469351128357904391)

Personally, one bad experience was enough for me using API keys to access an account on the yobit garbage exchange four years ago, after which I lost 0.5 BTC, but it was my funds, and here such a number of users and such vulnerability suffered, IMHO here is completely the fault of the developers. :)



The next victim of hackers in the DeFi segment was the Grim Finance platform, losses are estimated at more than $30 million, developers have suspended deposits and recommend users to withdraw their funds urgently.

https://twitter.com/financegrim/status/1472357770846519312
https://i.ibb.co/92VD9CN/2021-12-21-1627445.jpg (https://imgbb.com/)

With a name like the platform, investors needed to be more circumspect

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 22, 2021, 11:50:59 AM
for a link to 1 post.
The next victim of hackers in the DeFi segment was the Grim Finance platform, losses are estimated at more than $30 million, developers have suspended deposits and recommend users to withdraw their funds urgently.

https://twitter.com/financegrim/status/1472357770846519312
https://i.ibb.co/92VD9CN/2021-12-21-1627445.jpg (https://imgbb.com/)

With a name like the platform, investors needed to be more circumspect

Grim Finance Hacked for $30 Million in Fantom Tokens
Grim Finance is the latest DeFi protocol to be hit by an exploit.
https://decrypt.co/88727/grim-finance-hacked-30-million-fantom-tokens
https://cryptobriefing.com/fantom-defi-project-grim-finance-suffers-30m-hack/


Vulcan Forged-$140M
https://twitter.com/VulcanForged/status/1470365117774770180
https://www.theblockcrypto.com/post/127270/96-private-keys-stolen-from-vulcan-forged-in-140-million-theft


Gelato-$26M
https://twitter.com/gelatonetwork/status/1470289886406004736


8IGHT FINANCE- $1.75M
https://rekt.news/8ight-finance-rekt/


Title: Re: DeFi hacks [history]
Post by: Daltonik on December 23, 2021, 04:38:57 PM
There are also reports that the Visor protocol (Visorfinance) was attacked using a re-entry exploit and lost over 8.8 million VISR tokens, which as of this event was estimated at about $8.8 million, after that the price fell from $1 to $0.02, after which the project team announced the migration of user funds to a new contract to restore them
https://twitter.com/peckshield/status/1473315405498576901
https://visorfinance.medium.com/?p=7920e1dee55a



Title: Re: DeFi hacks [history]
Post by: zasad@ on December 24, 2021, 01:01:02 PM
There are also reports that the Visor protocol (Visorfinance) was attacked using a re-entry exploit and lost over 8.8 million VISR tokens, which as of this event was estimated at about $8.8 million, after that the price fell from $1 to $0.02, after which the project team announced the migration of user funds to a new contract to restore them
https://twitter.com/peckshield/status/1473315405498576901
https://visorfinance.medium.com/?p=7920e1dee55a


Visor Finance -$8.8M
Visor Finance Suffers DeFi Hack: Lost 8.8 million VISR tokens
https://blog.coincodecap.com/visor-finance-suffers-defi-hack
VISOR Finance Suffers DeFi Hack $8.2M Lost | Bitcoin News
https://medium.com/coinmonks/visor-finance-suffers-defi-hack-8-2m-lost-bitcoin-news-4a80e99199f0


Title: Re: DeFi hacks [history]
Post by: hd49728 on December 24, 2021, 03:31:19 PM
$8.8M is not big but not small.

I wonder that will the Visor Finance team will do compensation for their users. If they seriously compensate for their users, they will have to sacrifice their income in many months and in the same time, they will have to pay cost for staffs, developments, operations, maintenance and other things to keep their DeFi platform up and run.

It is not a good thing and it's bad to see it happened around Christmas which should be a peaceful period for all.


Title: Re: DeFi hacks [history]
Post by: Daltonik on December 30, 2021, 10:57:17 AM
Polygon developers revealed a case of theft committed by a hacker on December 4 of 801,601 MATIC tokens worth more than $2 million, which was made possible thanks to an exploit in the smart contract Polygon, which was reported on December 3 by @leonspacewalker (https://twitter.com/leonspacewalker), which later received with another user, whose name is not called, a reward of $3.46 million for reporting a bug.
source: https://blog.polygon.technology/all-you-need-to-know-about-the-recent-network-upgrade/?utm_source=Twitter-Main&utm_medium=Tweet&utm_campaign=Tier-1-Announcement


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 30, 2021, 04:23:48 PM
Some results of 2021

The Biggest DeFi Hacks of 2021 until May 2021
https://www.cybavo.com/blog/defi-hacks-2021/

DeFi Has Accounted for Over 75% of Crypto Hacks in 2021
https://finance.yahoo.com/news/defi-accounted-over-75-crypto-140000154.html

Biggest Defi Hack in 2021
Poly Network Suffers Record-Breaking $600.3 Million Hack
https://decrypt.co/78163/polynetwork-suffers-record-breaking-600-3m-hack




#RugPull PeckShield has detected that Metaswap Gas (MGAS) soft-rugged, the stolen funds (1,100 BNB) are transfered to TornadoCash
https://twitter.com/peckshield/status/1475331156459790336?

#RugPull PeckShield has detected that  METADAO rugged, the stolen funds (800 Ether) are transferred to @TornadoCash
(#Ethereum). DO NOT STAKE in this contract and if you've approved it, REVOKE
https://twitter.com/PeckShieldAlert/status/1475434691939520523?

Tinyman -  the amount of hacking is unknown
Official Announcement About the Incidents of 01.01.2022
https://tinymanorg.medium.com/official-announcement-about-the-incidents-of-01-01-2022-56abb19d8b19
"When the attack began, total liquidity in Tinyman was around 43 million USD, only to be reduced to around 20 million even hours after the attack. Following our advice, projects and users have begun removing their liquidities, which brought the total number down to 5 million USD. It is crucial to realize that the difference between the 43 million USD and the current number is not a lost amount, a huge portion of this amount was reclaimed by the users and is totally safe in their wallets."





[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Daltonik on January 11, 2022, 08:02:46 AM
Every day, a new hack now, on January 10, hackers managed to withdraw 165.2 million LMT tokens worth approximately $18.2 million from the hot wallets of the sports NFT platform Lympo (daughter of Animoca Brand), according to the developers , the following wallets were compromised:

https://etherscan.io/address/0x5D32b87A43a2bd1f7df209d2F475b165d2c09E24
https://etherscan.io/address/0x526232F70b97938E19394e57BC5eE1d5d929074e
https://etherscan.io/address/0xB0a60eBA24f6CF18CFDED0672c5C7a7529DcC342
https://etherscan.io/address/0x934dd62782BFe4a8E3f096E014266e5F5adc1b2a
https://etherscan.io/address/0x877eECC3Ae4Bb28f048c16CD65A44cDE025345a1
https://etherscan.io/address/0x36d97147cF8E1B75254748Cf0A102316fCc61697
https://etherscan.io/address/0xA432C0081307733e801Ea7877e725F4E0adfbBfF
https://etherscan.io/address/0x4b936321b0E3E2d919412502B6aDA09E9b7d484b
https://etherscan.io/address/0x75912Da145cA00092AF317F8c3A84073A5665256
https://etherscan.io/address/0x4C801611cdaB559861d4dB24155927F903DEa02A

source: https://twitter.com/Lympo_io/status/1480582931794083842
            https://medium.com/lympo-official/lympo-statement-to-the-community-914d6b453b1f


Title: Re: DeFi hacks [history]
Post by: IQnawaz123 on January 11, 2022, 08:13:07 AM
Because of developer incompetence, many DeFi projects get hacked.


Title: Re: DeFi hacks [history]
Post by: zasad@ on January 12, 2022, 10:55:15 AM
Every day, a new hack now, on January 10, hackers managed to withdraw 165.2 million LMT tokens worth approximately $18.2 million from the hot wallets of the sports NFT platform Lympo (daughter of Animoca Brand), according to the developers , the following wallets were compromised:

https://etherscan.io/address/0x5D32b87A43a2bd1f7df209d2F475b165d2c09E24
https://etherscan.io/address/0x526232F70b97938E19394e57BC5eE1d5d929074e
https://etherscan.io/address/0xB0a60eBA24f6CF18CFDED0672c5C7a7529DcC342
https://etherscan.io/address/0x934dd62782BFe4a8E3f096E014266e5F5adc1b2a
https://etherscan.io/address/0x877eECC3Ae4Bb28f048c16CD65A44cDE025345a1
https://etherscan.io/address/0x36d97147cF8E1B75254748Cf0A102316fCc61697
https://etherscan.io/address/0xA432C0081307733e801Ea7877e725F4E0adfbBfF
https://etherscan.io/address/0x4b936321b0E3E2d919412502B6aDA09E9b7d484b
https://etherscan.io/address/0x75912Da145cA00092AF317F8c3A84073A5665256
https://etherscan.io/address/0x4C801611cdaB559861d4dB24155927F903DEa02A

source: https://twitter.com/Lympo_io/status/1480582931794083842
            https://medium.com/lympo-official/lympo-statement-to-the-community-914d6b453b1f

Animoca Brands’ Lympo NFT platform hacked for $18.7 million
https://cointelegraph.com/news/animoca-brands-lympo-nft-platform-hacked-for-18-7-million
"The sports NFT minting platform suffered a hot wallet security breach across several project wallets, losing $18 million worth of LMT.
Sports nonfungible token (NFT) minting platform and Animoca Brands subsidiary Lympo suffered a hot wallet security breach and lost 165.2 million LMT tokens worth $18.7 million at the time of the hack."


Title: Re: DeFi hacks [history]
Post by: zasad@ on January 28, 2022, 01:00:54 PM
Qubit Finance,  X-Bridge $80M
Binance Smart Chain, Ethereum Crypto Bridge Hacked for $80 Million
https://decrypt.co/91447/binance-smart-chain-ethereum-crypto-bridge-hacked-80-million
"An exploit in decentralized finance (DeFi) protocol Qubit Finance enabled one hacker to walk away with $80 million in stolen crypto yesterday.
The specific smart contract flaw that enabled the attack was located in X-Bridge, a cross-chain bridge that facilitates easy token swaps between Ethereum and Binance Smart Chain. "


Title: Re: DeFi hacks [history]
Post by: Daltonik on February 03, 2022, 06:28:44 AM
It looks like cross-blockchain bridge Wormhole was hacked as a result of the exploit and, according to preliminary estimates, lost more than $326 million. dev's Wormhole itself confirmed a total loss of 120,000 ETH and announced that funds would be added to the bridge to stop the wrapped ETH on Solana. This is one of the biggest hacks in the history of DeFi. :(
https://www.coindesk.com/tech/2022/02/02/blockchain-bridge-wormhole-suffers-possible-exploit-worth-over-250m/

https://i.ibb.co/Qnt2fGr/2022-02-03-112638.jpg (https://twitter.com/wormholecrypto/status/1489001949881978883)


UPD: The venture capital company Jump Crypto, which owns Certus One, which is the developer of the Wormhole cross-chain bridge, announced that it has invested 120,000 ETH in the Solana-Ethereum bridge.  All funds have been restored, Wormhole has been restored. The ETH contract is filled and all wETH are secured 1:1.

https://i.ibb.co/WWK81ND/2022-02-04-144457.jpg (https://twitter.com/JumpCryptoHQ/status/1489301013408497666)



Title: Re: DeFi hacks [history]
Post by: Daltonik on February 04, 2022, 09:36:26 AM
DeFi the KLAYswap project announced a hacking incident, as a result of which the project lost about 2.2 billion KRW, or about $1.83 million, the hacker managed to create a third-party js link on the KLAYswap external interface, as a result of which the user was sent to a fake KLAYswap page.

Details are here: https://medium.com/klayswap/klayswap-incident-report-feb-03-2022-f20ba2d8e4dd

https://i.ibb.co/8M2T44W/2022-02-03-134208.jpg (https://twitter.com/KLAYswap/status/1489259689552461824)


Title: Re: DeFi hacks [history]
Post by: Daltonik on February 08, 2022, 11:41:37 AM
The DeFi Meter project lost about $4.3 million as a result of a hacker attack, 1391 ETH and 2.74 BTC were withdrawn from the project, as the developers said, the hacker used the vulnerability of the automatic unpacking of gas tokens in the protocol, such as ETH and BNB.

https://i.ibb.co/HpVfc70/2022-02-08-163624.jpg (https://twitter.com/peckshield/status/1490121762847092736)

https://i.ibb.co/4SG14vB/2022-02-08-163736.jpg (https://twitter.com/Meter_IO/status/1490045486606139392)


Title: Re: DeFi hacks [history]
Post by: Daltonik on February 08, 2022, 02:07:50 PM
Here is another message about the attack, it seems that the DeFi QiDao Protocol project lost tokens for a total of $13 million, thanks to the exploit, hackers managed to withdraw tokens QI, WETH, USDC, SDT, MOCA, STACK, sdam3CRV and MATIC. Although the project team itself recognizes the fact of the exploit, but claims that users' funds are safe, but analysts see a different picture. :(

https://i.ibb.co/0rgG66y/2022-02-08-190151.jpg (https://twitter.com/QiDaoProtocol/status/1490944375165128706)

https://i.ibb.co/hLtF6hN/2022-02-08-190123.jpg (https://twitter.com/SlowMist_Team/status/1490989174362894336)


Title: Re: DeFi hacks [history]
Post by: Daltonik on February 11, 2022, 07:35:40 AM
The DeFi team of the Dego protocol reports the hacking of its address providing liquidity on UniSwap and PancakeSwap and the liquidity for Dego pairs has been withdrawn, the team reports that the incident is being investigated and the amount of losses is being determined.

https://i.ibb.co/p1JSQ3w/2022-02-11-122830.jpg (https://twitter.com/dego_finance/status/1491633269330173956)

https://i.ibb.co/ZH96YkL/2022-02-11-123035.jpg (https://twitter.com/dego_finance/status/1491691395404365828)


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 17, 2022, 07:36:08 AM
Over 4,000 ‘Criminal Whales’ Hold $25 Billion Worth of Crypto: Report
Criminal crypto balances surged from $3 billion to $11 billion, mostly due to the crypto market's rise in 2021 but also an increase in hacks.
https://decrypt.co/92995/over-4000-criminal-whales-hold-25-billion-worth-crypto-report
"New Chainalysis data has found that 4,068 “criminal whales” hold $25 billion worth of cryptocurrency. The firm defines criminal crypto whales as any private wallet that holds $1 million or more of cryptocurrency and has received 10% or more of those funds through illicit addresses. (In other words, not all of that $25 billion is illicit.)"


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 02, 2022, 03:03:33 PM
Crypto-Related Crime Hit Record $14B in 2021—But Shrank by Volume: Chainalysis
Crypto scammers bagged a whopping $14 billion last year. Still, crime is becoming a much smaller part of the industry.
Andrew Asmakov(C)
https://decrypt.co/89854/crypto-related-crime-hit-record-high-14b-2021-chainalysis
"As Chainalysis reported last month, revenues from crypto scams in 2021 were up 81% on the previous year (corrected to 82% in today’s report) to $7.8 billion.

Of this total, so-called rug pulls—a malicious practice where developers build a seemingly legitimate crypto project only to get away with investors' money—accounted for 37% of all crypto scam revenue, or more than $2.8 billion.

“Many investors could likely have avoided losing funds to rug pulls if they’d stuck to DeFi projects that have undergone a code audit—or if [decentralized exchanges] required code audits before listing tokens,” Chainalysis said.

Cryptocurrency theft grew even more, according to the report, with about $3.2 billion worth of crypto stolen in 2021—a staggering 516% increase compared to 2020."


Crypto Crime Trends for 2022: Illicit Transaction Activity Reaches All-Time High in Value, All-Time Low in Share of All Cryptocurrency Activity
https://blog.chainalysis.com/reports/2022-crypto-crime-report-introduction/


Crypto Scam Revenue Up 81% in 2021, Hits $7.7 Billion: Chainalysis
DeFi rug pulls accounted for 37% of all crypto scam revenue in 2021, up from 1% in 2020, according to the blockchain data platform.
https://decrypt.co/88453/crypto-scam-revenue-hit-7-7-billion-2021-chainalysis



Title: Re: DeFi hacks [history]
Post by: kaka manteng on March 02, 2022, 06:46:45 PM
DeFi financial system has been compared to the wild west, but that's how a new story begins.
2020
18 February 2020
Arbs Exploit DeFi to Make $900k in Seconds; bZx hack.
https://thedefiant.substack.com/p/arbs-exploit-defi-to-make-900k-in

21 February 2020
Fulcrum had a $2.5M vulnerability over a month ago and still hasn’t told anyone
https://medium.com/@1inch.exchange/yes-we-hacked-bzx-fulcrum-but-one-month-ago-3f7e5c437ee3

19 April 2020
Multicoin Capital-backed DeFi protocol dForce loses ~$25M total locked value in an exploit
https://www.theblockcrypto.com/amp/linked/62346/multicoin-capital-backed-defi-protocol-dforce-loses-25m-total-locked-value-in-an-exploit

21 April 2020
Dforce return $ 25 million back !!!
https://twitter.com/lawmaster/status/1252483198115774464

19 May 2020
BlockFi Experiences Data Breach – Crypto Lending Hack
https://defirate.com/blockfi-hack/

18 Jun 2020
A cryptocurrency bug put $545,000 of DeFi funds at risk
https://decrypt.co/32720/a-cryptocurrency-bug-put-545000-of-defi-funds-at-risk

20 Jun 2020
Balancer hacked ~ $ 500,000
https://medium.com/balancer-protocol/incident-with-non-standard-erc20-deflationary-tokens-95a0f6d46dea

14 Jul 2020
How BZRX Uniswap Listing Made One Trader $550K In 30 Mins
https://cryptopotato.com/how-bzrx-uniswap-listing-made-one-trader-550k-in-30-mins/

5 August 2020
Blatant “bug” led to $370,000 DeFi hack, say experts. Opyn hack.
https://decrypt.co/37671/blatant-bug-led-to-370000-defi-hack-say-expert

7 September 2020
$250k Soft Yearn (SYFI)
https://cointelegraph.com/news/jackpot-user-turns-200-into-250k-thanks-to-a-buggy-defi-protocol

13 September 2020
$8M  bZx protocol
https://www.theblockcrypto.com/post/77656/defi-protocol-bzx-attacked-lost-8-million-faulty-code

14 September 2020
$8M returned  bZx protocol
https://twitter.com/bZxHQ/status/1305496675474006017

29 September 2020
$15 Million  Hackers Drain $15 Million From ‘Unreleased’ Yearn Finance Project
https://bitcointalk.org/index.php?topic=5267124.msg55282297#msg55282297

29 September 2020
$10 Million  $10 Million Ethereum Vulnerability Patched by Whitehat Hacker
https://fullycrypto.com/10-million-ethereum-vulnerability-patched-by-whitehat-hacker

11 October 2020
wLEO Was Hacked on Ethereum. Damage $ 42,000
https://bitcointalk.org/index.php?topic=5267124.msg55365482#msg55365482

26 October 2020
Harvest Finance- 23 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55455370#msg55455370

12 November 2020
Akropolis- 2 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55591391#msg55591391

14 November 2020
Value DeFi 6 million US dollars
https://twitter.com/value_defi/status/1327660571592773632

17 November 2020
Origin Defi Protocol 7 million US dollars
https://news.bitcoin.com/origin-defi-protocol-suffers-massive-flash-loan-attack-ousd-stablecoin-value-plunges-85/

22 November 2020
DeFi Protocol Pickle Finance 20 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55653413#msg55653413

14 December 2020
Nexus Mutual  8 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55829590#msg55829590

18 December 2020
Warp Finance 7,7 million US dollars
https://www.theblockcrypto.com/linked/88415/defi-warp-finance-attacked-lost-7-7-million-stablecoins

28 December 2020
DeFi protocol Cover 5 million US dollars
https://www.theblockcrypto.com/post/89368/defi-protocol-cover-exploited-attackers-minted-at-least-40-quintillion-tokens

___
https://decrypt.co/54128/hackers-stole-3-8-billion-in-cryptocurrency-hacks-in-2020
Hackers Stole $3.8 Billion in Cryptocurrency Hacks in 2020

Information disclosure and analysis of major hacks in the DeFe ecosystem
https://github.com/yearn/yearn-security/tree/master/disclosures
__

2021

February 4, 2021
Yearn.finance 9 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56271047#msg56271047

February 14, 2021
Cream Finance 37,5 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56458888#msg56458888

February 28, 2021
Furucombo 14 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56458888#msg56458888

March 4, 2021
Meerkat Finance (Binance Smart Chain) 32 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56490389#msg56490389

March 5, 2021
PAID Network (PAID) 3 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56498767#msg56498767

March 8, 2021
DODO DEX 2 million US dollars, $1.89 million has been recovered
https://bitcointalk.org/index.php?topic=5267124.msg56530098#msg56530098

March 15, 2021
Roll 3000 ETH
https://cryptoslate.com/hackers-steal-3000-eth-from-roll-causing-massive-price-dumps-of-nearly-100/

March 17, 2021
Iron Finance $170,000  
https://bitcointalk.org/index.php?topic=5267124.msg56605708#msg56605708

March 20, 2021
TurtleDex  9000 BNB =2.4M $  
https://bitcointalk.org/index.php?topic=5267124.msg56617046#msg56617046

April 4, 2021
Force DAO - $367 000
https://bitcointalk.org/index.php?topic=5267124.msg56864596#msg56864596

April 19, 2021
EasyFi DeFi protocol - 6M $
https://bitcointalk.org/index.php?topic=5267124.msg56835129#msg56835129

May 2, 2021
Spartan Protocol -30M
https://bitcointalk.org/index.php?topic=5267124.msg56919497#msg56919497

May 9, 2021
Rari Capital  -10M
https://bitcointalk.org/index.php?topic=5267124.msg57018020#msg57018020

May 12, 2021
(DeFi) protocol xToken  -24.5M
https://bitcointalk.org/index.php?topic=5267124.msg56997287#msg56997287

May 20, 2021
Pancake Bunny  -200M
https://bitcointalk.org/index.php?topic=5267124.msg57050581#msg57050581

May 20, 2021
Venus Incident Report
https://bitcointalk.org/index.php?topic=5267124.msg57054439#msg57054439

May 27, 2021
Wild Credit $ 637K.  All funds were returned to the protocol.
https://bitcointalk.org/index.php?topic=5267124.msg57106288#msg57106288

May 28, 2021
DeFi project BurgerSwap - $ 7.2M
https://bitcointalk.org/index.php?topic=5267124.msg57106299#msg57106299

May 30, 2021
DeFi project Belt Finance - $ 6.2M
https://bitcointalk.org/index.php?topic=5267124.msg57120256#msg57120256

Jyne 21, 2021
DeFi project Impossible finance - $ 0.5M
https://bitcointalk.org/index.php?topic=5267124.msg57284357#msg57284357

Jyne 28, 2021
Safe Dollar - $ 0.25M
https://bitcointalk.org/index.php?topic=5267124.msg57340075#msg57340075

July 1, 2021
WhaleFarm- $ 2M
https://bitcointalk.org/index.php?topic=5267124.msg57367513#msg57367513

July 11, 2021
ChainSwap - $8M
https://bitcointalk.org/index.php?topic=5267124.msg57439162#msg57439162

July 15, 2021
Bondly Finance - Token Price Tanks
https://bitcointalk.org/index.php?topic=5267124.msg57473981#msg57473981

July 16, 2021
THORChain -2500 ETH
https://bitcointalk.org/index.php?topic=5267124.msg57471971#msg57471971

August 4, 2021
Popsicle Finance -25M
https://bitcointalk.org/index.php?topic=5267124.msg57613393#msg57613393

August 10, 2021
PolyNetwork -600M
https://bitcointalk.org/index.php?topic=5267124.msg57662150#msg57662150

August 12, 2021
Poly Network Hacker Returns $342 Million
https://bitcointalk.org/index.php?topic=5267124.msg57677686#msg57677686

August 13, 2021
Maze Protocol -4M
https://bitcointalk.org/index.php?topic=5267124.msg57691964#msg57691964

August 14, 2021
DAO Maker -7M
https://bitcointalk.org/index.php?topic=5267124.msg57677718#msg57677718

August 19, 2021
Ethereum DEX Avoids $350M DeFi Hack
https://bitcointalk.org/index.php?topic=5267124.msg57731551#msg57731551

August 29, 2021
xToken- 4,5M
https://bitcointalk.org/index.php?topic=5267124.msg57820934#msg57820934

August 30, 2021
Cream Finance-19M
https://bitcointalk.org/index.php?topic=5267124.msg57820934#msg57820934

August 31, 2021
Aurory Project-0,5M
https://bitcointalk.org/index.php?topic=5267124.msg57835544#msg57835544

September 4, 2021
DAO Maker-4M
https://bitcointalk.org/index.php?topic=5267124.msg57857298#msg57857298

September 10, 2021
AFKSystems -12M
https://bitcointalk.org/index.php?topic=5267124.msg57910886#msg57910886

September 12, 2021
Zabu Finance -3,2M
https://bitcointalk.org/index.php?topic=5267124.msg57923560#msg57923560     !

September 17, 2021
MISO IDO platform (Hack and return of coins) -865 ETH (3M)
https://bitcointalk.org/index.php?topic=5267124.msg57957934#msg57957934  

September 20, 2021
pNetwork Protocol -$12M
https://bitcointalk.org/index.php?topic=5267124.msg57980467#msg57980467  

September 21, 2021
Vee.Finance  -$35M
https://bitcointalk.org/index.php?topic=5267124.msg57995378#msg57995378

September 30, 2021
Compound bug  -$80M
https://bitcointalk.org/index.php?topic=5267124.msg58062585#msg58062585

October 15, 2021
Indexed Finance -$16M
https://bitcointalk.org/index.php?topic=5267124.msg58188360#msg58188360

October 20, 2021
PancakeHunny -$1,9M
https://bitcointalk.org/index.php?topic=5267124.msg58236768#msg58236768

October 27, 2021
Cream Finance -$130M
https://bitcointalk.org/index.php?topic=5267124.msg58283286#msg58283286

November 5, 2021
bZx -$55M
https://bitcointalk.org/index.php?topic=5267124.msg58355796#msg58355796

November 30, 2021
MonoXFinance $31 M
https://bitcointalk.org/index.php?topic=5267124.msg58586607#msg58586607

December 1, 2021
BadgerDAO $100 M
https://bitcointalk.org/index.php?topic=5267124.msg58599650#msg58599650

December 4, 2021
Polygon  801,601 MATIC tokens worth more than $2 million
https://bitcointalk.org/index.php?topic=5267124.msg58857717#msg58857717

December 8, 2021
8IGHT FINANCE- $1.75M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 11, 2021
Gelato-$26M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 13, 2021
Vulcan Forged-$140M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 21, 2021
Grim Finance  $30M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 22, 2021
Visor Finance -$8.8M
https://bitcointalk.org/index.php?topic=5267124.msg58808603#msg58808603

December 27, 2021
Metaswap Gas (MGAS) 1,100 BNB
https://bitcointalk.org/index.php?topic=5267124.msg58909773#msg58909773

December 27, 2021
METADAO 800 Ether
https://bitcointalk.org/index.php?topic=5267124.msg58909773#msg58909773

____
Reports  2021 Hack
https://bitcointalk.org/index.php?topic=5267124.msg59405892#msg59405892


2022

January 1,2022
Tinyman -  the amount of hacking is unknown
https://bitcointalk.org/index.php?topic=5267124.msg58909773#msg58909773

January 11,2022
Lympo NFT platform-  $18.7 million
https://bitcointalk.org/index.php?topic=5267124.msg58968153#msg58968153

January 28,2022
Qubit Finance,  X-Bridge  $80M
https://bitcointalk.org/index.php?topic=5267124.msg59097768#msg59097768

February 2,2022
Wormhole   $326 M
https://bitcointalk.org/index.php?topic=5267124.msg59144112#msg59144112

February 4,2022
KLAYswap   $1,83 M
https://bitcointalk.org/index.php?topic=5267124.msg59153910#msg59153910

February 8,2022
DeFi Meter   $4,3 M
https://bitcointalk.org/index.php?topic=5267124.msg59189702#msg59189702

February 8,2022
DeFi QiDao Protocol  $13 M
https://bitcointalk.org/index.php?topic=5267124.msg59191163#msg59191163

February 11,2022
Dego  damage is assessed
https://bitcointalk.org/index.php?topic=5267124.msg59218259#msg59218259

to be continued..

Russian
https://bitcointalk.org/index.php?topic=5227888.0

This really makes me decide if I'm going to invest to DeFi projects by just looking at the list you will really know how DeFi projects can scam participants.
Well this list really helps me a lot not to look more into DeFi projects.


Title: Re: DeFi hacks [history]
Post by: JayTrain on March 02, 2022, 07:25:58 PM
The list of hacks is quite impressive, although everyone says that decentralized exchanges are safe, and statistics say the opposite, there are hackers who withdraw huge amounts, so there is no 100% confidence anywhere in the crypto world.


Title: Re: DeFi hacks [history]
Post by: Daltonik on March 03, 2022, 09:19:05 AM
The hacker exploited the Treasure DAO vulnerability and managed to steal more than 100 NFT, worth 426,511 MAGIC about $1.44 million, the bug allowed buying NFT for zero MAGIC tokens used on the Treasure platform.

https://i.ibb.co/JsSjxLz/2022-03-03-141606.jpg (https://twitter.com/peckshield/status/1499250224455245825)


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 03, 2022, 10:40:51 AM
The list of hacks is quite impressive, although everyone says that decentralized exchanges are safe, and statistics say the opposite, there are hackers who withdraw huge amounts, so there is no 100% confidence anywhere in the crypto world.
I use decentralized exchanges 1 inch and uniswap and they have proven to be safe. And I don’t often see news about decentralized exchange hacks. So far, most of the news tells us about hacks of decentralized projects, but 2022 has just begun, and the results will need to be analyzed in December of this year.


Title: Re: DeFi hacks [history]
Post by: Daltonik on March 10, 2022, 05:20:02 PM
The Fantasy Finance project was subjected to an exploit, as a result of which $ 2.6 million was withdrawn, hackers used a protocol error that allowed XFTM to be minted using a small number of FSM Fantasm tokens, instead of using both of these tokens. The hackers started with 50 FTM, gradually using more and more amounts to exchange so they managed to take over a total of more than 2,800,000 XFTM.

The stolen funds were later exchanged for more than 1,007 ETH of about $2.6 million at current prices using the Tornado Cash privacy protocol.
The developers of Fantasm stated that not the entire pool was emptied and there are still 1,820,012 FTM in it, and also that they are developing a compensation plan for affected users.

Fantasm Finance Team report on the incident: https://medium.com/@fantasmfinance/fantasm-finance-post-mortem-exploit-09-march-2022-daf48ead016f

https://i.ibb.co/8zzvS2j/2022-03-10-221208.jpg (https://twitter.com/nipun_pit/status/1501816047711580160)

https://i.ibb.co/zG7XcJS/2022-03-10-221222.jpg (https://twitter.com/fantasm_finance/status/1501569232881995785)




It is reported that the DeFi protocol Deus Finance DAO was subjected to an exploit due to which. the hacker was able to withdraw about $3 million, including 200,000 DAI and 1101.8 ETH.

https://i.ibb.co/D98dqN7/2022-03-15-225612.jpg (https://twitter.com/peckshield/status/1503632734299701250)

The developers reported that they are aware of exploits that relate to a loan contract worth $10 million.
And as they themselves stated that the contract was closed, both $DEUS and $DEI are not affected and they are working on a brief description of the hack that will be published after a full assessment of what happened.

https://i.ibb.co/mbMZV9Q/2022-03-15-225833.jpg (https://twitter.com/DeusDao/status/1503652836978143242)



It seems that after a slight lull, a band of hacking of Defi projects began, it is reported that hackers managed to withdraw $11 million from the DeFi protocols Agave and Hundred Finance, for the attack, the attackers used an exploit on the Gnosis Chain network that allowed them to use re-entry and instant loans.

Sorce: https://www.theblockcrypto.com/post/137932/defi-protocols-agave-and-hundred-finance-exploited-on-gnosis-chain-for-11-million

[moderator's note: consecutive posts merged]


Title: Re: DeFi hacks [history]
Post by: Daltonik on March 18, 2022, 11:29:02 AM
The Rare Bears project team reported that on March 16, a hacker using a phishing attack on users of the Rare Bears Discord channel was able to seize 179 NFT Bears tokens, thus emptying the project on 286 ETH.

https://i.ibb.co/9WW9X4S/2022-03-18-162259.jpg (https://twitter.com/BearsRare/status/1504293859467350019)

https://i.ibb.co/58Sjv8Q/2022-03-18-162422.jpg (https://twitter.com/PeckShieldAlert/status/1504340385673654273)


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 21, 2022, 11:54:55 AM
Li Finance protocol loses $600,000 in latest DeFi exploit
https://cointelegraph.com/news/li-finance-protocol-loses-600-000-in-latest-defi-exploit

The Li Finance swap aggregator has experienced a smart contract exploit leading to the loss of around $600,000 from 29 users’ wallets.
https://twitter.com/lifiprotocol/status/1505738407938387971?




Title: Re: DeFi hacks [history]
Post by: Daltonik on March 23, 2022, 09:38:31 AM
The OneRing Finance DeFi protocol was subjected to a hacker attack, as a result of which the attacker managed to seize funds worth about $2 million. The hacker used a script to execute an instant loan, which had a self-destruct mechanism and, as the developers stated, this makes it very difficult to find the vulnerabilities used. To perform the exploit, the attacker placed a special smart contract on the Fantom platform.

Source: https://medium.com/oneringfinance/onering-finance-exploit-post-mortem-after-oshare-hack-602a529db99b


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 31, 2022, 12:49:22 PM
Rare Bears Discord phishing attack nabs $800K in NFTs
https://cointelegraph.com/news/rare-bears-discord-phishing-attack-nabs-800k-in-nfts

https://twitter.com/BearsRare/status/1504293859467350019?
"Discord has unfortunately been compromised. Please DO NOT click any links, connect your wallet and block all incoming DMs in our discord. Our team are working on the situation as we speak 🙏🏼"

_____________
$622M Ronin sidechain hack

Axie Infinity Tokens AXS, SLP Reeling After $622M Ronin Hack
https://decrypt.co/96433/axie-infinity-tokens-axs-slp-reeling-622m-ronin-hack
A day after Sky Mavis disclosed that a hacker stole 173,600 ETH worth $622 million from the Ronin sidechain, the Axie Infinity Shards (AXS) and Smooth Love Potion (SLP) tokens are still reeling.

Community Alert: Ronin Validators Compromised
https://roninblockchain.substack.com/p/community-alert-ronin-validators?s=r


Title: Re: DeFi hacks [history]
Post by: hd49728 on March 31, 2022, 12:53:45 PM
Community Alert: Ronin Validators Compromised
https://roninblockchain.substack.com/p/community-alert-ronin-validators?s=r
The huge compromise because of very low validators on a very centralized network like Ronin is undirectly convincing me that Ethereum is bigger and better than Binance Smart Chain.

People should know how big Ethereum network is in their total hashrate and how many validators on Ethereum network. Let's compare it to total validators on Binance Smart Chain. I am sure they will see how Ethereum is much safer and more healthy than Binance Smart Chain.

About Axie Infinity, I don't know why their team naively or carelessly to set up too low number of validators to approve transactions on Ronin chain.


Title: Re: DeFi hacks [history]
Post by: noorman0 on April 01, 2022, 02:05:30 PM
Bored Ape Yacht Club (BAYC) Discord Hacked, NFT Stolen
https://coingape.com/bored-ape-bayc-discord-hacked-nft-stolen/
Separately, Taiwanese singer Jay Chou said his tokens were stolen in a phishing attack. The stolen goods included a BAYC, a Mutant Ape Yacht Club, two Doodles, and 169 ETH ($549,000), according to data from Etherscan (https://etherscan.io/address/0xe34F004BDef6F069b92dc299587D6c8A731072Da)

STAY SAFE. Do not mint anything from any Discord right now. A webhook in our Discord was briefly compromised. We caught it immediately but please know: we are not doing any April Fools stealth mints / airdrops etc. Other Discords are also being attacked right now.




Title: Re: DeFi hacks [history]
Post by: zasad@ on April 03, 2022, 09:52:14 AM
Inverse Finance  $15.6 million
https://www.coindesk.com/tech/2022/04/02/defi-lender-inverse-finance-exploited-for-156-million/
DeFi Lender Inverse Finance Exploited for $15.6M
It is the third multimillion-dollar crypto attack to make headlines in recent days.

https://twitter.com/bertcmiller/status/1510284763332071427?s=21
"The attack is a little more nuanced than I / others thought. Brief thread."


Title: Re: DeFi hacks [history]
Post by: safar1980 on April 03, 2022, 01:35:22 PM
This is how scammers steal NFT tokens

Don't click on stealth mints, and especially don't approve "SET APPROVAL FOR ALL" transactions. They have a script that gets your most valuable NFTs and requests token approval access for them, then transfers it to the scammer's wallet.

https://twitter.com/serpentau/status/1509785117577064448?


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 06, 2022, 09:37:52 AM
https://blog.openzeppelin.com/15-billion-rugpull-vulnerability-in-convex-finance-protocol-uncovered-and-resolved/
 :o$15 Billion Rugpull Vulnerability in Convex Finance protocol Uncovered and Resolved
APRIL 4, 2022

"TLDR: In late 2021, as part of a security audit for a client, OpenZeppelin conducted a security review of the Convex Finance protocol. As part of the audit, the Security Research Team uncovered a vulnerability that, if exploited by two of three anonymous multi-signature wallet (multisig) signers, would have given the Convex multisig direct control over Convex’s locked value—then approximately $15 billion. Convex documentation specifically stated such control was not possible. This vulnerability has since been patched by the Convex Team."


Title: Re: DeFi hacks [history]
Post by: safar1980 on April 08, 2022, 08:34:34 AM
Crypto 2022: Hackers have nabbed $1.22 billion already

Hackers so far are focusing on decentralized finance (DeFi) projects to steal crypto this year, a new report found, a reversal from 2021 when they used scams and online fraud for most of their exploits.
So far, investors have lost over $1.22 billion to hackers in the first three months of the year, nearly eight times more than the $154 million lost in the first quarter of 2021, according to crypto security firm Immunefi. Ninety-nine percent of those losses were from software exploits, the report found, specifically the hacks against Wormhole and Ronin.
https://i.ibb.co/4fHFfyn/image.jpg (https://ibb.co/9v7pvXk)
source
https://finance.yahoo.com/news/crypto-hackers-stolen-173940395.html


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 08, 2022, 12:59:39 PM
New scam SberCoin.Finance
https://coinmarketcap.com/currencies/sber/
Trading in the SBER token has been launched under the guise of the official stablecoin of Sberbank.

Account suspended
https://twitter.com/SberCoinBsc
https://forklog.com/neizvestnye-zapustili-fejkovyj-sberkoin-na-birzhe-pancakeswap/



Title: Re: DeFi hacks [history]
Post by: safar1980 on April 09, 2022, 03:38:40 PM
WonderHero game disabled after hackers steal $320,000 in cryptocurrency
The operators of cryptocurrency play-to-earn game WonderHero have disabled the service after hackers stole about $320,000 worth of Binance Coin (BNB).
The attack caused the price of WonderHero’s own coin, WND, to plummet more than 90%.

https://therecord.media/wonderhero-game-disabled-after-hackers-steal-320000-in-cryptocurrency/


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 11, 2022, 08:49:46 AM
Starstream Finance $4M
Starstream Finance Hacked, Around $4M Stolen
Starstream Finance had their treasury drained in an exploit and has advised anyone holding funds in AgoraDefi to withdraw them. The Team has announced this incident on their official Discord.


Title: Re: DeFi hacks [history]
Post by: casperBGD on April 11, 2022, 09:58:28 AM
did not find this topic earlier, there is so many DeFi hacks

it is good to see that there are white hackers as well, that find breaches and share with projects, for bounties, projects find it hard to deploy on-chain, without audit, to be fast and grab the market, and that leads to code that is not polished, which leads to hacks
hopefully, numbers will go down in the future, but with more people in the industry, it does seem as inevitable to see more hacks


Title: Re: DeFi hacks [history]
Post by: Daltonik on April 13, 2022, 12:13:28 PM
The Defi team of the Elephant Money project reports that it suffered from an exploit as a result of which hackers managed to withdraw 27,416 BNB and 30 billion Elephant tokens worth ~ $22 million from the project.

https://twitter.com/ElephantStatus/status/1514007291116199936
https://medium.com/elephant-money/reserve-exploit-52fd36ccc7e8


Title: Re: DeFi hacks [history]
Post by: Daltonik on April 19, 2022, 05:40:30 PM
As a result of the exploit, Beanstalk Farms lost about $182 million from the Defi project, in total, the hacker managed to withdraw funds for about $80 million using the Tornado Cash mixer.

https://twitter.com/PeckShieldAlert/status/1515715931963801603
https://twitter.com/PeckShieldAlert/status/1515715931963801603


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 20, 2022, 05:37:28 AM
As a result of the exploit, Beanstalk Farms lost about $182 million from the Defi project, in total, the hacker managed to withdraw funds for about $80 million using the Tornado Cash mixer.

https://twitter.com/PeckShieldAlert/status/1515715931963801603
https://twitter.com/PeckShieldAlert/status/1515715931963801603

https://www.theverge.com/2022/4/18/23030754/beanstalk-cryptocurrency-hack-182-million-dao-voting
Beanstalk cryptocurrency project robbed after hacker votes to send themself $182 million

https://decrypt.co/98118/ethereum-defi-protocol-beanstalk-hacked-182-million-what-you-need-know
Ethereum DeFi Protocol Beanstalk Hacked for $182 Million—What You Need to Know
Beanstalk got jacked by a giant flash attack.

https://etherscan.io/tx/0xcd314668aaa9bbfebaf1a0bd2b6553d01dd58899c508d4729fa7311dc5d33ad7



Title: Re: DeFi hacks [history]
Post by: Daltonik on April 22, 2022, 04:41:51 PM
The Chinese company SlowMist, specializing in blockchain security, reported that in the period from April 12 to April 21, Terra network users lost their funds by clicking on phishing links placed in Google ads. Thus, the attacker withdrew funds for $4.31 million, in total assets were withdrawn from 52 addresses.

https://twitter.com/SlowMist_Team/status/1516961951032692736

https://i.ibb.co/9t0jwHK/2022-04-22-213940.jpg (https://twitter.com/SlowMist_Team/status/1516961951032692736)


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 23, 2022, 02:20:34 PM
https://www.businessinsider.in/cryptocurrency/news/a-defi-hacker-compromised-a-lesser-known-protocol-but-forgot-to-take-their-winnings/articleshow/91003503.cms
"A DeFi hacker compromised a lesser-known protocol but forgot to take their winnings
The hacker compromised a protocol called Zeed for over $1 million.
DeFi hacks have become a serious concern for the crypto industry over the past year.
Almost 97% of all cryptocurrency stolen in 2022 came from DeFi protocols."


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 28, 2022, 02:29:39 PM
Deus Finance $13.4M
https://www.coindesk.com/tech/2022/04/28/how-deus-finance-was-exploited-for-134m-on-fantom/
https://twitter.com/peckshield/status/1519530463337250817?
How Deus Finance Was Exploited for $13.4M on Fantom
The attack, which used a flash loan, was the second in two months.


Title: Re: DeFi hacks [history]
Post by: lionheart78 on April 30, 2022, 07:28:40 PM
DEFI Lender Rari Capital $80M+
https://finance.yahoo.com/news/defi-lender-rari-capital-fei-164816180.html
https://twitter.com/BlockSecTeam/status/1520350965274386433
https://i.imgur.com/yZCvTnq.png
The hacker exploited a reentrancy vulnerability in Rari's Fuse lending protocol, according to a tweet by smart contract analysis firm Block Sec.[1]


[1] https://finance.yahoo.com/news/defi-lender-rari-capital-fei-164816180.html


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 04, 2022, 08:20:53 PM
https://cointelegraph.com/news/more-than-1-6-billion-exploited-from-defi-so-far-in-2022
More than $1.6 billion exploited from DeFi so far in 2022
The amount exploited this year so far surpasses the total amount stolen in all of 2020 and 2021 combined, with the month of March alone beating 2020 by over $200 million.

https://twitter.com/CertiKTech/status/1521195341982412809?
"We have seen $1.6B lost in the #crypto/#web3 world so far this year.
In just the first 4 months on 2022 we have passed the total amount lost in 2021 ($1.3B) and in 2020 ($516MM)."

https://bitcointalk.org/index.php?topic=5397109.msg60034017#msg60034017


Title: Re: DeFi hacks [history]
Post by: btc_angela on May 04, 2022, 08:27:42 PM
^^ Not surprised with the numbers though, I mean with so much money flowing on Defi right now, the hackers are going to fill their pockets with this money and will still be aggressive this year.

And as we go along this 2022, there could be another big hacks, don't want to sound doom and gloom, but the developers will have to step their game as well so that they won't fall victims from this hacking groups.


Title: Re: DeFi hacks [history]
Post by: zasad@ on June 01, 2022, 11:07:47 AM
https://decrypt.co/93874/biggest-defi-hacks-heists
13 Biggest DeFi Hacks and Heists
There's a lot of money flowing into DeFi. And thanks to hacks and exploits, there's sometimes a lot of money flowing out, too. :) :'(
1.Poly Network: $611 Million
2.Ronin: $552 Million
3.Wormhole: $326 Million
..


Title: Re: DeFi hacks [history]
Post by: RussianEnglishTranslation on June 01, 2022, 03:44:23 PM
The benefit of using DeFi on new chains like CNDL and HBAR is that these chains are using EVM contracts that are tried and tested. DApps are just porting their code over to the new chains. It's when you get experimental DeFi stuff where things get hacked most of the time, or they are pretend hacks and real exit scams by the devs.


Title: Re: DeFi hacks [history]
Post by: zasad@ on June 01, 2022, 08:57:19 PM
Mirror Protocol Being Attacked as $2 Million Already Drained by Hacker
https://u.today/mirror-protocol-being-attacked-as-2-million-already-drained-by-hacker
"Because of an incorrect calculation, with only $1,000 worth of Luna, hackers can easily get $1.3 million in collateral, while its real value is significantly lower. Despite a low collateral price, traders can still easily borrow real funds and withdraw them without worrying about their cheap collateral."


Title: Re: DeFi hacks [history]
Post by: Daltonik on June 05, 2022, 01:47:48 PM
On May 4, hackers hacked the Discord servers of the Bored Ape Yacht Club (BAYC) project and with the help of phishing links placed in the channels, they stole 200ETH or ~$360,000. The exploit, according to the developers, was of a short-term nature and was quickly neutralized by the BAYC team.

https://www.coindesk.com/business/2022/06/04/yuga-labs-confirms-discord-server-hack-200-eth-worth-of-nfts-stolen/


Title: Re: DeFi hacks [history]
Post by: Daltonik on June 07, 2022, 05:43:38 PM
The hacker using the exploit managed to withdraw 1.65 million EGLD or about $113 million from Maiar DEX after discovering the fact of suspicious actions, the exchange was taken offline to investigate and eliminate the vulnerability. https://twitter.com/beniaminmincu/status/1533598583001337863
https://cointelegraph.com/news/maiar-decentralized-crypto-exchange-goes-offline-after-bug-discovery


Title: Re: DeFi hacks [history]
Post by: zasad@ on June 09, 2022, 10:01:04 AM
https://decrypt.co/102377/ethereum-layer-2-solution-optimism-loses-20-million-tokens-in-interlayer-snafu
Ethereum Layer-2 Solution Optimism Loses 20 Million Tokens in Interlayer Snafu
"The anonymous thief has sold off one million of the tokens as launch partner Wintermute tries to coax the hacker into cooperating.
In brief
The Layer 2 scaling solution provider failed to sync its Optimism address to an Ethereum address before a large transfer.
The stolen OP tokens were valued at $35 million at the time of the hack, with 19 million tokens still missing."

https://cointelegraph.com/news/optimism-loses-20m-tokens-after-l1-and-l2-confusion-exploited


____
Last Updated Jun 10, 2022 @ 11:31
https://cryptopotato.com/optimism-hacker-promises-to-return-18m-op-tokens-sends-another-1m-to-buterin/
Optimism Hacker Promises to Return 18M OP Tokens, Sends Another 1M to Buterin


Title: Re: DeFi hacks [history]
Post by: Daltonik on June 12, 2022, 07:08:28 PM
...
Last Updated Jun 10, 2022 @ 11:31
https://cryptopotato.com/optimism-hacker-promises-to-return-18m-op-tokens-sends-another-1m-to-buterin/
Optimism Hacker Promises to Return 18M OP Tokens, Sends Another 1M to Buterin

Well, at least the story with a happy ending really still knows how VB can benefit in non-obvious cases, because what happened is also part of his fault as a developer, because sending a hacker 1 M VB can be regarded as a sign of gratitude, in any case, the hacker still owns 1 million OP https://optimistic.etherscan.io/address/0x60b28637879b5a09d21b68040020ffbf7dba5107


Title: Re: DeFi hacks [history]
Post by: zasad@ on June 16, 2022, 09:57:19 PM
Inverse Finance Loses $1.2M to Hackers
https://coinfomania.com/defi-protocol-inverse-finance-hacked-again-for-1-2m/
"PeckShield said the attack was initiated with a flash loan worth 27,000 Wrapped Bitcoin (WBTC). The large deposit received from the loan was then used to manipulate the price of the protocol’s pool of funds. In the process, assets such as Tether USD (USDT), DOLA, Wrapped Bitcoin (WBTC), and Curve DAO token (CRV) were used."

https://twitter.com/peckshield/status/1537382891230883841


Title: Re: DeFi hacks [history]
Post by: Daltonik on June 24, 2022, 11:13:05 AM
The Harmony team notifies about the loss of assets worth ~ $ 100 million (85,867 ETH) as a result of a successful hacker attack on the Horizon cross-chain bridge, the developers have contacted law enforcement agencies and an investigation of the incident has been launched.
hacker's address: https://etherscan.io/address/0x0d043128146654c7683fbf30ac98d7b2285ded00

https://twitter.com/harmonyprotocol/status/1540110924400324608


Title: Re: DeFi hacks [history]
Post by: zasad@ on June 30, 2022, 08:47:34 AM
https://decrypt.co/104138/north-korean-attackers-behind-100m-harmony-hack-report
North Korean Attackers Behind $100M Harmony Hack: Report
"Analysis suggests the hack is the work of the Lazarus Group, the Pyongyang-backed group behind a similar $622 million hack of Axie Infinity.

According to a report released today by blockchain analytics firm Elliptic, the manner in which the funds were stolen and subsequently laundered points to the involvement of The Lazarus Group, a notorious North Korea-affiliated cybercriminal organization."


Title: Re: DeFi hacks [history]
Post by: Daltonik on July 01, 2022, 01:29:01 PM
Optimism NFT marketplace Quixotic as a result of an exploit caused by an unsuccessful contract update, which was used by a hacker, lost $100,000 (https://twitter.com/apetimism/status/1542746813748219905) in ERC - 20 tokens< the Quixotic team informs that all tokens will be returned to the owners, and their NFTs are safe.

https://twitter.com/quixotic_io/status/1542790067130978307


Title: Re: DeFi hacks [history]
Post by: Daltonik on July 03, 2022, 02:58:38 PM
Hackers have emptied the $6 million Crema Finance liquidity pool, according to blockchain auditor OtterSec hackers used flash loans on the Solend landing platform. Crema Finance was forced to suspend the operation of its application.

https://twitter.com/osec_io/status/1543469811287465984
https://twitter.com/Crema_Finance/status/1543416225622941696


Title: Re: DeFi hacks [history]
Post by: Daltonik on July 07, 2022, 07:54:10 AM
The hacker returns 6,064 ETH and 23,967.9 SOL stolen by him from the Crema Finance protocol, as a reward, the hacker left 45,455 SOL for himself. According to the Crema Finance team, they managed to reach such an agreement thanks to lengthy negotiations with the attacker.

https://twitter.com/Crema_Finance/status/1544792330674135040


Title: Re: DeFi hacks [history]
Post by: zasad@ on July 07, 2022, 02:05:32 PM
Evmos Name Service hack

https://twitter.com/EvmosNS/status/1543500126186278912
"New Smart Contract Deployed 0xD3D001724aB1C76809b9f7c2C5a2eBfc625Ee1a4
https://app.evmosnameservice.com
Old Smart contract domains not displayed in dApp
We will share a recovery plan for old contract registered domain users.
Hacked contract 0xEcF5cB1250c2e73a70636a24746aB269d40D01bA"

https://twitter.com/EvmosNS/status/1543500572917366784
"Everyone can able to register domains in the new smart contract http://app.evmosnameservice.com
We will share a recovery plan for hacked contract registered domain holders."


Title: Re: DeFi hacks [history]
Post by: Daltonik on July 11, 2022, 01:19:26 PM
The OMNI protocol suffered from the actions of a hacker who managed to withdraw more than 1300 ETH, the developers themselves say that they lost only the funds used for the beta version test and the users' funds are not affected.

https://twitter.com/peckshield/status/1546096506159058947

https://twitter.com/OMNI_xyz/status/1546143829375459332


Title: Re: DeFi hacks [history]
Post by: zasad@ on July 13, 2022, 11:15:21 AM
https://beincrypto.com/uniswap-8m-ethereum-massive-phishing-attack/
Uniswap Users Lose Over $8M Worth of Ethereum in Massive Phishing Attack
"Some individuals using Uniswap V3 have suffered a phishing attack. The attacker has stolen over 7,500 ETH, worth about $8.1 million.

Several users have lost ETH after experiencing a phishing attack using the Uniswap V3 protocol. Numerous sources are reporting that over 7,500 ETH was stolen. The incident has nothing to do with the Uniswap protocol itself, rather than the victims approved malicious transactions."


Title: Re: DeFi hacks [history]
Post by: zasad@ on July 20, 2022, 09:07:47 AM
https://twitter.com/PREMINT_NFT/status/1548578432920850432
PREMINT hack $400000

https://decrypt.co/105385/300-nfts-stolen-400k-in-ethereum-taken-in-premint-hack
300+ NFTs Stolen, $400K in Ethereum Taken In Premint Hack
Hackers infiltrated the popular NFT registration platform and used a fake pop-up to coerce users into giving up their wallet information.


Title: Re: DeFi hacks [history]
Post by: zasad@ on July 27, 2022, 02:51:10 PM
$1.1 million music streaming protocol Audius

https://www.theblock.co/post/159308/hacker-pockets-1-1-million-after-stealing-from-music-streaming-protocol-audius?
Hacker pockets $1.1 million after stealing from music streaming protocol Audius

"Audius was hacked using a malicious governance vote.
The hacker transferred 18 million AUDIO tokens and sold them for $1.1 million."


Title: Re: DeFi hacks [history]
Post by: vv181 on July 29, 2022, 04:02:00 AM
28 July 2022
Nirvana - $3.5 million flash loan exploit

https://www.theblock.co/post/159975/solana-stablecoin-nirvana-sinks-90-amid-3-5-million-flash-loan-exploit

https://nitter.net/PeckShieldAlert/status/1552589510986215425
#PeckShieldAlert Seems like @nirvana_fi
 exploited @peckshield
 
Exploiters already bridged stolen funds to Ethereum 0xB9AE2624Ab08661F010185d72Dd506E199E67C09

https://nitter.net/AndyBTC_/status/1552546781929639937
Looks like @nirvana_fi
 got hacked. Someone drained the protocol via what looks like a flash loan attack for ~3mil USDT. They've sent it to ETH mainnet via wormhole, and converted it to DAI. #opsec #crypto #hack #cryptohack

This is the eth address:


Flash loan exploit, again, and yet again :-\


Title: Re: DeFi hacks [history]
Post by: Daltonik on August 02, 2022, 08:02:02 PM
Nomad Bridge lost more than $150 million as a result of an exploit that was active for some time, the greatest damage was caused to the networks of EVMOS, Moonbeam, as it turned out, the main reason was a fatal error in the Replica contract, which is responsible for issuing funds.

https://twitter.com/samczsun/status/1554252024723546112


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 03, 2022, 11:18:53 AM
Issues in the Solana Ecosystem

https://twitter.com/SolanaStatus/status/1554695981781901312
"An exploit allowed a malicious actor to drain funds from a number of wallets on Solana. As of 5am UTC approximately 7,767 wallets have been affected.

The exploit has affected several wallets, including Slope and Phantom. This appears to have affected both mobile and extension."


Title: Re: DeFi hacks [history]
Post by: Daltonik on August 03, 2022, 05:30:23 PM
Issues in the Solana Ecosystem

https://twitter.com/SolanaStatus/status/1554695981781901312
"An exploit allowed a malicious actor to drain funds from a number of wallets on Solana. As of 5am UTC approximately 7,767 wallets have been affected.

The exploit has affected several wallets, including Slope and Phantom. This appears to have affected both mobile and extension."

It seems to me that Solana had constant failures in the mainnet, there is only one question who can be behind the emptying of users' wallets, perhaps the Solana protocol has a number of vulnerabilities that the developers are silent about or do not know about.


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 04, 2022, 10:03:54 AM
Issues in the Solana Ecosystem

https://twitter.com/SolanaStatus/status/1554695981781901312
"An exploit allowed a malicious actor to drain funds from a number of wallets on Solana. As of 5am UTC approximately 7,767 wallets have been affected.

The exploit has affected several wallets, including Slope and Phantom. This appears to have affected both mobile and extension."

It seems to me that Solana had constant failures in the mainnet, there is only one question who can be behind the emptying of users' wallets, perhaps the Solana protocol has a number of vulnerabilities that the developers are silent about or do not know about.
https://twitter.com/SolanaStatus/status/1554921396408647680?
"After an investigation by developers, ecosystem teams, and security auditors, it appears affected addresses were at one point created, imported, or used in Slope mobile wallet applications. 1/2"

Read this thread on twitter. Looks like one of the wallets has a problem.


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 10, 2022, 01:33:00 PM
https://crypto-academy.org/36-million-back-to-nomad-bridge-recovery-account/
Over $36 Million Back to Nomad Bridge’s Recovery Account
"The wallet, identified by Etherscan as the “official Nomad funds recovery address,” has received ETH 2,179.5 (equal to about $3.9 million), USDC 9.77 million, USDT 5 million, WBTC 196 ($4.7 million), DAI 3.7 million, as well as various sums of other ERC-20 tokens."


https://www.coindesk.com/business/2022/08/09/defi-protocol-curvefinance-hacked-570k-stolen/
DeFi Protocol Curve.Finance Gets Hacked and $570K Is Stolen
The source of the hack has been “found and reverted,” according to the protocol.


Title: Re: DeFi hacks [history]
Post by: Daltonik on August 15, 2022, 04:47:07 AM
https://twitter.com/AcalaNetwork/status/1558642849649856512
Acala Network suffered from an exploit that modified the configuration of the Honzon protocol, with which hackers managed to print 1.2 billion AUSD in Acala Network, as a result of which the price of the AUSD stablecoin dropped to $0.05.

https://twitter.com/WatcherGuru/status/1558735108672065538



Title: Re: DeFi hacks [history]
Post by: RussiaUkraineTranslation on August 15, 2022, 01:37:42 PM
A lot of DeFi DApps get hacked because they have very complicated contracts and this is a new technology. Staking on audited platforms like HEX and MAXX finance are much safer however. HEX has been live for a couple years now without issue and the contracts behind these projects are well proven and safer because they involve staking and not complicated bridges or swaps etc. In fact, it's often more profitable to stake on platforms like MAXX finance or Alchemix than it is to lend or use farms.


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 18, 2022, 12:31:22 PM
Celer Network
https://twitter.com/CelerNetwork/status/1560022871564775424
"📢📢📢We are seeing reports that reflects potential DNS hijacking of cbridge frontend. We are investigating at the moment and please do not use the frontend for bridging at the moment."

https://twitter.com/CelerNetwork/status/1560046913436946432
"📢📢📢If you recently used cBridge, please make sure to check and revoke any token approval for the following contracts:
Ethereum: 0x2A2aA50450811Ae589847D670cB913dF763318E8
BSC: 0x5895da888Cbf3656D8f51E5Df9FD26E8E131e7CF
(cont' in next thread)"

____
Ronin $625M
https://cointelegraph.com/news/ronin-hackers-transferred-stolen-funds-from-eth-to-btc-and-used-sanctioned-mixers
Ronin hackers transferred stolen funds from ETH to BTC and used sanctioned mixers
"The hackers continue to spread out the stolen funds using Bitcoin privacy tools as a means to remain anonymous, despite the identity of the hackers believed to be a North Korean cybercrime group."


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 31, 2022, 01:12:41 PM
DeFi project OptiFi lost $661,000
https://thetimeshub.in/defi-project-optifi-lost-661000-in-failed-update/34737/
https://decrypt.co/108585/solana-defi-exchange-optifi-bricks-itself-loses-661k

"OptiFi, a Solana-based decentralized exchange, said on Monday that it accidentally shut down its program and that all funds are now inaccessible.
Some $661,000 worth of USDC is now permanently locked within the program. OptiFi said that it will fully refund affected users."


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 07, 2022, 02:02:00 PM
Kyber Network hack  $265 000
https://twitter.com/kybernetwork/status/1565421305410686976
"1/ ❗️Notice of Exploit of KyberSwap Frontend:

We identified and neutralized an exploit on the KyberSwap frontend. Affected users will be compensated. We have summarized the details in this thread⬇️"

https://getblock.net/en/news/kyber-network-team-recovers-265-000-stolen-in-hack
Kyber Network team recovers $265 000 stolen in hack
According to the platform’s representatives, the attack vector on DEX KyberSwap was successfully identified and removed


Title: Re: DeFi hacks [history]
Post by: bounceback on September 07, 2022, 02:26:38 PM
Certik Skynet reports that the smart contact blockchain network Avalanche suffered a recent flash lending attack, according to information from Certik the attackers managed to steal $370k USDC and involve several other DEFI projects.

Resource: https://mobile.twitter.com/CertiKAlert/status/1567314528357990401?s=20&t=H0Sq29gTMSLHgPJHZYaMWw


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 14, 2022, 01:20:03 PM
New Free DAO (NFD)- $1.25M
New Free DAO (NFD) Dumps 99% After $1.2M FlashLoan Attack
Another day, another DeFi hack. Decentralised finance (DeFi) protocol New Free DAO has lost $1.25 million in flashloan attacks that caused its native token NFD to crash 99%.
https://medium.com/@CryptoSavingExpert/new-free-dao-nfd-dumps-99-after-1-2m-flashloan-attack-3f54ed604d61


Title: Re: DeFi hacks [history]
Post by: Daltonik on September 20, 2022, 01:06:08 PM
As a result of the hacker attack, the Wintermute marketmaker lost assets worth $160 million, as it is assumed his wallet was created using profanity, the CEO confirmed the hack.

https://twitter.com/SlowMist_Team/status/1572180126707896320
https://twitter.com/EvgenyGaevoy/status/1572134271011225601


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 21, 2022, 02:16:57 PM
https://blog.chainalysis.com/reports/axie-infinity-ronin-bridge-dprk-hack-seizure/
$30 Million Seized: How the Cryptocurrency Community Is Making It Difficult for North Korean Hackers To Profit
"But today I had the privilege of joining the Axie Infinity team on stage at AxieCon to deliver some good news: With the help of law enforcement and leading organizations in the cryptocurrency industry, more than $30 million worth of cryptocurrency stolen by North Korean-linked hackers has been seized. This marks the first time ever that cryptocurrency stolen by a North Korean hacking group has been seized, and we’re confident it won’t be the last.

These are the results thus far of our investigation following the March 2022 theft of more than $600 million from Ronin Network, a sidechain built for the play-to-earn game Axie Infinity."


Title: Re: DeFi hacks [history]
Post by: dansus021 on September 22, 2022, 04:35:38 AM
can i add in the list wintermute hack lost $160m source : https://rekt.news/wintermute-rekt-2/

also this website is reliable telling me about current hack in defi


Title: Re: DeFi hacks [history]
Post by: Daltonik on September 26, 2022, 02:47:36 PM
The news is not related to DeFi, but it still concerns the vulnerability of addresses to hacking if you have ever used the Profanity address generator, hackers managed to steal ~732 ETH ($950,000) from the Ethereum address created with it using the well-known vulnerability of this generator (https://twitter.com/k06a/status/1570292102726324226).

https://twitter.com/PeckShieldAlert/status/1574286302501306368



Title: Re: DeFi hacks [history]
Post by: zasad@ on September 28, 2022, 02:02:34 PM
The news is not related to DeFi, but it still concerns the vulnerability of addresses to hacking if you have ever used the Profanity address generator, hackers managed to steal ~732 ETH ($950,000) from the Ethereum address created with it using the well-known vulnerability of this generator (https://twitter.com/k06a/status/1570292102726324226).

https://twitter.com/PeckShieldAlert/status/1574286302501306368



Hacker steals $950,000 from crypto vanity address as exploits continue
https://www.theblock.co/post/172773/hacker-steals-950000-from-crypto-vanity-address-as-exploits-continue
"Hackers are continuing to steal cryptocurrency through an exploit linked to vanity addresses created by a tool called Profanity.
The latest hack comes after Wintermute lost $160 million as a result of this issue."


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 05, 2022, 01:31:46 PM
Transit Swap loses over $21M

https://cointelegraph.com/news/transit-swap-loses-over-21m-due-to-internal-bug-hack-issues-apology
Transit Swap loses over $21M due to code bug exploit, issues apology


https://www.coindesk.com/business/2022/10/03/transit-swap-exploiter-returns-large-chunk-of-289m-hack/

Transit Swap Exploiter Returns Large Chunk of $28.9M Hack
Security firms help locate the hacker's IP address following the $28.9 million exploit.

In a blog post published on Monday, Transit Swap said that $18.9 million has been returned after a slew of security firms helped triangulate the hacker's IP address.
https://medium.com/@TransitSwap/updates-about-transitfinance-4731c38d6910


Title: Re: DeFi hacks [history]
Post by: RussiaUkraineTranslation on October 05, 2022, 09:00:06 PM
Lately the target for hacks have been bridges because that is where the most money is. Audited DeFi platforms like MAXX finance and HEX are secure and well tested.


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 07, 2022, 03:44:41 PM
BNB BRIDGE - REKT  $80M
https://rekt.news/bnb-bridge-rekt/
"2M BNB stolen in a hack as complex as Binance’s naming system.

BSC Token Hub, the BNB bridge between the old Binance Beacon Chain and BSC, now BNB Chain… was exploited into minting two lots of 1M BNB directly to the hacker’s address."

BNB Chain Resumes Activity After 2 Million Token Exploit
https://decrypt.co/111448/bnb-chain-resumes-activity-2-million-token-exploit


Title: Re: DeFi hacks [history]
Post by: Daltonik on October 07, 2022, 04:07:59 PM
BNB BRIDGE - REKT  $80M
https://rekt.news/bnb-bridge-rekt/
"2M BNB stolen in a hack as complex as Binance’s naming system.

BSC Token Hub, the BNB bridge between the old Binance Beacon Chain and BSC, now BNB Chain… was exploited into minting two lots of 1M BNB directly to the hacker’s address."

BNB Chain Resumes Activity After 2 Million Token Exploit
https://decrypt.co/111448/bnb-chain-resumes-activity-2-million-token-exploit

After the incident with the hacking of the BSC Token Hub bridge, the BSC development team proposed holding a vote on chain management on the following issues:
1. Should hacked funds be frozen or not?
2. Do I need to use automatic BNB burning to cover the remaining hacked funds or not?
3. Conducting a Whitehat program for future detected errors, $1 million for each significant error detected.
4. Announcement of a reward for the capture of hackers, up to 10% of the funds returned.
The BSC validator voting feature for general opinion will be enabled in the next few days as a result of the BNB Beacon Chain update.

Source: https://www.bnbchain.org/en/blog/bnb-chain-ecosystem-update/


Title: Re: DeFi hacks [history]
Post by: Aliem Nur on October 07, 2022, 04:56:28 PM
BNB BRIDGE - REKT  $80M
https://rekt.news/bnb-bridge-rekt/
"2M BNB stolen in a hack as complex as Binance’s naming system.

BSC Token Hub, the BNB bridge between the old Binance Beacon Chain and BSC, now BNB Chain… was exploited into minting two lots of 1M BNB directly to the hacker’s address."

BNB Chain Resumes Activity After 2 Million Token Exploit
https://decrypt.co/111448/bnb-chain-resumes-activity-2-million-token-exploit
this is the latest, I'm really shocked about BNBChain getting hacked when Binance is also very massive working on the project,
and of course this is like a blow to CZ, because it's a very large number, reportedly the BNBChain network will be paused for the next few hours,
is it when is this back to normal again?.


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 07, 2022, 07:08:31 PM
BNB BRIDGE - REKT  $80M
https://rekt.news/bnb-bridge-rekt/
"2M BNB stolen in a hack as complex as Binance’s naming system.

BSC Token Hub, the BNB bridge between the old Binance Beacon Chain and BSC, now BNB Chain… was exploited into minting two lots of 1M BNB directly to the hacker’s address."

BNB Chain Resumes Activity After 2 Million Token Exploit
https://decrypt.co/111448/bnb-chain-resumes-activity-2-million-token-exploit
this is the latest, I'm really shocked about BNBChain getting hacked when Binance is also very massive working on the project,
and of course this is like a blow to CZ, because it's a very large number, reportedly the BNBChain network will be paused for the next few hours,
is it when is this back to normal again?.
CZ has already tweeted that user funds are safe. I'm more concerned that validators will get the right to run a decentralized blockchain, even though smart chain binance was not considered decentralized. But the developers want to implement the same thing in Ethereum with the new ERC-20R/721R token standard.


Title: Re: DeFi hacks [history]
Post by: Daltonik on October 11, 2022, 11:00:57 AM
Little by little, funds are being refunded to dex Transit Swap users affected by the hacker, who returned 6,500 BNB and promises to return another 3,500 BNB later for a reward of 2,500 BNB. Such an agreement was reached by the Transit Swap team as a result of negotiations with the hacker, who previously returned most of the stolen.

https://medium.com/@TransitSwap/updates-about-transitfinance-317f4fe67931


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 12, 2022, 01:33:36 PM
https://www.bloomberg.com/news/articles/2022-10-12/crypto-platform-mango-hit-by-latest-hack-in-digital-asset-sector#
Crypto Attack Swipes $100 Million From DeFi Service Mango
"Incident comes just days after $100 million Binance Coin hack
Mango says attackers indicated a willingness to communicate

An attacker spirited away about $100 million from decentralized finance provider Mango by manipulating the price of its token in an exploit that wiped out depositors on the crypto platform.

The heist began with two accounts funded with the stablecoin USD Coin, the platform said Wednesday on Twitter. The accounts took large positions in Mango perpetual futures, causing the price of the Mango token to spike."
____

https://www.theblock.co/post/176299/hacker-steals-2-3-million-from-templedao
Hacker steals $2.3 million from TempleDAO


Title: Re: DeFi hacks [history]
Post by: Daltonik on October 13, 2022, 10:08:12 AM
Chainalysis collected statistics on hacking this year, so for example, October 2022 has not ended yet, but it has already become the largest month in the history of hacking activity for the entire year. So far this month, $718 million has been stolen from the DeFi protocols using 11 different hacks.

https://i.imgur.com/5Lu73t2.jpg

Cross-chain bridges are the main target for hackers: in October, 3 bridges were hacked and almost $600 million was stolen, this is 82% of losses this month and 64% of losses for the whole year.

https://i.imgur.com/PbzM1Oc.jpg

During this year, hackers earned more than $3 billion for 125 hacks.

https://i.imgur.com/5U9GWFT.jpg

Analysis of hacks shows that if cex was previously the target of hackers , then starting from 2021 their main goal is Defi protocols.

https://i.imgur.com/BXVqycW.jpg

Source: https://twitter.com/chainalysis/status/1580312153269374980


Title: Re: DeFi hacks [history]
Post by: Daltonik on October 15, 2022, 04:21:33 AM
Mango Markets is due to complete the voting on October 15, according to the approval of the payment to the hacker in the amount of $47 million, already more than 98% of voting tokens approve the transaction.
By the way, under the terms of the deal with the hacker, it is stipulated that Mango Markets will not bring him to criminal responsibility.
This will be one of the largest payments to a hacker, if we consider that he spent $10 million on carrying out the attack, then his catch will be $37 million.

Source: https://cointelegraph.com/news/mango-market-s-dao-forum-set-to-approve-47m-settlement-with-hacker


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 19, 2022, 03:00:04 PM
Celo Protocol Moola Market Loses Over $10M in Market Manipulation Attack
https://www.coindesk.com/markets/2022/10/19/celo-protocol-moola-market-loses-over-10m-in-market-manipulation-attack/

"Celo-based lending and borrowing protocol Moola Market had over $10 million worth of tokens stolen, and later returned, Wednesday morning after a market manipulation attack.
The exploit was the second of its kind in the last few weeks, with the attackers manipulating the prices of Moola’s native MOO tokens to borrow collateral against their positions – effectively draining the protocol."


Title: Re: DeFi hacks [history]
Post by: NicNacCoin on October 19, 2022, 03:33:41 PM
Defi projects are the most hacked in a very short period of time.So many coins have been hacked in such a short period of time which is really sad.But I invested in two Defi platforms and now they are worthless. In fact, such projects come and leave people in a very confused state and people are completely out of the hands of various investments Destroys trust. People are afraid to invest only because of these reasons


Title: Re: DeFi hacks [history]
Post by: Daltonik on October 19, 2022, 04:08:52 PM
Celo Protocol Moola Market Loses Over $10M in Market Manipulation Attack
https://www.coindesk.com/markets/2022/10/19/celo-protocol-moola-market-loses-over-10m-in-market-manipulation-attack/

"Celo-based lending and borrowing protocol Moola Market had over $10 million worth of tokens stolen, and later returned, Wednesday morning after a market manipulation attack.
The exploit was the second of its kind in the last few weeks, with the attackers manipulating the prices of Moola’s native MOO tokens to borrow collateral against their positions – effectively draining the protocol."

The latest data analytically indicate a loss of approximately $8.4 million in assets of several tokens 8.8M CELO ($6.5M), 765k cEUR ($0.7M), 1.8M MOO ($0.6M) and 644k cUSD https://twitter.com/FrankResearcher/status/1582448720985014273 , but this of course does not affect anything another vulnerability of the Defi protocol was used


Title: Re: DeFi hacks [history]
Post by: Ipyana MW on October 26, 2022, 01:16:13 PM
Some stats from quarter 3, 2022 for the generations to come 😊
Elliptic says that DeFi continues to be the key target for exploits as compared to CeFi. DeFi represents 98.8% of the total losses, while CeFi represents 1.2% of the total losses.


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 26, 2022, 02:40:09 PM
Decentralized exchange QuickSwap exploited for $220K, plans to close lending markets
https://www.theblock.co/post/179333/decentralized-exchange-quickswap-exploited-for-220k-plans-to-close-lending-markets

"QuickSwap DEX was exploited for $200,000.
The exploit used flash loans to attack a vulnerability with the Curve Oracle.
QuickSwap, a decentralized exchange on Polygon, was exploited for $220,000, according to the exchange."


Title: Re: DeFi hacks [history]
Post by: Daltonik on October 28, 2022, 11:04:57 AM
The Team Finance DeFi protocol project lost ~ $15.8 million in assets due to a vulnerability in the token migration function, which the hacker managed to detect and use to carry out the attack, he needed only 1.76 ETH.
https://twitter.com/peckshield/status/1585587858978623491

Hacker Transactions:
https://etherscan.io/tx/0xb2e3ea72d353da43a2ac9a8f1670fd16463ab370e563b9b5b26119b2601277ce


Title: Re: DeFi hacks [history]
Post by: Hamza2424 on October 28, 2022, 05:36:17 PM
Dear the major hack or scams in defi are due to some reasons as let me explain one of the major reason. As you all know that in DeFi protocols and Apps the source codes are open source many of the scammer just copy code and make a few changes to create a new platform similar to previous one this happened with Dexs in early 2021 and 2022. It cause major scams and people gets trapped.


Title: Re: DeFi hacks [history]
Post by: Daltonik on November 02, 2022, 01:36:59 PM
The decentralized Rubic exchange lost more than $1.2 million (34 million RBC and BRBC tokens) after a hacker managed to compromise the wallet of the exchange administrator by obtaining private keys from him, the wallet managed the RBC/BRBC bridge and the rewards for staking.

https://twitter.com/CryptoRubic/status/1587704548688367619






Title: Re: DeFi hacks [history]
Post by: zasad@ on November 02, 2022, 01:41:55 PM
https://cointelegraph.com/news/deribit-crypto-exchange-halts-withdrawals-amid-28m-hot-wallet-hack@
"Deribit crypto exchange halts withdrawals amid $28M hot wallet hack
Crypto exchange Deribit halted withdrawals following a hot wallet hack where hackers got away with $28 million in stolen funds.

The exchange emphasized that client funds are safe as losses are covered by Deribit’s reserves, stating:
“Client assets, Fireblocks or any of the cold storage addresses are not affected. It's company procedure to keep 99% of our user funds in cold storage to limit the impact of these type of events.”
"


Title: Re: DeFi hacks [history]
Post by: Daltonik on November 04, 2022, 12:19:18 PM
Gala Games lost ~ 26% in price amid fears of hacking or fraud after one address through DEX PancakeSwap issued ~56 billion pGALA, which is the equivalent of $2.2 billion.
https://twitter.com/lookonchain/status/1588352050642837505

However, hackers managed to implement tokens for ~13,000 BNB, Huobi announced the temporary delisting of the GALA token (https://www.huobi.com/support/en-us/detail/84921856563770), Binance temporarily suspended the input and output of the GALA token (https://twitter.com/binance/status/1588434639643111425).
https://twitter.com/peckshield/status/1588273496819634176

Everything happened as assumed due to an incorrect configuration of the bridge used by Gala Games to interact with the BNB Smart Chain.
https://twitter.com/pNetworkDeFi/status/1588266897061031936


Title: Re: DeFi hacks [history]
Post by: FP91G on November 04, 2022, 02:52:20 PM
DeFi Protocol Solend Struck by $1.26M Oracle Exploit
Solana-based decentralized finance (DeFi) protocol Solend has suffered an exploit in relation to pricing oracles, resulting in $1.26 million in bad debt.
The exploit was centered around the hubble stablecoin (USDH) and affected the Stable, Coin98, and Kamino lending pools, according to a tweet by Solend.
A pricing oracle is a source of data that provides asset values for blockchains. Hacks and exploits related to decentralized finance, which is a form of lending that takes place without intermediaries, have surged over the past month. Security firm Chainalysis reported that $718 million had been stolen in the first two weeks of October.

https://www.coindesk.com/business/2022/11/02/defi-protocol-solend-struck-by-126m-oracle-exploit/


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 09, 2022, 02:21:35 PM
https://cointelegraph.com/news/deribit-hackers-move-stolen-ether-to-tornado-cash-crypto-mixer
Deribit hackers move stolen Ether to Tornado Cash crypto mixer
"The Deribit hot wallet hacker has transferred 1,610 ETH (over $2.5 million) to Tornado Cash, according to data from the Ethereum block explorer Etherscan.
In the aftermath of the $28 million Deribit hack, the unknown exploiter is moving stolen funds using the decentralized cryptocurrency mixer, Tornado Cash."


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 16, 2022, 01:13:42 PM
https://beincrypto.com/dfx-finance-hacked-exploiter-drains-4m-funnels-funds-tornado-cash/
DFX Finance Hacked, Exploiter Drains $4M And Funnels Funds to Tornado Cash
DeFi protocol DFX Finance has been hacked with the attacker stealing about $4 million.
The team has paused all contracts and will issue a post-mortem soon.
DeFi hacks have been common in 2022 and account for the majority of security incidents.
____


DeFi project Flare on hacked. $17.9 million
https://forklog.com/news/defi-proekt-flare-na-bnb-chain-vzlomali-na-17-9-mln

https://twitter.com/peckshield/status/1591831184526516226?


https://twitter.com/peckshield/status/1591833722621689856?
"The stolen funds/loss is about ~$17M and 4,000 BNB of them are being washed via
@TornadoCash
https://bscscan.com/address/0xe55d77f74ea9335d3a83a673f83f38527a68eb20  "

https://twitter.com/peckshield/status/1591837070926151680?
"It should be rugged with the 3.9B $Flare by calling withdrawProfit() of an unverified contract:  https://bscscan.com/tx/0xa09135020bb1271ff684db407783a52163c31c7255955cec1e83fc68a751c027"


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 24, 2022, 08:43:45 AM
https://twitter.com/boshen1011/status/1595265219898789888?

"@boshen1011
A total of 42M worth of crypto assets, including 38M in USDC were stolen from my personal wallet ending in 894 in the early morning of November 10 EST.

The stolen assets are personal funds and do not affect on Fenbushi related entities."

Bo Shen is the founder of Fenbushi Capital


Title: Re: DeFi hacks [history]
Post by: Daltonik on December 02, 2022, 08:22:43 AM
The Ankr DeFi protocol was hacked, as a result, a huge number of aBNBc tokens were issued by the attackers, after which its price fell to zero, losses are estimated at about $15 million.
https://twitter.com/PeckShieldAlert/status/1598527823224111104
https://twitter.com/ankr/status/1598503332477280256

The project team confirms the hack and declares that the users' funds are safe, and will be reimbursed by the reissue of aBNBc based on a snapshot of users' wallets.
https://twitter.com/ankr/status/1598570449390260226


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 02, 2022, 01:03:05 PM
The Ankr DeFi protocol was hacked, as a result, a huge number of aBNBc tokens were issued by the attackers, after which its price fell to zero, losses are estimated at about $15 million.
https://twitter.com/PeckShieldAlert/status/1598527823224111104
https://twitter.com/ankr/status/1598503332477280256

The project team confirms the hack and declares that the users' funds are safe, and will be reimbursed by the reissue of aBNBc based on a snapshot of users' wallets.
https://twitter.com/ankr/status/1598570449390260226


https://cointelegraph.com/news/ankr-confirms-exploit-asks-for-immediate-trading-halt
"BNB Chain-based decentralized finance (DeFi) protocol Ankr has confirmed it has been hit by a multi-million dollar exploit on Dec. 1.

The attack appeared to be first discovered by on-chain security analyst PeckShield at approximately 12:35 am UTC on Dec. 2. "


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 11, 2022, 12:40:10 PM
7 000 000$ lodestar finance
https://twitter.com/LodestarFinance/status/1601687317604839424

https://tokeninsight.com/en/news/arbitrum-ecosystem-defi-protocol-lodestar-finance-exploited
"Arbitrum ecosystem DeFi protocol Lodestar Finance tweeted that it was exploited and deposits have been drained. The protocol has set all interest rates to 0.

An attacker manipulated the exchange rate of the plvGLP contract to 1.83 GLP per plvGLP. They supplied plvGLP collateral to lodestar and borrowed all available liquidity. After the hack several plvGLP holders also took advantage of the opportunity and also cashed out at 1.83 glp per plvGLP. The hacker burned a little over 3 million in GLP, their profit on this exploit was the stolen funds on Lodestar - minus the GLP they burned.

Lodestar Finance said that 2.8 million of the GLP (about $2.4 million) was recoverable. The team is going to reach out to the hacker and see if they can negotiate a bug bounty to recover more funds."


Title: Re: DeFi hacks [history]
Post by: AliErkic on December 14, 2022, 12:28:02 AM
Wow, what a long list!
DeFi is known to be coded badly but I wouldn't expect such a long list...
Devs really need to set up a better code, review it better and do more education on how to code properly.
We can't afford much more DeFi hacks, DeFi is already known to be famous for hacks.

And all hacker funds are laundered in mixers, it's a shame.
I hope, all hackers will be caught, funds seized and hackers put into prison!


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 14, 2022, 01:35:31 PM
And all hacker funds are laundered in mixers, it's a shame.
I hope, all hackers will be caught, funds seized and hackers put into prison!
Just like in a children's fairy tale: good will triumph over evil!
______
https://www.coinbase.com/blog/transparency-report-2022
Key Takeaways:

"There were a total of 12,320 requests during the reporting period, a ~66% increase over last year’s report.

The ~57% of requests from outside of the United States was a ~6% increase over our previous report. In addition, 21 Countries sent requests for the first time in 2022, including 11 that sent more than one: Andorra (2), Argentina (2), Brazil (5), Bulgaria (3), China (12), Croatia (3), Czech Republic (104), Liechtenstein (4), Serbia (5), Slovakia (6), Taiwan (6).

~80% of law enforcement requests were from the U.S., U.K., Germany, and Spain."


Title: Re: DeFi hacks [history]
Post by: AliErkic on December 15, 2022, 03:38:52 AM
And all hacker funds are laundered in mixers, it's a shame.
I hope, all hackers will be caught, funds seized and hackers put into prison!
"There were a total of 12,320 requests during the reporting period, a ~66% increase over last year’s report.
It's a long way to stop scammers. Like Brad Garlingcrook, he's still praising his shitcoin.


Title: Re: DeFi hacks [history]
Post by: cryptops.exchange on December 15, 2022, 05:23:18 AM
The hacks seem to involve using buggy smart contracts or protocols. It is really a shame and harmful for the early reputation DeFi of as a whole. Maybe it is better to find DeFi projects to investment with that don't even use smart contracts or any protocols at all?


Title: Re: DeFi hacks [history]
Post by: FP91G on December 17, 2022, 01:50:14 PM
Solana DeFi Exchange Raydium Hacked for Over $2 Million
The attacker appears to have used the protocol’s own private keys to drain liquidity pools. It’s unclear how they got them.
https://decrypt.co/117455/solana-raydium-hacked-2-million

The wallet draining LP Pools from Raydium liquidity pools has received over $2.2M now, including $1.6M $SOL
https://twitter.com/nansenportfolio/status/1603762024667746305?


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 23, 2022, 03:06:40 PM
The 2022 Rug Pull Report
https://www.soliduslabs.com/reports/rug-pull-report

https://www.coingecko.com/research/publications/how-many-cryptocurrencies-faile
"3,322 cryptocurrencies that were listed on CoinGecko in 2021, have failed (categorised as a dead coin).
The last bull market run that started in November 2020 saw a spike in cryptocurrencies listed, with more than 8000 cryptocurrencies listed in 2021. As of today, nearly 40% have been deactivated and delisted from CoinGecko."
https://i.ibb.co/DQ6Rzp1/content-Dead-Cryptocurrencies-JN-28-Nov-2.png (https://ibb.co/vkrjVYc)


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 24, 2022, 07:20:01 PM
What a long list. DeFi hacks and exploits will continue.  We have so many dubious actors right on the space, one can not be more than careful enough.

I think Insurance coverage might make a big difference against hacks. What do you think?

https://markets.businessinsider.com/news/currencies/global-drug-cartel-binance-launder-millions-crypto-exchange-dea-investigation-2022-12
"This is actually an example of where the transparency of blockchain transactions works against criminal actors," Matthew Price, the senior director of investigations at Binance, told Forbes. "The bad guys are leaving a permanent record of what they're doing."

I also write a lot about refunds. Every year it will become more and more difficult to hide the stolen funds.


Title: Re: DeFi hacks [history]
Post by: Daltonik on December 26, 2022, 10:55:27 AM
Hackers managed to re-attack the Rubic cross-chain swap aggregator project, they compromised one of the smart contracts, the damage amounted to ~$1.41 million. The Rubic team reported that 49 users were affected, and promised to compensate for their losses.

https://twitter.com/peckshield/status/1606937055761952770
https://twitter.com/CryptoRubic/status/1607076270663208960


Title: Re: DeFi hacks [history]
Post by: $crypto$ on December 26, 2022, 05:59:45 PM
Bitkeep has been the next hack, according to hacking sources Bitkeep involved 4 chains of ETH, BSC, POLYGON and TRX, and now $31m has come out as its transaction volume.

It is likely that their losses will increase given that there is currently no response from BitKeep.

Source from OKlink: https://twitter.com/OKLink/status/1607356529929506817


Title: Re: DeFi hacks [history]
Post by: safar1980 on December 27, 2022, 03:43:45 PM
Top Five DeFi Crime Trends of 2022
Decentralized finance (DeFi) has had a challenging year – losing 75% of its total value locked over the last 11 months.  However, while the crypto crash might have hit investors, it did not deter criminals. Bug exploits, logic faults, private key compromises and social engineering attacks broke records in 2022, stealing a record $2.7 billion from DeFi protocols. That is more than half of the $5.1 billion stolen overall from DeFi since 2020. Furthermore, four of 2022’s worst DeFi hacks secured their place on the list of top ten biggest crypto heists of all time.
https://hub.elliptic.co/analysis/top-five-defi-crime-trends-of-2022/


Title: Re: DeFi hacks [history]
Post by: o48o on December 27, 2022, 11:09:11 PM
That's like modern day bank robbery but more effective and profitable. And while whose seem a lot, i think that centralized exchange hacks combined with exit scams are far worse.

As in comparison bitfinex lost $623 million in one hack, coincheck $560 million, and FTX just got hacked for $600 million. And if we start to count exit scams, remember that plustoken team got $2.9 Billion and ran. Not to mention all the leaked user data with all the cexes.


Title: Re: DeFi hacks [history]
Post by: dbshck on December 28, 2022, 02:38:18 AM
https://www.bloomberg.com/news/articles/2022-10-12/crypto-platform-mango-hit-by-latest-hack-in-digital-asset-sector#
Crypto Attack Swipes $100 Million From DeFi Service Mango
"Incident comes just days after $100 million Binance Coin hack
Mango says attackers indicated a willingness to communicate

An attacker spirited away about $100 million from decentralized finance provider Mango by manipulating the price of its token in an exploit that wiped out depositors on the crypto platform.

The heist began with two accounts funded with the stablecoin USD Coin, the platform said Wednesday on Twitter. The accounts took large positions in Mango perpetual futures, causing the price of the Mango token to spike."

Update: Mango exploiter (Avraham Eisenberg) arrested https://www.coindesk.com/policy/2022/12/27/mango-markets-exploiter-eisenberg-arrested-in-puerto-rico/


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 28, 2022, 03:01:32 PM
Rubic DEX aggregator hack leads to $1.4m of user funds stolen
https://crypto.news/rubic-dex-aggregator-hack-leads-to-1-4m-of-user-funds-stolen/
Cross-chain decentralized finance (DeFi) protocol Rubic was compromised, resulting in funds stored in its user’s addresses being siphoned out and transferred to the hackers.


Defrost Finance hack & Returned $12M
https://www.coindesk.com/business/2022/12/26/defrost-finance-says-hacked-funds-have-been-returned/
Defrost Finance Says Hacked Funds Have Been Returned
The hack, which some observers had characterized as a rug pull, was estimated to have netted $12 million.



___
Update: Mango exploiter (Avraham Eisenberg) arrested https://www.coindesk.com/policy/2022/12/27/mango-markets-exploiter-eisenberg-arrested-in-puerto-rico/
add to OP


Title: Re: DeFi hacks [history]
Post by: FP91G on December 29, 2022, 10:33:59 AM
Hackers have been able to steal NFTs like magic with a little-known OpenSea feature. It's the newest hack, and multiple millions in Apes have been lost to it already.
https://twitter.com/harpieio/status/1606034727491624961?

The OpenSea contract allows for "gasless sales," where users can sell NFTs by signing an unreadable message like the one above.
Here's the catch: you can also set up ⚠️private auctions with custom prices⚠️ with these unreadable signatures.
https://twitter.com/harpieio/status/1606034729102217216


Title: Re: DeFi hacks [history]
Post by: zasad@ on January 05, 2023, 12:21:56 PM
Nikhil Gopalani- COO / Ops & BD - Nike / RTFKT
https://www.crunchbase.com/person/nikhil-gopalani

Nikhil Gopalani(C)
https://twitter.com/Nikgopalani/status/1610120899570663425
"Hey Clone X community - I was hacked by a clever Phisher (same phone # as apple ID) & sold all my clone x / some other nfts... Obviously pretty upset and hurt by this and I havent really been able to move all day. Hope people who bought my clones love them (being positive)"


https://twitter.com/ImmuneBytes/status/1610683109904912384
"RTFKT COO @Nikgopalani
 became the victim of a #phishing attack. On Jan 2, he allegedly lost $173,000 worth of #NFTs to the exploit.
The list of stolen NFTs includes 19 CloneX NFTs, 18 RTKFT Space Pods, 17 Loot Pods, 11 CryptoKicks, 19 RTFKT Animus Eggs, and more. Source:
@opensea"


Title: Re: DeFi hacks [history]
Post by: safar1980 on January 10, 2023, 12:38:57 PM
SlowMist 2022 Security Report (https://www.slowmist.com/report/2022-Blockchain-Security-and-AML-Analysis-Annual-Report(EN).pdf): Hacking incidents caused losses of $3.777b, a decrease of about 61% compared to $9.795b in 2021. In 2022, there were 10 security incidents with a loss of hundreds of millions, cross-chain bridges accounted for 4 of them.
https://twitter.com/WuBlockchain/status/1612448354591727616?


Title: Re: DeFi hacks [history]
Post by: safar1980 on January 15, 2023, 11:24:18 AM
Famous NFT influencer NFT God suffered a hacking scheme.
https://chainwitcher.com/nft-god-hacked/

Last night my entire digital livelihood was violated.
Every account connected to me both personally and professionally was hacked and used to hurt others.
Less importantly, I lost a life changing amount of my net worth
https://twitter.com/NFT_GOD/status/1614442000958324739

What conceit do you need to have to call yourself God?


Title: Re: DeFi hacks [history]
Post by: zasad@ on January 25, 2023, 01:27:25 PM
https://techcrunch.com/2023/01/24/north-korea-fbi-harmony-horizon-crypto/
FBI accuses North Korean government hackers of stealing $100M in Harmony bridge theft
"The FBI accused two groups of North Korean government hackers of carrying out last year’s heist of $100 million in crypto stolen from a company that allows users to transfer cryptocurrency from one blockchain to another.

On Monday, the FBI announced that the Lazarus Group and APT38 — two groups linked to the North Korean government by both cybersecurity companies and government agencies — were responsible for the hack against the Horizon bridge, created by the U.S. company Harmony, in June 2022."


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 01, 2023, 11:22:47 AM
https://cointelegraph.com/news/hackers-takeover-azuki-s-twitter-account-steal-over-750k-in-less-than-30-minutes
Hackers breach Azuki’s Twitter account, stealing $758K in 30 minutes
Most of the funds stolen were from a single wallet, with $751,321.80 in USDC drained from the malicious link.

https://twitter.com/emilyrosemcg/status/1619046380533854209?
"AZUKI OFFICIAL TWITTER ACCOUNT IS HACKED.
DO NOT CLICK LINKS FROM OUR ACCOUNT.
PLEASE RETWEET."


Another Defi Hack
https://bitcointalk.org/index.php?topic=5267124.0

https://twitter.com/BonqDAO/status/1620908233761378304
"Bonq protocol was exposed to an oracle hack, where exploiter increased the ALBT price and minted large amounts of BEUR. The BEUR was then swapped for other tokens on Uniswap. Then, the price was decreased to almost zero, which triggered the liquidation of ALBT troves."

BonqDAO protocol suffers $120M loss after oracle hack
https://cointelegraph.com/news/bonqdao-protocol-suffers-120m-loss-after-oracle-hack

Subscribe to the project's twitter and discord. If the project does not die, they will publish an article on how they will recoup the losses.


Title: Re: DeFi hacks [history]
Post by: Daltonik on February 02, 2023, 11:20:00 AM
The BonqDAO protocol lost $120 million as a result of a hacker attack, where the hacker used the method of manipulating the price of the ALBT token, so he informed the protocol that the cost of the ALBT token is equal to 5 billion MATIC, which the protocol actually agreed with, despite the fact that the BonqDAO protocol has an oracle from Chainlink.

Source: https://cointelegraph.com/news/bonqdao-protocol-suffers-120m-loss-after-oracle-hack
             https://twitter.com/BonqDAO/status/1620908233761378304
             https://twitter.com/peckshield/status/1620926816868499458


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 03, 2023, 02:55:32 PM
https://twitter.com/peckshieldalert/status/1620452597105676291?
"#PeckShieldAlert ~24 exploits grabbed $8.8M in January 2023.
As of January 31st, 2023, ~$2.6M worth of stolen funds (~2,668 $BNB & 1,200 $ETH) were transferred into Mixers (TornadoCash, Fixedfloat, and sideshift[.]ai)."
https://i.ibb.co/8YbqVT4/Fnyy-H4a-AAMdt-Y2.jpg (https://ibb.co/LNrmfbh)



https://crypto.news/lendhub-loses-6m-to-hackers/
LendHub loses $6m to hackers
According to a report issued by the team on Friday, DeFi digital asset lending firm LendHub has lost $6 million in digital assets on its network.




Title: Re: DeFi hacks [history]
Post by: safar1980 on February 04, 2023, 05:08:45 PM
Orion Protocol Hacked, $3 Million Lost: Here's How  (https://u.today/orion-protocol-hacked-3-million-lost-heres-how)
PeckShield, a reputable cryptocurrency security research team, unveils the design of alleged attacks against Orion Protocol. Meanwhile, its team says only internal funds were at risk. Orion Protocol hacked for $3 million thanks to well-known bug: PeckShield According to the statement shared by PeckShield representatives on Twitter, Orion Protocol, a popular liquidity machine for CEXes and DEXes, suffered a hacker attack today, Feb. 3, 2023.


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 04, 2023, 07:06:53 PM
2023 DeFi hacks. Continuation
1 post  (https://bitcointalk.org/index.php?topic=5267124.msg54946420#msg54946420) has exhausted the limit of information, the continuation will be in this post

January 4, 2023
RTFKT COO Nikgopalani $0,173M
https://bitcointalk.org/index.php?topic=5267124.msg61547671#msg61547671

January 12, 2023
LendHub loses $6M
https://bitcointalk.org/index.php?topic=5267124.msg61703100#msg61703100

February 1,2023
BonqDAO protocol suffers $120M
https://bitcointalk.org/index.php?topic=5267124.msg61691280#msg61691280

February 3,2023
Orion Protocol  $3M
https://bitcointalk.org/index.php?topic=5267124.msg61709050#msg61709050

February 9,2023
CoW Swapl  $0,182M
https://bitcointalk.org/index.php?topic=5267124.msg61740866#msg61740866

February 10,2023
DeFi Protocol dForce $3,65M
https://bitcointalk.org/index.php?topic=5267124.msg61746599#msg61746599

February 16,2023
DeFi Protocol Platypus  $8,5M
https://bitcointalk.org/index.php?topic=5267124.msg61802035#msg61802035

February 27,2023
DeFi Protocol  LaunchZone  $0,7M
https://bitcointalk.org/index.php?topic=5267124.msg61837040#msg61837040

March 13,2023
Euler Finance  $196M
https://bitcointalk.org/index.php?topic=5267124.msg61904478#msg61904478

March 13,2023
PeopleDAO  $0,12M
https://bitcointalk.org/index.php?topic=5267124.msg61916813#msg61916813

March 26,2023
Kokomo Finance $4M
https://bitcointalk.org/index.php?topic=5267124.msg61998945#msg61998945

March 29,2023
DEFISafeMoon $8,9M
https://bitcointalk.org/index.php?topic=5267124.msg62004227#msg62004227

April 4, 2023
Exploiter Front Runs $25M
https://bitcointalk.org/index.php?topic=5267124.msg62037817#msg62037817

April 10, 2023
SushiSwap $3,3M
https://bitcointalk.org/index.php?topic=5267124.msg62067347#msg62067347

April 13, 2023
Yearn Finance $11M
https://bitcointalk.org/index.php?topic=5267124.msg62115758#msg62115758

April 16, 2023
Hundred Finance Protocol $7.4M
https://bitcointalk.org/index.php?topic=5267124.msg62151334#msg62151334

April 25, 2023
zkSync DEX Merlin $1.82M
https://bitcointalk.org/index.php?topic=5267124.msg62152558#msg62152558

May 1, 2023
Level Finance $1M
https://bitcointalk.org/index.php?topic=5267124.msg62189833#msg62189833

May 10, 2023
Deus Finance $6M
https://bitcointalk.org/index.php?topic=5267124.msg62225011#msg62225011

May 20, 2023
Swaprum $3M
https://bitcointalk.org/index.php?topic=5267124.msg62333807#msg62333807

May 25, 2023
ZachXBT: $31.6M
https://bitcointalk.org/index.php?topic=5267124.msg62299944#msg62299944

May 30, 2023
Jimbos Protocol: $7.5M
https://bitcointalk.org/index.php?topic=5267124.msg62334136#msg62334136

June 12, 2023
Sturdy Finance: $0.8M
https://bitcointalk.org/index.php?topic=5267124.msg62406071#msg62406071

June 14, 2023
Hashflow: $0.6M
https://bitcointalk.org/index.php?topic=5267124.msg62409187#msg62409187

June 27, 2023
Chibi Finance: $1M
https://bitcointalk.org/index.php?topic=5267124.msg62475146#msg62475146

July 04, 2023
Poly Network: $5M
https://bitcointalk.org/index.php?topic=5267124.msg62503144#msg62503144

July 07, 2023
Multichain Fantom Bridge: $126M
https://bitcointalk.org/index.php?topic=5267124.msg62515049#msg62515049

July 12, 2023
Arcadia Finance: $0.455M
https://bitcointalk.org/index.php?topic=5267124.msg62539307#msg62539307

July 17, 2023
Rodeo Finance: $0.888M
https://bitcointalk.org/index.php?topic=5267124.msg62572884#msg62572884

July 21, 2023
Conic Finance: $3.2M
https://bitcointalk.org/index.php?topic=5267124.msg62582178#msg62582178

July 26, 2023
Era Lend: $3.4M
https://bitcointalk.org/index.php?topic=5267124.msg62604116#msg62604116

August 1, 2023
Curve Finance: $52M
https://bitcointalk.org/index.php?topic=5267124.msg62631337#msg62631337

August 2, 2023
Kannagi Finance: $3.4 M
https://bitcointalk.org/index.php?topic=5267124.msg62636636#msg62636636

August 8, 2023
decentralized exchange Cypher: $1 M
https://bitcointalk.org/index.php?topic=5267124.msg62669792#msg62669792

August 14, 2023
Steadefi: $1.1 M
https://bitcointalk.org/index.php?topic=5267124.msg62704762#msg62704762

August 14, 2023
Aave’s Earning Farm: $0.287 M
https://bitcointalk.org/index.php?topic=5267124.msg62704762#msg62704762

August 14, 2023
Uwerx: $0.327 M
https://bitcointalk.org/index.php?topic=5267124.msg62704762#msg62704762

August 14, 2023
Zunami Protocol: $2.1 M
https://bitcointalk.org/index.php?topic=5267124.msg62704762#msg62704762

August 30, 2023
Exactly Protoco: $7.3 M
https://bitcointalk.org/index.php?topic=5267124.msg62769424#msg62769424

August 30, 2023
Magnate Finance: $6.4 M
https://bitcointalk.org/index.php?topic=5267124.msg62769424#msg62769424

September 05, 2023
Stake.com: $41 M
https://bitcointalk.org/index.php?topic=5267124.msg62804160#msg62804160

September 20, 2023
Harbour: $0,25 M
https://bitcointalk.org/index.php?topic=5267124.msg62875589#msg62875589

September 20, 2023
MBL Computer: $0,8 M
https://bitcointalk.org/index.php?topic=5267124.msg62875589#msg62875589

September 27, 2023
Mixin Network: $200 M
https://bitcointalk.org/index.php?topic=5267124.msg62908895#msg62908895

October 08, 2023
Galxe platform: $0,15 M
https://bitcointalk.org/index.php?topic=5267124.msg62980429#msg62980429

October 11, 2023
Star arena: $0,274 M
https://bitcointalk.org/index.php?topic=5267124.msg62980886#msg62980886

October 12, 2023
Platypus Finance: $2 M
https://bitcointalk.org/index.php?topic=5267124.msg62983709#msg62983709

November 01, 2023
Onyx Protocol: $2.1 M
https://bitcointalk.org/index.php?topic=5267124.msg63089287#msg63089287

November 08, 2023
AstridFinance: $0.245 M
https://bitcointalk.org/index.php?topic=5267124.msg63123860#msg63123860

November 15, 2023
Raft: $3.3 M
https://bitcointalk.org/index.php?topic=5267124.msg63163154#msg63163154

November 23, 2023
KyberSwap: $48 M
https://bitcointalk.org/index.php?topic=5267124.msg63206715#msg63206715

December 06, 2023
Florence Finance: $1.45 M
https://bitcointalk.org/index.php?topic=5267124.msg63278918#msg63278918

December 14, 2023
OKX Dex: $0.37 M
https://bitcointalk.org/index.php?topic=5267124.msg63320564#msg63320564

December 28, 2023
Across Protocol: $0.88 M
https://bitcointalk.org/index.php?topic=5267124.msg63401295#msg63401295

December 31, 2023
Orbit Chain's bridge: $81.5 M
https://bitcointalk.org/index.php?topic=5267124.msg63433078#msg63433078

December 31, 2023
Levana Protocol$1M
https://bitcointalk.org/index.php?topic=5267124.msg63434618#msg63434618

2024 DeFi hacks. Continuation

January 3, 2024
Radiant Capital $4.4M
https://bitcointalk.org/index.php?topic=5267124.msg63438775#msg63438775

January 17, 2024
Socket $3.3M
https://bitcointalk.org/index.php?topic=5267124.msg63512194#msg63512194

January 24, 2024
Concentric.fi $1.6M
https://bitcointalk.org/index.php?topic=5267124.msg63549538#msg63549538

January 25, 2024
Gamee $7M
https://bitcointalk.org/index.php?topic=5267124.msg63555379#msg63555379

February 23,2024
Sky Mavis Co-Founder Jeffrey Zirlin’s $9.7M
https://bitcointalk.org/index.php?topic=5267124.msg63709404#msg63709404

February 28,2024
MicroStrategy’s X account hacked $0.42M
https://bitcointalk.org/index.php?topic=5267124.msg63730629#msg63730629

March 02,2024
SenecaUSD $6.5M
https://bitcointalk.org/index.php?topic=5267124.msg63748555#msg63748555

March 06,2024
OrdiZK Team $1.4M
https://bitcointalk.org/index.php?topic=5267124.msg63765847#msg63765847

March 06,2024
WOOFi $8M
https://bitcointalk.org/index.php?topic=5267124.msg63767952#msg63767952

April 03,2024
Web3 gaming platform Munchables $62.5M
https://bitcointalk.org/index.php?topic=5267124.msg63895187#msg63895187

April 10,2024
Prisma Finance $11M
https://bitcointalk.org/index.php?topic=5267124.msg63927999#msg63927999



to be continued..

__
hacked DeFi bridges
https://gist.github.com/cwhinfrey/9fd1bbc31bbcff08fca242b90c7f875d


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 04, 2023, 07:12:48 PM
reserve


Title: Re: DeFi hacks [history]
Post by: safar1980 on February 10, 2023, 02:10:12 PM
CoW Swap hacker milks over 550 BNB using ‘solver’ exploit
Security firm PeckShield reported that the hacker successfully drained roughly 551 BNB off CoW Swap into Tornado Cash, which was worth around $181,600 at the time of writing.

https://cointelegraph.com/news/cow-swap-hacker-milks-over-550-bnb-using-solver-exploit


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 11, 2023, 03:21:29 PM
https://thenewscrypto.com/defi-protocol-dforce-exploited-of-3-65-million-by-hacker/
DeFi Protocol dForce Exploited of $3.65 Million by Hacker
"Initial funding of 0.99ETH was transmitted from the DeFi system RAILGUN Project.
dForce said the assault, which affected just its wstETH/ETH-Curve vault, had been stopped.
To the tune of $3.6 million in cryptocurrency, an assault on the reentrancy vulnerability of the decentralized finance (DeFi) protocol dForce has resulted in the theft of funds. Curve Finance is an automated market maker (AMM) platform. That uses the Arbitrum and Optimism blockchains, and its vault was the target of the hack."


Title: Re: DeFi hacks [history]
Post by: safar1980 on February 22, 2023, 01:37:24 PM
Norwegian Authorities Seize $5.9M From Crypto Game Axie Infinity Hack
The economic crime unit said it is the biggest crypto seizure ever made by Norwegian police.
https://www.coindesk.com/policy/2023/02/16/norwegian-authorities-seize-59m-from-crypto-game-axie-infinity-hack/


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 22, 2023, 02:26:21 PM
https://www.coindesk.com/markets/2023/02/16/usp-stablecoin-loses-dollar-peg-as-defi-protocol-platypus-suffers-85m-attack/
USP Stablecoin Loses Dollar Peg as DeFi Protocol Platypus Suffers $8.5M Attack
"The flash loan attack caused Platypus Finance’s native stablecoin to fall to 48 cents from $1. The potential loss is $8.5 million, according to blockchain security firm CertiK.
Decentralized finance (DeFi) protocol Platypus Finance suffered a flash-loan attack on Thursday, blockchain security firm CertiK tweeted. The potential loss in the exploit is $8.5 million.
Platypus USD (USP), the protocol’s stablecoin, lost its price peg to the dollar as a result of the exploit, falling to 48 cents from its $1 anchor, according to CoinGecko.
"For now all operations are paused until we get more clarity," a Platypus team member posted in the protocol's Discord server."


Title: Re: DeFi hacks [history]
Post by: safar1980 on March 01, 2023, 02:01:10 PM
Suspects in $9M DeFi platform Platypus attack arrested in France

French police have arrested suspects alleged to have stolen over $8 million from the decentralized finance (DeFi) platform Platypus Finance.
https://coingeek.com/suspects-in-9m-defi-platform-platypus-attack-arrested-in-france/


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 01, 2023, 02:17:31 PM
https://cointelegraph.com/news/700-000-drained-from-bnb-chain-based-defi-protocol-launchzone
$700,000 drained from BNB Chain-based DeFi protocol LaunchZone
BNB Chain-based DeFi protocol LaunchZone claims an exploit led to $700,000 of funds being drained from its liquidity pool, with its native token plunging in value.
"$700,000 worth of funds has been drained from BNB Chain-based decentralized finance (DeFi) protocol LaunchZone, with the project alleging an attacker carried out an exploit.

Details remain scarce after more than 80% of funds in the LaunchZone liquidity pool were drained on Feb. 27. A message on the project’s official Telegram group warned users not to buy tokens until more information has been gathered:"



Title: Re: DeFi hacks [history]
Post by: safar1980 on March 05, 2023, 09:33:14 AM
Arbitrum DEX ArbiSwap Rug Pulls Users for Over $100K
ArbiSwap’s native ARBI tokens fell from $1.5 to a fraction of a cent in the past 24 hours.
https://www.coindesk.com/tech/2023/03/02/arbitrum-dex-arbiswap-rug-pulls-users-for-over-100k/


Title: Re: DeFi hacks [history]
Post by: Daltonik on March 07, 2023, 07:00:43 AM
The next month of 2023 has ended, during which 7 Defi projects were attacked by hackers: BonqDAO, Orion, dForce Network, Platypus Finance, Hope Finance, Flexible, LaunchZone.
According to Defi Llama for the month of February 2023, Defi projects lost a total of $21.41 million in assets.



Title: Re: DeFi hacks [history]
Post by: mulia sabee on March 07, 2023, 02:10:14 PM
DeFi financial system has been compared to the wild west, but that's how a new story begins.
2020
18 February 2020
Arbs Exploit DeFi to Make $900k in Seconds; bZx hack.
https://thedefiant.substack.com/p/arbs-exploit-defi-to-make-900k-in

21 February 2020
Fulcrum had a $2.5M vulnerability over a month ago and still hasn’t told anyone
https://medium.com/@1inch.exchange/yes-we-hacked-bzx-fulcrum-but-one-month-ago-3f7e5c437ee3

19 April 2020
Multicoin Capital-backed DeFi protocol dForce loses ~$25M total locked value in an exploit
https://www.theblockcrypto.com/amp/linked/62346/multicoin-capital-backed-defi-protocol-dforce-loses-25m-total-locked-value-in-an-exploit

21 April 2020
Dforce return $ 25 million back !!!
https://twitter.com/lawmaster/status/1252483198115774464

19 May 2020
BlockFi Experiences Data Breach – Crypto Lending Hack
https://defirate.com/blockfi-hack/

18 Jun 2020
A cryptocurrency bug put $545,000 of DeFi funds at risk
https://decrypt.co/32720/a-cryptocurrency-bug-put-545000-of-defi-funds-at-risk

20 Jun 2020
Balancer hacked ~ $ 500,000
https://medium.com/balancer-protocol/incident-with-non-standard-erc20-deflationary-tokens-95a0f6d46dea

14 Jul 2020
How BZRX Uniswap Listing Made One Trader $550K In 30 Mins
https://cryptopotato.com/how-bzrx-uniswap-listing-made-one-trader-550k-in-30-mins/

5 August 2020
Blatant “bug” led to $370,000 DeFi hack, say experts. Opyn hack.
https://decrypt.co/37671/blatant-bug-led-to-370000-defi-hack-say-expert

7 September 2020
$250k Soft Yearn (SYFI)
https://cointelegraph.com/news/jackpot-user-turns-200-into-250k-thanks-to-a-buggy-defi-protocol

13 September 2020
$8M  bZx protocol
https://www.theblockcrypto.com/post/77656/defi-protocol-bzx-attacked-lost-8-million-faulty-code

14 September 2020
$8M returned  bZx protocol
https://twitter.com/bZxHQ/status/1305496675474006017

29 September 2020
$15 Million  Hackers Drain $15 Million From ‘Unreleased’ Yearn Finance Project
https://bitcointalk.org/index.php?topic=5267124.msg55282297#msg55282297

29 September 2020
$10 Million  $10 Million Ethereum Vulnerability Patched by Whitehat Hacker
https://fullycrypto.com/10-million-ethereum-vulnerability-patched-by-whitehat-hacker

11 October 2020
wLEO Was Hacked on Ethereum. Damage $ 42,000
https://bitcointalk.org/index.php?topic=5267124.msg55365482#msg55365482

26 October 2020
Harvest Finance- 23 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55455370#msg55455370

12 November 2020
Akropolis- 2 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55591391#msg55591391

14 November 2020
Value DeFi 6 million US dollars
https://twitter.com/value_defi/status/1327660571592773632

17 November 2020
Origin Defi Protocol 7 million US dollars
https://news.bitcoin.com/origin-defi-protocol-suffers-massive-flash-loan-attack-ousd-stablecoin-value-plunges-85/

22 November 2020
DeFi Protocol Pickle Finance 20 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55653413#msg55653413

14 December 2020
Nexus Mutual  8 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg55829590#msg55829590

18 December 2020
Warp Finance 7,7 million US dollars
https://www.theblockcrypto.com/linked/88415/defi-warp-finance-attacked-lost-7-7-million-stablecoins

28 December 2020
DeFi protocol Cover 5 million US dollars
https://www.theblockcrypto.com/post/89368/defi-protocol-cover-exploited-attackers-minted-at-least-40-quintillion-tokens

___

https://decrypt.co/54128/hackers-stole-3-8-billion-in-cryptocurrency-hacks-in-2020
Hackers Stole $3.8 Billion in Cryptocurrency Hacks in 2020

Information disclosure and analysis of major hacks in the DeFe ecosystem
https://github.com/yearn/yearn-security/tree/master/disclosures
__

2021

February 4, 2021
Yearn.finance 9 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56271047#msg56271047

February 14, 2021
Cream Finance 37,5 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56458888#msg56458888

February 28, 2021
Furucombo 14 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56458888#msg56458888

March 4, 2021
Meerkat Finance (Binance Smart Chain) 32 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56490389#msg56490389

March 5, 2021
PAID Network (PAID) 3 million US dollars
https://bitcointalk.org/index.php?topic=5267124.msg56498767#msg56498767

March 8, 2021
DODO DEX 2 million US dollars, $1.89 million has been recovered
https://bitcointalk.org/index.php?topic=5267124.msg56530098#msg56530098

March 15, 2021
Roll 3000 ETH
https://cryptoslate.com/hackers-steal-3000-eth-from-roll-causing-massive-price-dumps-of-nearly-100/

March 17, 2021
Iron Finance $170,000  
https://bitcointalk.org/index.php?topic=5267124.msg56605708#msg56605708

March 20, 2021
TurtleDex  9000 BNB =2.4M $  
https://bitcointalk.org/index.php?topic=5267124.msg56617046#msg56617046

April 4, 2021
Force DAO - $367 000
https://bitcointalk.org/index.php?topic=5267124.msg56864596#msg56864596

April 19, 2021
EasyFi DeFi protocol - 6M $
https://bitcointalk.org/index.php?topic=5267124.msg56835129#msg56835129

May 2, 2021
Spartan Protocol -30M
https://bitcointalk.org/index.php?topic=5267124.msg56919497#msg56919497

May 9, 2021
Rari Capital  -10M
https://bitcointalk.org/index.php?topic=5267124.msg57018020#msg57018020

May 12, 2021
(DeFi) protocol xToken  -24.5M
https://bitcointalk.org/index.php?topic=5267124.msg56997287#msg56997287

May 20, 2021
Pancake Bunny  -200M
https://bitcointalk.org/index.php?topic=5267124.msg57050581#msg57050581

May 20, 2021
Venus Incident Report
https://bitcointalk.org/index.php?topic=5267124.msg57054439#msg57054439

May 27, 2021
Wild Credit $ 637K.  All funds were returned to the protocol.
https://bitcointalk.org/index.php?topic=5267124.msg57106288#msg57106288

May 28, 2021
DeFi project BurgerSwap - $ 7.2M
https://bitcointalk.org/index.php?topic=5267124.msg57106299#msg57106299

May 30, 2021
DeFi project Belt Finance - $ 6.2M
https://bitcointalk.org/index.php?topic=5267124.msg57120256#msg57120256

Jyne 21, 2021
DeFi project Impossible finance - $ 0.5M
https://bitcointalk.org/index.php?topic=5267124.msg57284357#msg57284357

Jyne 28, 2021
Safe Dollar - $ 0.25M
https://bitcointalk.org/index.php?topic=5267124.msg57340075#msg57340075

July 1, 2021
WhaleFarm- $ 2M
https://bitcointalk.org/index.php?topic=5267124.msg57367513#msg57367513

July 11, 2021
ChainSwap - $8M
https://bitcointalk.org/index.php?topic=5267124.msg57439162#msg57439162

July 15, 2021
Bondly Finance - Token Price Tanks
https://bitcointalk.org/index.php?topic=5267124.msg57473981#msg57473981

July 16, 2021
THORChain -2500 ETH
https://bitcointalk.org/index.php?topic=5267124.msg57471971#msg57471971

August 4, 2021
Popsicle Finance -25M
https://bitcointalk.org/index.php?topic=5267124.msg57613393#msg57613393

August 10, 2021
PolyNetwork -600M
https://bitcointalk.org/index.php?topic=5267124.msg57662150#msg57662150

August 12, 2021
Poly Network Hacker Returns $342 Million
https://bitcointalk.org/index.php?topic=5267124.msg57677686#msg57677686

August 13, 2021
Maze Protocol -4M
https://bitcointalk.org/index.php?topic=5267124.msg57691964#msg57691964

August 14, 2021
DAO Maker -7M
https://bitcointalk.org/index.php?topic=5267124.msg57677718#msg57677718

August 19, 2021
Ethereum DEX Avoids $350M DeFi Hack
https://bitcointalk.org/index.php?topic=5267124.msg57731551#msg57731551

August 29, 2021
xToken- 4,5M
https://bitcointalk.org/index.php?topic=5267124.msg57820934#msg57820934

August 30, 2021
Cream Finance-19M
https://bitcointalk.org/index.php?topic=5267124.msg57820934#msg57820934

August 31, 2021
Aurory Project-0,5M
https://bitcointalk.org/index.php?topic=5267124.msg57835544#msg57835544

September 4, 2021
DAO Maker-4M
https://bitcointalk.org/index.php?topic=5267124.msg57857298#msg57857298

September 10, 2021
AFKSystems -12M
https://bitcointalk.org/index.php?topic=5267124.msg57910886#msg57910886

September 12, 2021
Zabu Finance -3,2M
https://bitcointalk.org/index.php?topic=5267124.msg57923560#msg57923560     !

September 17, 2021
MISO IDO platform (Hack and return of coins) -865 ETH (3M)
https://bitcointalk.org/index.php?topic=5267124.msg57957934#msg57957934  

September 20, 2021
pNetwork Protocol -$12M
https://bitcointalk.org/index.php?topic=5267124.msg57980467#msg57980467  

September 21, 2021
Vee.Finance  -$35M
https://bitcointalk.org/index.php?topic=5267124.msg57995378#msg57995378

September 30, 2021
Compound bug  -$80M
https://bitcointalk.org/index.php?topic=5267124.msg58062585#msg58062585

October 15, 2021
Indexed Finance -$16M
https://bitcointalk.org/index.php?topic=5267124.msg58188360#msg58188360

October 20, 2021
PancakeHunny -$1,9M
https://bitcointalk.org/index.php?topic=5267124.msg58236768#msg58236768

October 27, 2021
Cream Finance -$130M
https://bitcointalk.org/index.php?topic=5267124.msg58283286#msg58283286

November 5, 2021
bZx -$55M
https://bitcointalk.org/index.php?topic=5267124.msg58355796#msg58355796

November 30, 2021
MonoXFinance $31 M
https://bitcointalk.org/index.php?topic=5267124.msg58586607#msg58586607

December 1, 2021
BadgerDAO $100 M
https://bitcointalk.org/index.php?topic=5267124.msg58599650#msg58599650

December 4, 2021
Polygon  801,601 MATIC tokens worth more than $2 million
https://bitcointalk.org/index.php?topic=5267124.msg58857717#msg58857717

December 8, 2021
8IGHT FINANCE- $1.75M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 11, 2021
Gelato-$26M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 13, 2021
Vulcan Forged-$140M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 21, 2021
Grim Finance  $30M
https://bitcointalk.org/index.php?topic=5267124.msg58790597#msg58790597

December 22, 2021
Visor Finance -$8.8M
https://bitcointalk.org/index.php?topic=5267124.msg58808603#msg58808603

December 27, 2021
Metaswap Gas (MGAS) 1,100 BNB
https://bitcointalk.org/index.php?topic=5267124.msg58909773#msg58909773

December 27, 2021
METADAO 800 Ether
https://bitcointalk.org/index.php?topic=5267124.msg58909773#msg58909773

____
Reports  2021 Hack
https://bitcointalk.org/index.php?topic=5267124.msg59405892#msg59405892


2022

January 1,2022
Tinyman -  the amount of hacking is unknown
https://bitcointalk.org/index.php?topic=5267124.msg58909773#msg58909773

January 11,2022
Lympo NFT platform-  $18.7 million
https://bitcointalk.org/index.php?topic=5267124.msg58968153#msg58968153

January 28,2022
Qubit Finance,  X-Bridge  $80M
https://bitcointalk.org/index.php?topic=5267124.msg59097768#msg59097768

February 2,2022
Wormhole   $326 M
https://bitcointalk.org/index.php?topic=5267124.msg59144112#msg59144112

February 4,2022
KLAYswap   $1,83 M
https://bitcointalk.org/index.php?topic=5267124.msg59153910#msg59153910

February 8,2022
DeFi Meter   $4,3 M
https://bitcointalk.org/index.php?topic=5267124.msg59189702#msg59189702

February 8,2022
DeFi QiDao Protocol  $13 M
https://bitcointalk.org/index.php?topic=5267124.msg59191163#msg59191163

February 11,2022
Dego  damage is assessed
https://bitcointalk.org/index.php?topic=5267124.msg59218259#msg59218259

March 03,2022
Treasure DAO $1,44 M
https://bitcointalk.org/index.php?topic=5267124.msg59412238#msg59412238

March 10,2022
Fantasm Finance $2.6 M
https://bitcointalk.org/index.php?topic=5267124.msg59484103#msg59484103

March 16,2022
DeFi Agave и Hundred Finance $11 M
https://bitcointalk.org/index.php?topic=5267124.msg59484103#msg59484103

March 18,2022
Rare Bears $800K
https://bitcointalk.org/index.php?topic=5267124.msg59705205#msg59705205

March 21,2022
Li Finance $600K
https://bitcointalk.org/index.php?topic=5267124.msg59594924#msg59594924

March 22,2022
OneRing Finance $2M
https://bitcointalk.org/index.php?topic=5267124.msg59615100#msg59615100

March 23,2022
Ronin sidechain $622M
https://bitcointalk.org/index.php?topic=5267124.msg59705205#msg59705205

April 1,2022
Bored Ape Yacht Club $0,549M
https://bitcointalk.org/index.php?topic=5267124.msg59717956#msg59717956

April 2,2022
Inverse Finance $15,6M
https://bitcointalk.org/index.php?topic=5267124.msg59738961#msg59738961

April 7,2022
WonderHero $320 000
https://bitcointalk.org/index.php?topic=5267124.msg59811006#msg59811006

April 8,2022
Starstream $4M
https://bitcointalk.org/index.php?topic=5267124.msg59827200#msg59827200

April 12,2022
Elephant Money $22M
https://bitcointalk.org/index.php?topic=5267124.msg59849629#msg59849629

April 18,2022
Beanstalk $182M
https://bitcointalk.org/index.php?topic=5267124.msg59913835#msg59913835

April 20,2022
Deus Finance $13.4M
https://bitcointalk.org/index.php?topic=5267124.msg59992176#msg59992176

April 28,2022
DEFI Lender Rari Capital $80M
https://bitcointalk.org/index.php?topic=5267124.msg60014661#msg60014661

May 31,2022
Mirror Protocol   $2M
https://bitcointalk.org/index.php?topic=5267124.msg60269928#msg60269928

May 4,2022
Yacht Club (BAYC)   $0,36M
https://bitcointalk.org/index.php?topic=5267124.msg60292687#msg60292687

June 7,2022
Maiar DEX $1,65M
https://bitcointalk.org/index.php?topic=5267124.msg60309763#msg60309763

June 8 ,2022
Interlayer Snafu   $20M
https://bitcointalk.org/index.php?topic=5267124.msg60320761#msg60320761

June 16 ,2022
Inverse Finance   $1,2M
https://bitcointalk.org/index.php?topic=5267124.msg60377788#msg60377788

June 24 ,2022
Harmony   $100M
https://bitcointalk.org/index.php?topic=5267124.msg60431403#msg60431403

June 30 ,2022
NFT marketplace Quixotic $0,1M
https://bitcointalk.org/index.php?topic=5267124.msg60485134#msg60485134

July 3 ,2022
Crema Finance $6M
https://bitcointalk.org/index.php?topic=5267124.msg60500284#msg60500284
refund
https://bitcointalk.org/index.php?topic=5267124.msg60525793#msg60525793

July 3 ,2022
OMNI protocol 1300 ETH
https://bitcointalk.org/index.php?topic=5267124.msg60550807#msg60550807

July 12 ,2022
Ethereum in Massive Phishing Attack $8M
https://bitcointalk.org/index.php?topic=5267124.msg60559895#msg60559895

July 19 ,2022
PREMINT $0,4M
https://bitcointalk.org/index.php?topic=5267124.msg60597872#msg60597872

July  24 ,2022
Audius $1,1M
https://bitcointalk.org/index.php?topic=5267124.msg60639264#msg60639264

July 28 ,2022
Nirvana $3,5M
https://bitcointalk.org/index.php?topic=5267124.msg60647575#msg60647575

August 2 ,2022
Nomad Bridge $150M
https://bitcointalk.org/index.php?topic=5267124.msg60676431#msg60676431

Over $36 Million Bacк
https://bitcointalk.org/index.php?topic=5267124.msg60727075#msg60727075

August 9 ,2022
Protocol Curve $0,57M
https://bitcointalk.org/index.php?topic=5267124.msg60727075#msg60727075

August 30 ,2022
OptiFi $0,661M
https://bitcointalk.org/index.php?topic=5267124.msg60898572#msg60898572


September 1 ,2022
Kyber Network $0,265M
https://bitcointalk.org/index.php?topic=5267124.msg60859039#msg60859039

September 7 ,2022
Nereus Finance $0,37M
https://bitcointalk.org/index.php?topic=5267124.msg60898716#msg60898716

September 8 ,2022
New Free DAO $1,25M
https://bitcointalk.org/index.php?topic=5267124.msg60936613#msg60936613

September 20 ,2022
Wintermute $160M
https://bitcointalk.org/index.php?topic=5267124.msg60974088#msg60974088

September 27 ,2022
address exploit $0,95M
https://bitcointalk.org/index.php?topic=5267124.msg61024467#msg61024467

October 02 ,2022
Transit Swap $21M and return $18.9M
https://bitcointalk.org/index.php?topic=5267124.msg61066552#msg61066552

October 07 ,2022
BNB BRIDGE $80M
https://bitcointalk.org/index.php?topic=5267124.msg61079836#msg61079836

October 11 ,2022
DeFi Service Mango $100M
https://bitcointalk.org/index.php?topic=5267124.msg61107825#msg61107825
Mango exploiter (Avraham Eisenberg) arrested
https://bitcointalk.org/index.php?topic=5267124.msg61508069#msg61508069

October 12 ,2022
TempleDAO $2,3M
https://bitcointalk.org/index.php?topic=5267124.msg61107825#msg61107825

October 18 ,2022
Celo Protocol Moola Market $10M recovered over 93% funds
https://bitcointalk.org/index.php?topic=5267124.msg61148417#msg61148417

October 26 ,2022
Decentralized exchange QuickSwap exploited for $220K
https://bitcointalk.org/index.php?topic=5267124.msg61188392#msg61188392

October 28 ,2022
Team Finance DeFi protocol  $15.8 million
https://bitcointalk.org/index.php?topic=5267124.msg61199142#msg61199142

November 02 ,2022
decentralized Rubic exchange $1.2 million
https://bitcointalk.org/index.php?topic=5267124.msg61226574#msg61226574

November 02 ,2022
Deribit crypto exchange $28M
https://bitcointalk.org/index.php?topic=5267124.msg61226602#msg61226602

November 04 ,2022
DeFi Protocol Solend  $1.26M
https://bitcointalk.org/index.php?topic=5267124.msg61238487#msg61238487

November 15 ,2022
DFX Finance Hacked $4M
https://bitcointalk.org/index.php?topic=5267124.msg61301029#msg61301029

November 15 ,2022
DeFi project Flare on hacked. $17.9 million
https://bitcointalk.org/index.php?topic=5267124.msg61301029#msg61301029

December 02 ,2022
Ankr DeFi protocol  $15 million
https://bitcointalk.org/index.php?topic=5267124.msg61381777#msg61381777

December 11 ,2022
lodestar finance $7M
https://bitcointalk.org/index.php?topic=5267124.msg61426658#msg61426658

December 17 ,2022
Solana DeFi Exchange Raydium $2M
https://bitcointalk.org/index.php?topic=5267124.msg61457362#msg61457362

December 25 ,2022
Rubic DEX $1.4M
https://bitcointalk.org/index.php?topic=5267124.msg61510118#msg61510118

December 26 ,2022
Defrost Finance  hack & returned $12M
https://bitcointalk.org/index.php?topic=5267124.msg61510118#msg61510118

_______________________________________________________________

2023 DeFi hacks. Continuation
https://bitcointalk.org/index.php?topic=5267124.msg61709519#msg61709519

_______________________________________________________________

Report for 4 months 2022
https://bitcointalk.org/index.php?topic=5267124.msg60045276#msg60045276

https://cryptosec.info/defi-hacks/
https://rekt.news/


Russian
https://bitcointalk.org/index.php?topic=5227888.0

The benefit of using DeFi on new chains like CNDL and HBAR is that these chains are using EVM contracts that are tried and tested. DApps are just porting their code over to the new chains. It's when you get experimental DeFi stuff where things get hacked most of the time, or they are pretend hacks and real exit scams by the devs.


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 08, 2023, 03:14:29 PM
https://beincrypto.com/hacker-returns-stolen-funds-defi-lending-tender-fi/
White Hat Hacker Rewarded $97,000, Returns Stolen Funds to DeFi Lending Platform Tender.fi
The hacker behind the exploit of the decentralized finance lending platform Tender.fi has returned the stolen funds for a $97,000 bounty reward in Ether.
DeFi lending platform Tender.fi sees $1.59 million of assets drained by an alleged white hat hacker taking advantage of a misconfigured oracle.
According to the DeFi data analytics platform DefiLlama, the total value hacked in DeFi amounts to more than $5 billion.


Title: Re: DeFi hacks [history]
Post by: safar1980 on March 10, 2023, 04:11:08 PM
On March 9, Hedera successfully disabled IP proxies, cutting off network access.
The network’s token, Hedera (HBAR), has dropped 9% in the previous 24 hours.
The developers of the Hedera Hashgraph distributed ledger have revealed that some tokens from the network’s liquidity pool were stolen due to a smart contract vulnerability on the Hedera Mainnet. The hacker, according to Hedera, went after tokens in DEXs’ liquidity pools that used code adapted from Ethereum’s Uniswap v2 and deployed on its Hedera Token Service.
https://thenewscrypto.com/hacker-steals-tokens-from-hedera-exploiting-smart-contract-vulnerability/


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 10, 2023, 04:39:24 PM
https://thesis.neworder.network/#defi-landscape-consolidation-of-power-amongst-a-few-dominant-players
"Even as the number of DeFi applications has increased to around 1400 dapps, the top five Dapps still control a sizable portion of the total market. This occurrence is largely due to certain applications dominating specific sectors within the DeFi market. For example, Uniswap is the dominant player in the decentralized exchange (DEX) market, holding a market share of 59% by volume, an increase from 43.2% since the bear market. This pattern of dominance can be seen across other categories as well, with Lido leading in the liquid staking market, dYdX in the derivatives market, and MakerDAO in the lending and borrowing market. As most demand is concentrated among a few applications, these apps have an incentive to build out app-specific blockchains in order to extract as much value as possible from the blockchain and into the application itself."


Title: Re: DeFi hacks [history]
Post by: safar1980 on March 13, 2023, 11:04:22 AM
Euler Finance was exploited in a flash loan attack that drained hundreds of millions of decentralized stablecoins and synthetic ERC-20 tokens.
Ethereum-based noncustodial lending protocol Eurler finance faced a flash loan attack on March 13, with the attacker managing to steal millions in Dai, staked Ether (StETH) and wrapped Bitcoin (WBTC).According to on-chain data, as per the last update, the exploiter carried out multiple transactions, stealing nearly $196 million. The ongoing attack has already become the largest hack of 2023.
https://cointelegraph.com/news/euler-finance-hacked-for-over-195m-in-a-flash-loan-attack


Title: Re: DeFi hacks [history]
Post by: FP91G on March 15, 2023, 10:16:34 AM
The hacker committed a $196 million flash loan attack on the Ethereum-based lending protocol on March 13.
Ethereum-based noncustodial lending protocol Euler Finance is trying to cut a deal with the exploiter that stole millions from its protocol, demanding the hacker returns 90% of the funds they stole within 24 hours or face legal consequences.
https://cointelegraph.com/news/euler-finance-s-offer-to-hacker-keep-20m-or-face-the-law


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 15, 2023, 12:18:48 PM
https://coinmarketcap.com/headlines/news/peopledao-hacked-via-google-sheets/
PeopleDAO hacked via Google Sheets, $120,000 worth of ether stolen
"PeopleDAO, a group formed to buy a copy of the U.S. Constitution, has lost 76.5 ETH ($120,000) to a social engineering hack on March 6 that targeted the project’s monthly contributor payout form on Google Sheets.

A combination of errors led to the theft, according to the project team. First, the accounting lead mistakenly shared a link to the payout form with edit access to a public channel on the project’s Discord Server. The hacker was able to use this edit access on the form to insert their address and a 76.5 ETH payment. The hacker then made this row invisible on the form."


Title: Re: DeFi hacks [history]
Post by: safar1980 on March 16, 2023, 09:19:07 AM
For anyone who gets affected by the #Euler hack, watch this:
Someone(0x2a) sends a message to the hacker saying his life-saving (78 $ETH) is in @eulerfinance
The hacker then sends him 100 $ETH.
If 0x2a is being honest, it made extra 22 $ETH back.
https://twitter.com/ScopeProtocol/status/1636215381126938624?


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 17, 2023, 10:45:43 AM
For anyone who gets affected by the #Euler hack, watch this:
Someone(0x2a) sends a message to the hacker saying his life-saving (78 $ETH) is in @eulerfinance
The hacker then sends him 100 $ETH.
If 0x2a is being honest, it made extra 22 $ETH back.
https://twitter.com/ScopeProtocol/status/1636215381126938624?

A good way to get your coins back is by chatting with a hacker on the blockchain:
https://etherscan.io/tx/0xbe21a9719a4f89f7dc98419f60b247d69780b569cd8869c0031aae000f98cf17
This message was in the transaction signature:
"Please consider returning 90%/80%. I'm just a user that only had 78 wstETH as my life savings deposited into Euler, I'm not whale or millionaire. You can't imagine the mess I'm into right now, completely destroyed. I'm pretty sure 20M is already life changing for you and you'll bring back joy to a lot of affected people."

Euler Finance Exploiter 2
https://etherscan.io/address/0xb66cd966670d962c227b3eaba30a872dbfb995db

A lot of correspondence in the blockchain and a lot of begging.


Title: Re: DeFi hacks [history]
Post by: o48o on March 17, 2023, 04:18:52 PM
For anyone who gets affected by the #Euler hack, watch this:
Someone(0x2a) sends a message to the hacker saying his life-saving (78 $ETH) is in @eulerfinance
The hacker then sends him 100 $ETH.
If 0x2a is being honest, it made extra 22 $ETH back.
https://twitter.com/ScopeProtocol/status/1636215381126938624?
Ironically that person who got back 100eth instead of 78 is a criminal If he/she spends a dime from that that extra eth.

Weirdly i wouldn't even know where should it be returned. I might ask consultation from police




Title: Re: DeFi hacks [history]
Post by: zasad@ on March 18, 2023, 06:42:55 AM
For anyone who gets affected by the #Euler hack, watch this:
Someone(0x2a) sends a message to the hacker saying his life-saving (78 $ETH) is in @eulerfinance
The hacker then sends him 100 $ETH.
If 0x2a is being honest, it made extra 22 $ETH back.
https://twitter.com/ScopeProtocol/status/1636215381126938624?
Ironically that person who got back 100eth instead of 78 is a criminal If he/she spends a dime from that that extra eth.

Weirdly i wouldn't even know where should it be returned. I might ask consultation from police



There is an error in the tweet, the 0x2Af wallet returned the excess 12 ETH to the project treasury and wrote about it on the blockchain. The police won't ask him questions.
https://etherscan.io/tx/0xbb450229bf8eaf62d41e62b8d4e6495f1d952a10da0ef72bf048c376c56719e1
"I was affected by the recent Euler Finance hack and fortunately, I received back 100 ETH from the hacker, which is 12 ETH more than my original deposit of ~78 wstETH. With this transaction, I'm returning the extra 12 ETH that doesn't belong to me to the Euler Finance Deployer."

___
I just don't understand why 0x2Af returned 12 ETH. 78+12 =90 not 100, it should return 22 ETH.
Or 78 wstETH = 88 ETH


Title: Re: DeFi hacks [history]
Post by: GEMIN_M4 on March 18, 2023, 09:00:57 AM
It's amazing that in just 1 year there have been 9 attacks on decentralized finance. it is a challenge for developers to fix the system to cover the loopholes that could be harmful. also to realize a new and better security system.
Yet, we are been advice to move out of centralized exchanges, the losses from centralized exchanges is far more higher than all the losses of defi in combine but still, decentralised finance still have to get better with their security, hackers keeps taking advantage of projects is not encouraging for crypto space altogether, this is why Bitcoin is a much safer digital currency than the others.


Title: Re: DeFi hacks [history]
Post by: safar1980 on March 18, 2023, 06:57:50 PM
hacker returned 3000 ETH to Euler
https://etherscan.io/tx/0x20f89e9f029c1552ac1b1e2346c8305924ac76d9252a84c91a2b3157c669ab6a
https://etherscan.io/tx/0xe57b44752efa79fc06bba4e269738a27add7adb13603c4aa90e0437151e62023
https://etherscan.io/tx/0xc07feca033ff90cfcbeeac71d01daa8898e2cc4a9a22e9704e383740ab0da24a

Euler replied
https://etherscan.io/tx/0xc72d8b553651500c88730573a9839f230a98273dba16d1aad2496c8916ab1d04


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 22, 2023, 01:58:29 PM
Euler Finance Hack Contacted Developers
https://twitter.com/CertiKAlert/status/1638008865055813632?
"Lending platform @eulerfinance received on-chain messages earlier today from the exploiter.
The exploiter seeks to come to an agreement and have "no intention of keeping what is not theirs."
Their full message and the Euler response seen below 👇"
https://i.ibb.co/x1yYLh1/Frtg-Cmj-WIAMIm-HZ.jpg (https://ibb.co/ZB3SXdB)
https://forklog.com/news/vzlomshhik-euler-finance-vyshel-na-svyaz-s-razrabotchikami
"Euler representatives responded to the message and offered to contact via EOA or email."


Title: Re: DeFi hacks [history]
Post by: safar1980 on March 27, 2023, 02:48:07 PM
Euler Token Gains 28% as Exploiter returns 58,000 Stolen ETH (https://beincrypto.com/euler-token-gains-28-exploiter-returns-58k-eth/)
Euler Finance exploiter returned over 58,000 ETH on March 25 to the DeFi protocol.
Arkham Intelligence reported that the hacker still held over $100 million worth of the stolen assets.



Title: Re: DeFi hacks [history]
Post by: zasad@ on March 29, 2023, 01:42:00 PM
https://blockchain.news/news/kokomo-finance-accused-of-4m-exit-scam
"Kokomo Finance, an open-source and noncustodial lending protocol on Optimism, has been accused of an exit scam worth $4 million. The protocol allegedly plucked user funds via a smart contract loophole, causing the Kokomo Finance token to plummet 95% in value in a matter of minutes. Blockchain security firm CertiK alerted its followers to the situation in a tweet on March 26.
According to CertiK, the deployer of the KOKO token attacked the smart contract code of a wrapped Bitcoin token, cBTC, by resetting the reward speed and pausing the borrow function. An address beginning with "0x5a2d.." then approved the new cBTC smart contract to spend over 7000 Sonne Wrapped Bitcoin (So-WBTC). The attacker then called another command to swap the So-WBTC to the 0x5a2d address, which produced a $4 million profit, according to the security firm."


Title: Re: DeFi hacks [history]
Post by: Daltonik on March 30, 2023, 06:34:21 AM
Euler Token Gains 28% as Exploiter returns 58,000 Stolen ETH (https://beincrypto.com/euler-token-gains-28-exploiter-returns-58k-eth/)
Euler Finance exploiter returned over 58,000 ETH on March 25 to the DeFi protocol.
Arkham Intelligence reported that the hacker still held over $100 million worth of the stolen assets.

Subsequently, on March 28, the hacker returned the balance of 5 million DAi, thereby reimbursing almost all the damage done to the Euler Finance team, which incidentally caused a small pump EUL

https://twitter.com/PeckShieldAlert/status/1640585382843785216
https://etherscan.io/tx/0x92f3110e3239507b4c1d60ffdde14fbae443436f9cb33070383a7a3d9a2b4099

https://i.imgur.com/XA9Brr7.png


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 30, 2023, 01:30:15 PM
https://ambcrypto.com/safemoon-sfm-hackers-say-relax-as-dex-loses-millions-in-exploit/

DEFISafeMoon [SFM]: Hackers say ‘relax’ as DEX loses millions in exploit

Decentralized exchange SafeMoon was exploited to the tune of $8.9 million earlier today.
The hackers took advantage of a public burn bug to drain one of the DEX’s liquidity pools.
Decentralized Finance exchange SafeMoon [SFM] has lost millions of dollars following a compromised liquidity pool. which allowed hackers to exploit the BNB Chain-based DEX. The exploit took place on 29 March and drained $8.9 million from the liquidity pool.


Title: Re: DeFi hacks [history]
Post by: safar1980 on April 04, 2023, 11:43:04 AM
Euler Finance hacker returns ‘all of the recoverable funds’  (https://coinjournal.net/news/euler-finance-hacker-returns-all-of-the-recoverable-funds/)
Euler Finance has announced a total possible recovery of all the stolen funds.
The recovery ends the $1 million bounty that Euler Labs had issued.
The total recovery comes after Euler Finance convinced the hacker to return the money.
Euler Finance has today announced that the total refundable funds have been returned twenty-three days after the protocol was hacked.



Title: Re: DeFi hacks [history]
Post by: zasad@ on April 05, 2023, 10:13:18 AM
https://www.blockhead.co/2023/04/04/exploiter-front-runs-25m-from-mev-bots-using-ethereum-validator/
Exploiter Front Runs $25M From MEV Bots Using Ethereum Validator
"Twitter reminds us that the MEV exploit in the code is a feature, not a bug
In smart contract land, it is well known that if there's a vulnerability in the code, it is a feature and not a bug. One sophisticated exploiter albeit with malicious intent had successfully deployed an exploit using an Ethereum validator and a Flashbots MEV-relay to drain a group of MEV bots for a total of $25 million at time of writing.

The exploiter planned the reverse-sandwich attack by essentially honey potting a group of top performing Maximal Extractable Value (MEV) bots after verifying that these bots used his validator on low-liquidity pools throughout an 18-day operation."
https://twitter.com/Mudit__Gupta/status/1642844239733071872?s=19


Title: Re: DeFi hacks [history]
Post by: gaston castano on April 05, 2023, 12:28:30 PM
The hacker committed a $196 million flash loan attack on the Ethereum-based lending protocol on March 13.
Ethereum-based noncustodial lending protocol Euler Finance is trying to cut a deal with the exploiter that stole millions from its protocol, demanding the hacker returns 90% of the funds they stole within 24 hours or face legal consequences.
https://cointelegraph.com/news/euler-finance-s-offer-to-hacker-keep-20m-or-face-the-law


so they demand 90% of the total assets stolen, do those who demand know who did the theft, or is there some kind of address tracking where the hackers are?
and if that's the case I think the thieves will have a hard time selling the asset since their address has been tagged. :-\


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 05, 2023, 02:23:16 PM

so they demand 90% of the total assets stolen, do those who demand know who did the theft, or is there some kind of address tracking where the hackers are?
and if that's the case I think the thieves will have a hard time selling the asset since their address has been tagged. :-\

I don't think Ethereum is very difficult to sell or exchange for other coins right now. Euler Finance returned their 90% of the assets, then they will restart the protocol and fix the bugs.

___
https://twitter.com/peckshieldalert/status/1642717704934273030?
In Mar. 2023, $10.9M worth of #NFTs were stolen, representing a 32.72%% decrease from the previous month
Half of the stolen NFTs were quickly sold on marketplaces within 2 hours
 ~74.9% of the stolen NFTs were first sold on @blur_io,  followed by 19.5% on @opensea
https://i.ibb.co/68PGkjg/Fswaa-O-a-EAAEjw7.jpg (https://ibb.co/C674fRh)


Title: Re: DeFi hacks [history]
Post by: errorcode99 on April 05, 2023, 07:52:24 PM
PeckShield 'Team of leading cryptocurrency security researchers', unveils the alleged design of the attack on the Orion Protocol. Meanwhile, his team said it was only internal funds that were at risk. Orion Protocol was hacked for $3 million thanks to a well-known bug: PeckShield According to a statement shared by a PeckShield representative on Twitter, Orion Protocol, the popular liquidity engine for CEX and DEX, came under a hacker attack.


Title: Re: DeFi hacks [history]
Post by: Daltonik on April 08, 2023, 09:46:08 AM
CertiK Analysis presented a report on how much crypto projects lost in Q1 2023.
According to their data, losses of Web3 crypto projects are estimated at $320 million as a result of 207 incidents that occurred between January and March 2023, but this is almost three times less than DEFI losses in Q4 2022 ($950 million) and four times less than in Q1 2022 ($1.3 billion).
The biggest loss in Q1 2023 is considered to be the Euler Finance exploit, which caused damage in the amount of $197 million or more than 60% of the total losses for this period.
In total, we can talk about 90 incidents with exit scams that caused damage to investors by $31,043,335 and 52 incidents with flashloan/oracle manipulation exploits, the damage from which is estimated at $222,963,863

https://i.imgur.com/UNTVvqx.png

https://i.imgur.com/3H9cOQ1.png

Source: https://www.certik.com/resources/blog/3BaCA6ytR6uLFc1JVvt313-hack3d-the-web3-security-quarterly-report-q1-2023
There is also a video version of the report: https://www.youtube.com/watch?v=oAgLdGl56CE


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 10, 2023, 01:08:33 PM
https://decrypt.co/125799/sushiswap-smart-contract-bug-exploited-in-3-3-million-theft

SushiSwap Smart Contract Bug Exploited in $3.3 Million Theft
The decentralized exchange says it's "all hands on deck" and that some of the funds have been recovered.

"A bug introduced into SushiSwap four days ago was exploited late Saturday to drain about $3.3 million worth of Ethereum from a single user's account.

According to a Twitter post by blockchain security and data analytics company PeckShield, a wallet controlled by the victim—a prominent member of the Crypto Twitter community known as Sifu—was targeted by an "approve-related bug" in SushiSwap's RouterProcessor2 contract to steal about 1,800 ETH."


Title: Re: DeFi hacks [history]
Post by: FP91G on April 13, 2023, 12:25:09 PM
Tether Blacklists MEV Bots Exploiter ‘Sandwich the Ripper’ After ‘Official Requests’
Tether, a centralized entity behind popular stablecoin USDT, has blacklisted an Ethereum validator who had front-run MEV bots, earning $25 million via a sandwich attack.
The exploiter, who called themselves “Sandwich the Ripper,” will no longer be able to receive, send or redeem the $3 million worth of USDT held in their address.

Tether’s decision to blacklist the exploiter has drawn criticism from industry participants.

Uri Klarman, the CEO of bloXrouteLabs, told Blockworks in an interview that the exploiter did exactly what a sandwich bot would do.

“It didn’t hurt the consensus, it didn’t create two blocks at the same time, it gave them an invalid block that didn’t propagate,” Klarman said.
https://blockworks.co/news/tether-blacklists-mev-bots-exploiter


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 19, 2023, 11:16:59 AM
https://www.coindesk.com/business/2023/04/13/defi-protocols-aave-yearn-finance-likely-impacted-in-exploit-peckshield/

DeFi Protocol Yearn Finance Impacted in Nearly $11M Exploit That Occurred Via Aave Version 1

Join the most important conversation in crypto and Web3 taking place in Austin, Texas, April 26-28.
Secure Your Seat
A bug in a token issued by decentralized finance (DeFi) protocol Yearn Finance was impacted in an exploit this morning, security firm PeckShield tweeted, leading to millions of dollars in losses.
Losses could total over $11 million and occurred on Aave version 1, the data suggested. These were spread over U.S. dollar-pegged stablecoins dai (DAI), tether (USDT), USD coin (USDC), Binance USD (BUSD) and tru USD (TUSD).


Title: Re: DeFi hacks [history]
Post by: FP91G on April 26, 2023, 10:53:14 AM
Hacker Exploits Hundred Finance Protocol In $7.4 Million Heist
The multi-chain lending protocol hopes to contact its attacker as the HND token value falls 46%.
The multi-chain lending protocol Hundred Finance disclosed Saturday that it lost around $7 million after being hacked on the Ethereum layer-2 blockchain Optimism.
https://decrypt.co/136918/hacker-exploits-hundred-finance-protocol-in-7-4-million-heist


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 26, 2023, 03:10:48 PM
https://news.coincu.com/183924-breaking-zksync-dex-merlin-hacked-1-82-m/

BREAKING: zkSync DEX Merlin Hacked, $1.82 Million In Stolen Funds

zkSync, a Layer 2 scaling solution for Ethereum, has experienced a significant setback as its DEX Merlin was hacked. The hacker has stolen over $1.82 million in funds, and the LP has been drained.
BREAKING: zkSync DEX Merlin Hacked, $1.82 Million In Stolen Funds
According to the founder of OxScope, 0xBobie, the stolen funds have been identified to be in two wallets:

0x0b8a3ef6307049aa0ff215720ab1fc885007393d
0x2744d62a1e9ab975f4d77fe52e16206464ea79b7
The potential hacker bridged all the stolen funds to Ethereum.


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 03, 2023, 07:30:36 PM
https://cointelegraph.com/news/level-finance-confirms-1m-exploit-due-to-buggy-smart-contract

Level Finance confirms $1M exploit due to buggy smart contract
An attacker manipulated a “claim multiple” bug in a Level Finance smart contract to steal more than 214,000 LVL tokens from the exchange.
Level Finance informed its 20,000 Twitter followers that more than 214,000 of the exchange’s LVL tokens had been drained and swapped into 3,345 Binance Coin, with an approximate value of $1.01 million.
https://twitter.com/Level__Finance/status/1653140756540825638?


Title: Re: DeFi hacks [history]
Post by: Rampagoe004 on May 05, 2023, 11:35:30 AM
I have always said that all forms of modern finance have advantages and disadvantages. I hope this can be a punch in the face of those who praise DeFi as the best financial instrument. I prefer to think realistically. DeFi or centralization has several advantages. The drawback of being centralized is that all forms of finance are not completely transparent and data manipulation can occur. We also don't have full control over our assertion where we have to follow some rules made by the Bank or other security. And DeFi is very prone to being hijacked and hacked. For those who are really tech savvy it might not be a problem but when it's not your lucky day then you will face some downsides with your Defi.


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 10, 2023, 07:50:25 PM
https://cointelegraph.com/news/deus-finance-loses-6m-following-stablecoin-hack

Deus Finance loses $6M following stablecoin hack
"The attacker targeted the BNB Smart Chain and the Arbitrum network, with CoinMarketCap data showing the DEI price dropping 30% following the security incident.
Decentralized finance (DeFi) protocol Deus Finance has lost over $6 million due to a security breach on its stablecoin DEI. The hacker exploited a vulnerability in BNB Smart Chain (BSC) on May 5, according to blockchain security firm PeckShield.

A bot initiated the hack on BSC, which led to a more than $1.3 million loss. The attacker also targeted the Arbitrum network, with ARB/ETH deployments losing over $5 million. Twitter users claimed the token contract had a basic implementation error as the root cause."


Title: Re: DeFi hacks [history]
Post by: FP91G on May 21, 2023, 01:27:37 PM
UNIDENTIFIED INDIVIDUALS SEIZED CONTROL OF TORNADO CASH
On May 20, unknown persons seized control over the control mechanism of the Tornado Cash Ethereum mixer. According to Paradigm analyst samczsun, attackers have already begun to withdraw TORN tokens from smart contracts of the protocol.
According to the expert, unknown people introduced a malicious proposal, the code of which provided the ability to call the function EmergencyStop to update logic after acceptance. With its help, unknown people appropriated 1.2 million votes.

Hackers were able to revoke blocked tokens, transfer assets to the managing smart contract, and stop the router.

The analyst emphasized that attackers cannot withdraw cryptocurrency from separate pools. However, they have already begun to “merge” the blocked votes.

https://www.archyde.com/unidentified-individuals-seized-control-of-tornado-cash/


Title: Re: DeFi hacks [history]
Post by: RussianEnglishTranslation on May 22, 2023, 08:40:57 AM
Q Blockchain is the only chain with a legal layer that protects users. The constitution is recognized by international law and is enforced by root nodes who are also lawyers.


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 25, 2023, 12:29:18 PM
https://www.worldstockmarket.net/zachxbt-defi-project-fintoch-stole-31-6-million-from-users/
ZachXBT: DeFi project Fintoch stole $31.6 million from users
"DeFi project Fintoch was accused of that. that it may be a pyramid scheme, and its creators stole $31.6 million from users. Blockchain investigator @ZachXBT reported this.
Millions of users have been withdrawn to BNB Chain (formerly Binance Smart Chain) through the Tron and Ethereum networks. @ZachXBT writes that he began to suspect the Fintoch team of fraud after the project’s clients began to regularly report problematic withdrawal of capital from the site."


Title: Re: DeFi hacks [history]
Post by: FP91G on May 31, 2023, 04:35:13 PM
The Swaprum team has drained $3M in ETH from the protocol.
Swaprum is an Arbitrum-based decentralized exchange.
SAPR tokens have essentially become worthless following the heist.
Swaprum developers execute $3M heist
Despite their anonymity nature, cryptocurrencies follow the principles of transparency and trust. Nonetheless, exit scams and hacks have been long-term challenges in this space. Recent Swaprum events have reminded market players of the threats that scammers and hackers cause.

https://invezz.com/news/2023/05/20/just-in-sapr-tokens-worthless-following-3m-rug-pull-by-swaprum-developers/


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 31, 2023, 05:31:22 PM
https://www.msn.com/en-us/travel/other/1-this-crypto-coin-is-called-jimbo-2-8m-was-stolen-from-its-devs-in-flash-loan-attack/ar-AA1bUkUz
"Just days after releasing the second – and supposedly more stable and secure – version of its decentralized finance (DeFi) app, Jimbos Protocol over the weekend was hit by attackers who stole stole 4,090 ETH tokens from the project worth about $7.5 million.…

The developers behind the Arbitrum-based app were the apparent victims of a flash loan attack and now are scrambling to track down the light-fingered coders and retrieve the lost funds."


Title: Re: DeFi hacks [history]
Post by: zasad@ on June 14, 2023, 11:57:40 AM
https://cryptonews.com/news/new-report-north-koreas-cyber-army-allegedly-stole-3-billion-crypto-fund-nuclear-program.htm
New Report: North Korea's Cyber Army Allegedly Stole $3 Billion in Crypto to Fund Nuclear Program
"According to a recent analysis by The Wall Street Journal, state-sponsored hackers from North Korea have netted more than $3 billion from crypto thefts over the past five years.

The stolen funds have been supplying roughly half of North Korea's ballistic missile program, with defense accounting for a significant portion of the country's expenditure.

The report noted that North Korean hacking groups account for a huge portion of illicit cyber activities, as well as some of the biggest crypto heists ever.

For one, the North Korean Lazarus group of hackers is believed to be behind the hack of Axie Infinity's Ronin blockchain, which saw hackers make off with about $625 million worth of Ethereum and USDC in one of the largest crypto hacks of all time.

“When you look at the amount of funds stolen, [it] would look like an existential threat to what you are building," Aleksander Larsen, chief operating officer at Sky Mavis, told the WSJ.

The gaming company lost the funds after North Korean hackers reached out as a recruiter to an engineer. "


Title: Re: DeFi hacks [history]
Post by: FP91G on June 14, 2023, 03:58:56 PM
Decentralized finance (DeFi) platform Sturdy Finance has offered a $100,000 bounty to the hacker that exploited the protocol. The lending platform said that its team won’t pursue the issue further if the attacker accepts the offer.

On June 12, the DeFi platform suffered a loss of almost $800,000 in digital assets when an attacker exploited vulnerabilities within the platform. Security firms pinpointed that the cause of the exploit was a faulty price oracle and the hack was carried out through a reentrancy attack. In response, the platform paused all markets and assured the community that other funds were not at risk.
https://cointelegraph.com/news/defi-protocol-sturdy-finance-offers-100k-bounty-to-hacker-if-funds-are-returned


Title: Re: DeFi hacks [history]
Post by: FahriZah on June 14, 2023, 04:07:48 PM
Sometimes i seen somewhere the Defi hacks and finally i,m really satisfied about Defi hacking news from this post and best way to knowing as well always is better than others news.


Title: Re: DeFi hacks [history]
Post by: zasad@ on June 15, 2023, 10:40:42 AM
https://coinmarketcap.com/headlines/news/trading-firm-hashflow-faces-ongoing-exploit-with-600000-lost-so-far-peckshield/
Trading firm Hashflow faces ongoing exploit, with $600,000 lost so far: PeckShield
"Trading firm Hashflow is facing an ongoing exploit that has taken at least $600,000 in ether and arbitrum.

The vulnerability appears to refer to the firm's bridge contract, according to PeckShield. Hashflow offers cross-chain swaps as part of its trading service.

PeckShield said the exploit related to contract approvals. Since the exploit started, it seems that Hashflow has moved to revoke approvals for multiple tokens."


Title: Re: DeFi hacks [history]
Post by: FP91G on June 28, 2023, 04:58:40 PM
According to several reports, Chibi Finance, the decentralized finance (defi) platform built on top of Arbitrum, allegedly executed an exit scam on its users. Blockchain intelligence firm Peckshield provided a detailed account, revealing that approximately $1 million worth of cryptocurrency assets were illicitly withdrawn and converted into Ethereum.
https://news.bitcoin.com/chibi-finance-exit-scam-1-million-cryptocurrency-heist-rocks-defi-platform-on-arbitrum/


Title: Re: DeFi hacks [history]
Post by: abel1337 on June 28, 2023, 05:25:17 PM
According to several reports, Chibi Finance, the decentralized finance (defi) platform built on top of Arbitrum, allegedly executed an exit scam on its users. Blockchain intelligence firm Peckshield provided a detailed account, revealing that approximately $1 million worth of cryptocurrency assets were illicitly withdrawn and converted into Ethereum.
https://news.bitcoin.com/chibi-finance-exit-scam-1-million-cryptocurrency-heist-rocks-defi-platform-on-arbitrum/
Oh no, the fairly new Arbitrum is used as a scam platform by the scammers. It's not the first but I hope this won't encourage other DeFi projects to run as it can surely affect the Arbitrum as a project. With the increasing number of DeFi scams, there might be a time where people won't consider deFi projects as it is prone to being a scam and there might be a chance where a new solution to this DeFi running projects will be born. Of course there's a chance that it will be a trend and people will start transitioning to it as it is better. If everything lines up when a solution comes up, it might be the catalyst of the bull run.


Title: Re: DeFi hacks [history]
Post by: Daltonik on July 04, 2023, 05:32:57 PM
The Poly Network DeFi platform was hacked using a vulnerability in a smart contract, the hacker managed to issue tokens worth billions of dollars, in particular 99 million BNB, 10 billion BUSD, about 100 trillion SHIB, but they were of no value because they were not provided with liquidity. Nevertheless, the hacker was able to withdraw Ethereum for $ 5 million, Poly Network admitted the fact of hacking (https://twitter.com/PolyNetwork2/status/1675384703149568001)   

https://twitter.com/PeckShieldAlert/status/1675443876574937088

https://www.talkimg.com/images/2023/07/04/S0tGf.png



Title: Re: DeFi hacks [history]
Post by: o48o on July 04, 2023, 07:44:47 PM
The Poly Network DeFi platform was hacked using a vulnerability in a smart contract, the hacker managed to issue tokens worth billions of dollars, in particular 99 million BNB, 10 billion BUSD, about 100 trillion SHIB, but they were of no value because they were not provided with liquidity. Nevertheless, the hacker was able to withdraw Ethereum for $ 5 million, Poly Network admitted the fact of hacking (https://twitter.com/PolyNetwork2/status/1675384703149568001)   

https://twitter.com/PeckShieldAlert/status/1675443876574937088

https://www.talkimg.com/images/2023/07/04/S0tGf.png
Hackers famously use bridge attacks for their most successful attacks and Polygon is like a crypto made of bridges. *Surprised pikachu face*
One would think that a crypto project that's moving money for speed of 3 Million transactions per day would need to be iron proof for people to trust their money to it.
Now why would anyone want move real banks to decentralized platforms when they see something like this. Nor they should.

Sadly this won't be the last hack. Far from it.


Title: Re: DeFi hacks [history]
Post by: zasad@ on July 07, 2023, 10:57:58 AM
https://www.ibtimes.com/crypto-cons-this-week-multichain-fantom-bridge-loses-126m-aptos-network-compromised-airdrop-scam-3703896
Crypto Cons This Week: Multichain Fantom Bridge Loses $126M, Aptos Network Compromised By Airdrop Scam
"Multichain Fantom bridge lost $126M in WBTC, USDC, DAI, wETH, and Link from the exploit
The official Twitter accounts of the Aptos Network and that of its CEO were hacked on Friday
The hacked accounts posted details about a fraudulent airdrop

The Fantom bridge was looted of funds, approximately around $126 million consisting of crypto assets like WBTC, USDC, DAI, wETH, and Link.

The bad actors siphoned $30.9 million in WBTC, $13.6 million in wETH, and $57 million in USDC from the said bridge."


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on July 08, 2023, 08:07:48 AM
@zasad. I am quite shocked that the Multichain bridge was hacked 3 times. The second hack should have been very concerning already, I reckon. After this third hack, I shake my head. Everyone should start being skeptical about the developers and investigate. I also heard some stories that Multichain's CEO was arrested in China on May.

In any case, this is a list of all hacked DeFi bridges. It might be good to add for your list.

https://gist.github.com/cwhinfrey/9fd1bbc31bbcff08fca242b90c7f875d


Title: Re: DeFi hacks [history]
Post by: Freddie Boyer on July 08, 2023, 01:27:34 PM
Sometimes i seen somewhere the Defi hacks and finally i,m really satisfied about Defi hacking news from this post and best way to knowing as well always is better than others news.

It is very sad to read the series of events presented by zasad@ (OP). Of course there are many answers. we have to choose a good platform, store private keys to be safe and so on for let alone for ordinary people. If it's a disaster, even people who understand will also be affected if they have invested because it is safe at the start.

I think this is what a lot of people fear, saving then investing in crypto ends up being a tug of the rug and in vain. so, if this is the condition, who will be held responsible and blamed.


Title: Re: DeFi hacks [history]
Post by: zasad@ on July 12, 2023, 01:13:18 PM

https://gist.github.com/cwhinfrey/9fd1bbc31bbcff08fca242b90c7f875d
add
_____
https://cointelegraph.com/news/arcadia-finance-hacked-on-ethereum-and-optimism-for-455k
DeFi protocol Arcadia Finance hacked on Ethereum and Optimism for $455K
"A loophole in the code allowed the hacker to drain funds worth roughly $455,000 from Arcadia’s Ethereum and Optimism vaults.
A hacker drained approximately $455,000 from noncustodial decentralized finance (DeFi) protocol Arcadia Finance by exploiting a code vulnerability.

Blockchain investigator PeckShield alerted about the hack on Arcadia Finance, highlighting the cause as “the lack of untrusted input validation.” The code supposedly lacked a validation mechanism to cross-check unverified inputs. This loophole allowed the hacker to drain funds worth roughly $455,000 from Ethereum (darcWETH) and Optimism (darcUSDC) vaults."


Title: Re: DeFi hacks [history]
Post by: FP91G on July 19, 2023, 01:44:12 PM
Rodeo Finance Exploited For $888,000 In Another DeFi Hack on Arbitrum Network

Arbitrum Network-based Rodeo Finance lost 472 ether ($888,000) in a DeFi exploit today.

Blockchain security firm PeckShield revealed that the Rodeo Finance hacker transferred the stolen funds from Arbitrum to Ethereum.

Further analysis revealed that the attacker exchanged the stolen tokens for various other assets before converting them back to ether.

Hackers once again used Oracle manipulation technique to alter price feeds and exploit the platform out of nearly one million dollars worth of crypto.

https://cryptonews.com/news/arbitrum-based-rodeo-finance-exploited.htm


Title: Re: DeFi hacks [history]
Post by: zasad@ on July 21, 2023, 01:17:21 PM
https://cointelegraph.com/news/eth-curve-omnipool-platform-conic-finance-hacked-for-3-2-million-in-eth

Curve omnipool platform Conic Finance hacked for $3.2 million in ETH
"According to initial analysis by Peckshield, the root cause for Conic Finance’s hack was the new CurveLPOracleV2 contract.

Conic Finance, a liquidity pool balancing platform for the decentralized finance (DeFi) protocol Curve, has suffered an exploit on the Ethereum omnipool.

Conic Finance has been exploited for $3.26 million in Ether, the Web3 risk-alert source Beosin Alert reported on July 21. Nearly the entire amount of stolen cryptocurrency was sent to a new Ethereum address in just one transaction, according to data provided by Beosin."


Title: Re: DeFi hacks [history]
Post by: Gladitorcomeback on July 21, 2023, 02:04:55 PM
https://cointelegraph.com/news/eth-curve-omnipool-platform-conic-finance-hacked-for-3-2-million-in-eth

Curve omnipool platform Conic Finance hacked for $3.2 million in ETH
"According to initial analysis by Peckshield, the root cause for Conic Finance’s hack was the new CurveLPOracleV2 contract.

Conic Finance, a liquidity pool balancing platform for the decentralized finance (DeFi) protocol Curve, has suffered an exploit on the Ethereum omnipool.

Conic Finance has been exploited for $3.26 million in Ether, the Web3 risk-alert source Beosin Alert reported on July 21. Nearly the entire amount of stolen cryptocurrency was sent to a new Ethereum address in just one transaction, according to data provided by Beosin."

sad to see this and fortunately only Ethereum pool exploits and all other pools are safe. according to latest tweet, Conic team has fixed this pool issue now and all withdrawl can be done safely. They also claim that it not possible to exploit Ethereum mining pool gain.

hackers are in the search of finding any small door to enter and trying their best to steal fund. Dex projects should do many security audit to be safe and should close all doors for hackers.


Title: Re: DeFi hacks [history]
Post by: zasad@ on July 26, 2023, 10:34:21 AM
first ZKsync protocol

https://www.bitcoininsider.org/article/220933/era-lend-zksync-exploited-34m-reentrancy-attack
Era Lend on zkSync exploited for $3.4M in reentrancy attack

The lending app was drained of funds using a “read-only reentrancy” bug, a type of vulnerability that is often difficult for auditors to spot.

"Lending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract."


Title: Re: DeFi hacks [history]
Post by: Daltonik on August 01, 2023, 09:06:26 AM
Curve Finance lost $52 million as a result of the hack, this was caused by the exploitation of several liquidity pools as a result of an error in smart contracts using versions 0.2.15, 0.2.16 and 0.3.0. XNUMX.

https://twitter.com/PeckShieldAlert/status/1685794015915229184


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 02, 2023, 12:36:36 PM
https://beincrypto.com/kannagi-finance-zksync-era-rug-pull/

A Rocky Week for zkSync Era: EraLend Security Breach and Kannagi Finance Rug Pull


Kannagi Finance has walked away with $2.4 million worth of users' assets.
The incident is the first rug pull to affect the scaling solution zkSync Era.
It comes off the back of the $3.4 million hack EraLend suffered earlier.

"EraLend Loses $3.4M in Security Breach
On Tuesday, July 25, cyber attackers pilfered a staggering $3.4 million from EraLend, a lending platform operating on the zkSync Era. In the aftermath, the EraLend team promptly halted all activities.

A subsequent update revealed they had pinpointed a potentially involved crypto exchange account. Furthermore, they suspect that the culprits may have utilized a certain VPN provider to obscure their online tracks.

“We’ve pinpointed a suspicious CEX account that appears to be linked to an individual potentially involved in the incident. We are collaborating closely with the local police department, providing them with all relevant information,” said EraLend."


Title: Re: DeFi hacks [history]
Post by: FP91G on August 05, 2023, 10:10:39 PM
Curve Offers Hackers 10% Bounty in Exchange for Return of Crypto

Curve Finance and other victims of this week’s crypto lending heist have offered their hackers a 10% bounty in exchange for the return of the rest of their tokens.

"You will have no risk of us pursuing this further, no risk of law enforcement issues, etc," Curve, Metronome and Alchemix wrote in an on-chain message sent to a hacker's Ethereum address. The trio gave a deadline of August 6 at 0800 UTC, at which point their bounty will become a vigilante payout to whomever provides information that leads to the hacker's arrest and conviction.

https://markets.businessinsider.com/news/currencies/curve-offers-hackers-10-bounty-in-exchange-for-return-of-crypto-1032514282

https://twitter.com/curvefinance/status/1687180381714358272?


Title: Re: DeFi hacks [history]
Post by: bbc.reporter on August 07, 2023, 03:37:31 AM
Curve Offers Hackers 10% Bounty in Exchange for Return of Crypto

Curve Finance and other victims of this week’s crypto lending heist have offered their hackers a 10% bounty in exchange for the return of the rest of their tokens.

"You will have no risk of us pursuing this further, no risk of law enforcement issues, etc," Curve, Metronome and Alchemix wrote in an on-chain message sent to a hacker's Ethereum address. The trio gave a deadline of August 6 at 0800 UTC, at which point their bounty will become a vigilante payout to whomever provides information that leads to the hacker's arrest and conviction.

https://markets.businessinsider.com/news/currencies/curve-offers-hackers-10-bounty-in-exchange-for-return-of-crypto-1032514282

https://twitter.com/curvefinance/status/1687180381714358272?


News update. It appears that the hacker did not return the stolen funds to Curve Finance.

Curve is offering a $1.85 million bounty to anyone who can accurately identify the DeFi protocol's exploiter in a way that leads to definitive legal repercussions.

"The deadline for the voluntary return of funds in the Curve exploit passed at 0800 UTC," Curve publicly wrote in an Ethereum transaction's input data, adding: "We now extend the bounty to the public, and offer a reward valued at 10% of remaining exploited funds (currently $1.85M USD) to the person who is able to identify the exploiter in a way that leads to a conviction in the courts."


Source https://www.theblock.co/post/243464/curve-exploit-identity-bounty


However, he returned the funds of 2 DeFi protocols, Alchemix and Jpeg'd which he also sent a message telling eveyone that he was returning them because he was not scared, only returning them because he did not want to ruin the projects.

"I want to clarify that I'm refunding you not because you can find me, it's because I don't want to ruin your project," they explained in a transaction, adding: "Maybe it's a lot of money for a lot of people, but not for me, I'm smarter than all of you."

From the same news source.


Title: Re: DeFi hacks [history]
Post by: FP91G on August 09, 2023, 12:44:39 PM
Solana-based decentralized exchange Cypher lost close to $1 million in crypto Monday due to an exploit or security incident.
The protocol’s contracts are now frozen as contributors attempt to make contact with hackers to negotiate a return of funds.
Cypher is one of the fastest-growing protocols on the solana blockchain in part because of its loyalty program, which rewards depositors and traders with points that many users expect is the setup for an airdrop.
The exploit comes during Cypher’s biannual hacker house mtnDAO which it hosts in Salt Lake City alongside fellow Solana trading protocol marginfi. In its discord channel, marginfi said it was not impacted by the hack.

https://www.coindesk.com/business/2023/08/07/solana-based-cypher-protocol-experiences-exploit-freezes-smart-contract/


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 16, 2023, 02:41:59 PM
"In August 2023, Steadefi — a leveraged yield aggregation platform — was the victim of an attack. The attacker gained access to the private keys used to manage the project’s deployed contract, resulting in about $1.1 million in losses."

https://www.halborn.com/blog/post/explained-the-steadefi-hack-august-2023

"Blockchain security firm PeckShield revealed fresh vulnerabilities targeting decentralized finance (DeFi) projects on Aug. 9. According to the firm, Aave’s Earning Farm has been compromised by a reentrancy attack, resulting in the theft of at least $287,000 worth of Ether "

https://cointelegraph.com/news/aave-earning-farm-protocol-targeted-by-reentrancy-attack-peckshield

"Uwerx Loses $327,000 To A Flash Loan Attack

A flash loan attack on August 2 cut Uwerx's successful launch celebration short. The attacker flash-loaned 20,000 ETH (approximately $36,726,400) and swapped it for 5,053,637 WERX."
https://www.theportugalnews.com/news/2023-08-12/uwerxs-road-to-redemption-overcoming-hurdles-after-successful-launch-due-to-hack/80409

UZD Stablecoin Plummets As Zunami Protocol Loses Over $2.1 Million To Exploit
https://www.ibtimes.com/uzd-stablecoin-plummets-zunami-protocol-loses-over-21-million-exploit-3708535





Title: Re: DeFi hacks [history]
Post by: FP91G on August 23, 2023, 06:31:46 PM
Base project RocketSwap Labs has outlined its emergency program to bounce back from a brute force hack that swiped $865,000 or 471 Ether  from the protocol on Aug. 14.
The team explained on Aug. 15 that they plan on redeploying a new farm contract and open-source it on-chain, relinquish minting rights — presumably of RCKT — and will soon call on the hackers to return the assets, among other things

https://cointelegraph.com/news/base-dex-rocketswap-announces-emergency-plan-after-exploit


Title: Re: DeFi hacks [history]
Post by: zasad@ on August 30, 2023, 12:41:39 PM
https://www.theblock.co/post/246196/exactly-protocol-exploited-7-million-optimism-layer-2-network
"The exploit has resulted in estimated losses of over $7 million, according to security firms.

Exactly Protocol, a DeFi project that offers interest rate markets on the Optimism Layer 2 network, has become the latest victim of a security attack. The exploit, which was detected by security firms including BlockSec and Beosin, has resulted in estimated losses of over 4300 ether ($7.3 million)."


https://www.msn.com/en-us/money/markets/magnate-finance-executes-64-million-exit-scam-on-base-network-details/ar-AA1fLTXK
"Magnate Finance executes $6.4 million exit scam on Base Network
Magnate Finance, a lending project operating on the Ethereum Layer 2 network Base, has executed an exit scam, making off with an estimated $6.4 million. The event, described as a rug pull by security firm PeckShield, has sent shockwaves through the cryptocurrency community."


Title: Re: DeFi hacks [history]
Post by: safar1980 on September 06, 2023, 02:32:13 PM
North Korean hackers have allegedly stolen hundreds of millions in crypto to fund nuclear programs
North Korea-linked hackers stole $200 million worth of crypto from January to Aug. 18, accounting for over 20% of all stolen crypto this year, according to a recent report by TRM Labs.
https://www.cnbc.com/2023/09/06/north-korea-hackers-stole-crypto-to-fund-nuclear-program-trm-chainalysis.html


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 06, 2023, 03:35:51 PM
https://www.bleepingcomputer.com/news/security/crypto-casino-stakecom-loses-41-million-to-hot-wallet-hackers/
Crypto casino Stake.com loses $41 million to hot wallet hackers

"Online cryptocurrency casino Stake.com announced that its ETH/BSC hot wallets had been compromised to perform unauthorized transactions, with over $40 million in crypto reportedly stolen.

The platform immediately reassured users that their funds were safe, and all other wallets not directly impacted by the attack, including those holding BTC, LTC, XRP, EOS, and TRX, remained fully operational."

___
https://twitter.com/peckshieldalert/status/1698870451815285045
"PeckShieldAlert A total of ~$41M worth of cryptos were drained from Stake.com , with ~$15.7M on #Ethereum (9.62K $ETH), ~$7.85M on #Polygon (14.24M $MAITC), and $17.75M on #BNBChain (82.65K $BNB)"


Title: Re: DeFi hacks [history]
Post by: safar1980 on September 20, 2023, 02:21:12 PM
It has come to our notice that Harbor protocol has been exploited over the past few hours, resulting in a drain on a portion of the funds sitting in the stable-mint and stOSMO, LUNA and WMATIC vaults.
exploit against a Harbor DeFi protocol ​​ (https://twitter.com/Harbor_Protocol/status/1692836252498723154?)
$250,000 losses
Over $7m Stolen in Separate Attacks Against DeFi Protocols Exactly And Harbor
https://www.bitdegree.org/crypto/news/over-7m-stolen-in-separate-attacks-against-defi-protocols-exactly-and-harbor


GMBL Computer, a DeFi gambling protocol, was exploited for nearly 500 ETH, worth around $800,000 in today's prices.
The hacker's identity is known, and GMBL has offered a bounty for the return of funds to avoid legal action.
Despite accusations of an inside job, GMBL reported that half the stolen funds have already been recovered.
https://beincrypto.com/defi-gmbl-computer-exploited-eth-funds-returned/


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 27, 2023, 11:03:36 AM
https://www.coindesk.com/tech/2023/09/25/mixin-network-losses-nearly-200m-in-hack/
"Mixin Network has confirmed a report from SlowMist, a blockchain security consultancy, that it has been hacked for nearly $200 million.
“In the early morning of September 23…the database of Mixin Network's cloud service provider was attacked by hackers, resulting in the loss of some assets on the mainnet,” Mixin Network said in a statement. “The funds involved are approximately US$200 million.”
Mixin Network is a service similar to a layer-2 protocol, designed to make cross-chain transfers cheaper and more efficient.
But the problem with this, as many have pointed out on Twitter, is that it's reliant on a centralized database, creating a single point of failure."


Title: Re: DeFi hacks [history]
Post by: FP91G on September 27, 2023, 05:19:50 PM
Amazing Korean exchange upbit incident today

1. The Largest S.Korean exchange 
@Official_Upbit
 , abruptly halted Aptos' deposits and withdrawals, citing a wallet system maintenance without any specific reason

2. Various Korean users have posted authentication claiming that they received $APT without sending themselves

3. Reports have emerged that the Upbit customer center has been making phone calls to users who sold the deposited FAKE-APT tokens, requesting refunds.

4. What's so fucked up about this situation is that the deposited tokens are not the native
@Aptos_Network
 coin but a scam token called ClaimAPTGift
The only explanation for this situation is that Upbit's wallet system only checked the type and data and processed deposits and withdrawals


Scam token's address
https://apscan.io/account/0xc4f4e73e689b13799d6a1a52a9db1e0099de2e16967ca9bff97e9946dbedc4e9

https://twitter.com/definalist/status/1705900412208029894


Title: Re: DeFi hacks [history]
Post by: zasad@ on September 28, 2023, 08:51:25 AM
https://dune.com/21co/lazarus-group-crypto-holdings
"This dashboard tracks the crypto holdings of the cybercrime unit Lazarus Group (also known as APT38), which has conducted multiple hacks on behalf of the North Korean government. In total, we track 295 wallets identified by the U.S. Federal Bureau of Investigation (FBI) and Office of Foreign Assets Control (OFAC). For context, these are the largest hacks conducted by the Lazarus Group, as confirmed by the FBI:

March 29, 2022: ~$620 million theft from Sky Mavis’ Ronin Bridge.
June 22, 2022: ~$100 million Harmony’s Horizon Bridge hack.
June 2023: ~$100 million theft from Atomic Wallet.
July 22, 2023: ~$60 million theft from Alphapo.
July 22, 2023: ~$37 million theft from CoinsPaid.
September 4, 2023: ~$41 million theft from Stake.com.
We should note that this is a lower-bound estimation of Lazarus Group’s crypto holdings based on publicly available information. If you have identified or are aware of any other hacks that have been disclosed, please get in touch with us so we can track the assets here.

Find the reports of the FBI disclosing the wallet addresses here: January 23, 2023, August 22, 2023, September 6, 2023."


Title: Re: DeFi hacks [history]
Post by: FP91G on October 04, 2023, 10:28:37 AM
Combining all the incidents in September we’ve confirmed ~$332M lost to exploits, hacks and scams.

Exit scams were ~$1.9M

Flash loans were ~$0.4M

Exploits were ~$329.8M

Picture and graphics (https://pbs.twimg.com/media/F7RevySWYAACHkF?format=jpg&name=4096x4096)

https://twitter.com/CertiKAlert/status/1708094695832682893

Cumulative losses since the beginning of the year amount to approximately 1.34 billion dollars, including various hacks for 925.4 million.
https://bitcointalk.org/index.php?topic=5227888.msg62936942#msg62936942



Title: Re: DeFi hacks [history]
Post by: zasad@ on October 04, 2023, 05:22:55 PM
https://russia.postsen.com/local/484395/Fraudsters-began-to-take-advantage-of-the-departure-of-the-Binance-crypto-exchange-from-Russia.html
"The largest cryptocurrency platform Binance announced its final departure from Russia a week ago. However, cyber fraudsters are already trying to make money from this. “In the first five days, several fake groups were created on Telegram, eight fake tokens, one of which had a daily trading volume of $130,000, and, of course, a classic scam began on the P2P marketplace,” the CEO of CommEX (the buyer of the Russian business Binance) told Forbes ) for the development of the region and the CIS Anton Toroptsev"


Title: Re: DeFi hacks [history]
Post by: FP91G on October 11, 2023, 04:59:54 PM
Galxe platform experiences DNS attack, losses top $150K
The Web3 platform’s website has been restored, but the company still warns against using it. The hack may be linked to September’s attack on Balancer.

The website of Web3 community platform Galxe was offline for about an hour on Oct. 6. Galxe reported on X (formerly Twitter) that its website was down at 14:44 UTC, confirming 40 minutes later that it had experienced a security breach affecting its Domain Name System (DNS) record. It warned against visiting the domain until the situation was remedied.

At the time of writing, Galxe had not confirmed that its website was safe to use again. After the website was restored, some X posters were reporting that it was blocked by Google.



https://cointelegraph.com/news/galxe-protocol-experiences-dns-attack-october-6


Title: Re: DeFi hacks [history]
Post by: AnonBitCoiner on October 11, 2023, 06:44:40 PM
Star arena ,a best social platform experience defi hacking. The hackers able to access their contract and exploit a reentrancy vulnerability within the code which allowed them to inflate the share's value, reaching approximately $274K per share. Hackers steal almost 2.9 million worth of AVAX token. This hacks happened in October 2023.
Defi hacking is increased so much in 2023 and most of hacker target contract address and this hacks also is part of it. Need lot of protection and audit check everytime.

SOURCE (https://twitter.com/HalbornSecurity/status/1711485956182749667?s=19)

https://www.halborn.com/blog/post/explained-the-stars-arena-hack-october-2023



Title: Re: DeFi hacks [history]
Post by: zasad@ on October 12, 2023, 11:46:24 AM
https://cryptonews.com/news/defi-protocol-platypus-finance-hacked-for-over-2-million-avalanche-heres-what-happened.htm

DeFi Protocol Platypus Finance Hacked for Over $2 Million on Avalanche

"Decentralized finance (DeFi) protocol Platypus Finance has fallen victim to a security breach resulting in the loss of over $2 million.

In a recent blog post on X (formerly Twitter), security firm PeckShield noted that the Avalanche-based project has been exploited.

Following the alert, Platypus Finance confirmed that there had been suspicious activities in the protocol, prompting the project to take "the proactive measure of temporarily suspending all pools.""


Title: Re: DeFi hacks [history]
Post by: PolcaInvest on October 18, 2023, 01:58:50 PM
MEV bot earned $1.5 million thanks to a $4 attack
https://wixi.exchange/en/news/3479042.html


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 18, 2023, 02:25:09 PM
https://cointelegraph.com/news/stars-arena-recovers-stolen-funds-after-offering-bounty-exploit

Stars Arena recovers 90% of stolen funds after offering $257K bounty
"The exploiter of the Web3 social media platform agreed to keep a 10% bounty in exchange for returning the remainder of the stolen funds.
Web3 social media platform Stars Arena said it has recovered nearly all of the crypto stolen from an Oct. 7 exploit, minus a 10% bounty to the person responsible.

In an Oct. 11 X (Twitter) post, Stars Arena said around 90% of the 266,000 Avalanche exploited, at the time worth around $3 million, was returned after reaching an agreement to give a 27,610-AVAX bounty worth nearly $257,000 to the exploiter.

The bounty also included compensation for 1,000 AVAX worth over $9,000 seemingly lost by the exploiter in a bridge."


Title: Re: DeFi hacks [history]
Post by: FP91G on October 25, 2023, 01:34:18 PM
How Hackers Attacked Telegram Trading Bot to Steal $500,000
Hackers exploited a vulnerability in the Maestro Router 2 smart contract, stealing 280 ETH ($500,000) from Telegram trading bot Maestro.
The Maestro attack resulted in a 30% drop in JOE tokens' price due to lack of liquidity. The stolen ETH was transferred to Railgun, a crypto privacy tool.
Despite the hack, Maestro refunded all affected users by purchasing and returning the lost tokens. The bot has earned over $20 million in fees in 2

https://beincrypto.com/maestro-refunds-after-attack/


Title: Re: DeFi hacks [history]
Post by: zasad@ on October 26, 2023, 11:52:21 AM
https://twitter.com/DeDotFiSecurity/status/1717327912410456355

"🚨 ~$743,000 Exit Scam Alert 🚨

Fake $LINEA token has been rug pulled earlier today, previously flagged with a Rug Pull High Risk issue

@DeDotFi
 Scanner also identified token as a Honeypot

All the stolen funds were transferred to Tornado Cash"


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 01, 2023, 05:18:15 PM
https://cointelegraph.com/news/onyx-protocol-exploiter-siphon-2-1-m-loot-tornado-cash
"Decentralized peer-to-peer lending platform Onyx Protocol lost roughly $2.1 million in an exploit of a market with no liquidity that was deployed on Oct. 27.

The Onyx Protocol hacker exploited a known bug, a rounding issue behind the popular CompoundV2 fork, explained blockchain investigator PeckShield soon after alerting about the hack that went unnoticed by the protocol."


Title: Re: DeFi hacks [history]
Post by: safar1980 on November 06, 2023, 03:43:31 PM
FixedFloat blocked coins from hacker group Lazarus
Thanks to the coordinated efforts of our team over the past three days, an attempt to launder stolen funds associated with the hacker group Lazarus from the DPRK has been successfully thwarted.✔️

The total amount of funds subject to blocking amounted to about two million dollars. 💵

We will continue to work towards enhancing the security and reliability of our services. 🚀

Source:
https://twitter.com/FixedFloat/status/1720448805303161327


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 08, 2023, 10:43:37 AM
https://twitter.com/AstridFinance/status/1718236380009230406
"Unfortunately our smart contract was exploited due to a fix recommended by our auditor.

We have paused the contract.

We have taken a snapshot of all holders and will offer full refund and make everyone whole. Please wait as our team work out the refund process.

We truly apologize for what happened and will make sure everyone is refunded accordingly "

Damage approximately 245 000 dollars  AstridFinance

https://twitter.com/AstridFinance/status/1718563845323866383
"Hacker has decided to return our funds (minus 20% as per the bounty), as such we consider this as settled amicably."
https://etherscan.io/tx/0x27cbd5f2f12067bcc9be3bafa9140b849ee1ee68ae5329c2a4ba789685111ad7


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 15, 2023, 02:40:11 PM
Raft Suffers $3.3M Exploit That Drove Down Stablecoin 50%, but Hacker Likely Lost Money on Attack
https://www.coindesk.com/tech/2023/11/10/defi-platform-raft-suffers-33m-exploit-but-hacker-likely-takes-a-loss-on-the-attack/
"Decentralized finance (DeFi) platform Raft lost some $3.3 million in ether (ETH) after being hacked Friday afternoon – but the attacker may have suffered a loss on the heist.
On-chain data shows that the attacker drained 1,577 ETH from Raft, then sent 1,570 ETH to a burn address – destroying most of the stolen assets and leaving only 7 ETH for themselves. The hacker's address received 18 ETH via crypto mixer service Tornado Cash before the attack, blockchain data on Arkham shows, likely to fund transactions.
After executing the transfers and paying the blockchain fees, the exploiter's crypto wallet was left with only 14 ETH, fewer funds than the initial 18 ETH.
This means that they face a 4 ETH loss on the whole maneuver."

TrustPad Attack Post-Mortem
https://trustpad.medium.com/trustpad-attack-post-mortem-c09ccc01e0ef
exploit to one of TrustPad’s staking contracts


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 23, 2023, 09:54:24 AM
https://cryptonews.com/news/kyberswap-hacked-for-48-million-hackers-suggest-negotiations.htm
"KyberSwap Hacked for $48 Million, Hackers Suggest Negotiations
KyberSwap, a decentralized exchange, has been compromised in a hack resulting in the theft of $48 million, prompting the platform to advise users to withdraw their funds while the attackers hint at entering negotiations.

On-chain data indicates that the hack on KyberSwap resulted in significant losses of $48 million across several blockchain networks, including 20 million from Arbitrum, $15 million from Optimism and $7 million from Ethereum.

The stolen funds were primarily deposited in Ethereum (ETH), Wrapped Ethereum (wETH), and USD Coin (USDC). The analysis of the incident indicates a direct attack on the exchange’s liquidity pools instead of a vulnerability in the platform’s code."


Title: Re: DeFi hacks [history]
Post by: FP91G on November 23, 2023, 02:39:24 PM
Data shared by blockchain security platform PeckShield shows that more than $86.6 million in digital assets were transferred from the HECO Chain bridge to suspicious addresses. The security firm suggests that the bridge is compromised and an exploit is ongoing.

In response to the incident, Tron founder Justin Sun announced that HTX will fully compensate users for any losses incurred in the hack. The company has also temporarily suspended deposits and withdrawals as they investigate the incident. The executive said services will resume after the investigation is completed.


https://cointelegraph.com/news/heco-chain-bridge-hack-86-million-lost

HTX and Heco Cross-Chain Bridge Undergo Hacker Attack.
https://twitter.com/justinsuntron/status/1727304656622326180?


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 24, 2023, 10:22:53 AM
https://www.msn.com/en-us/news/technology/infstones-to-implement-key-rotations-following-vulnerability-disclosure-in-lido-protocol/ar-AA1kqfJR
InfStones to Implement Key Rotations Following Vulnerability Disclosure in Lido Protocol
"Addressing the Tailon library vulnerability
The vulnerability, which was discovered in the open-source Tailon library, posed a potential risk to the Lido Finance protocol. Lido Finance, known for being the largest liquid staking protocol on Ethereum, oversees a substantial amount of ether, amounting to 9.23 million with a market value exceeding $19 billion. The protocol allows users to deposit ETH and participate in network staking through validator nodes. These nodes issue a derivative token to users, representing their staked deposit. A network of contributors, known as operators, is responsible for running these ETH validator nodes."


Title: Re: DeFi hacks [history]
Post by: slashz9 on November 24, 2023, 12:06:14 PM
What do you think is the reason why this case always happens every year? If you look at history, there will always be things like this.
Is it that easy to hack or is the security of each project different, or is this a game of the people closest to it, because they are the ones who can reach it the easiest, and there are many other possibilities.


Title: Re: DeFi hacks [history]
Post by: Mate2237 on November 24, 2023, 03:24:08 PM
What do you think is the reason why this case always happens every year? If you look at history, there will always be things like this.
Is it that easy to hack or is the security of each project different, or is this a game of the people closest to it, because they are the ones who can reach it the easiest, and there are many other possibilities.
Most of them are hacked by closed friends and also careless or improper security caused by the developer. When a project is launched the developer should put the security of the site in his mind first and always and if it is not enough they should buy more security space for the site so that when a hacker visit the site it would bounced back but whereby you only develop the site and dump it like that without any extra security measures to prevent and protect the site then hackers will be very happy to penetrate.

In sometimes, co-workers, or a mistake of the owner of the DeFi caused the hack. And this has happened to me before. I mistakenly send a code that was sent to me in Facebook and it used to hacked my Facebook account, they are some emails DeFi received and they were trying to quote those messages by replying them and a code which was secretly sent was forwarded to them and the site was hacked.


Title: Re: DeFi hacks [history]
Post by: Velemir Sava on November 24, 2023, 03:58:36 PM
What do you think is the reason why this case always happens every year? If you look at history, there will always be things like this.
Is it that easy to hack or is the security of each project different, or is this a game of the people closest to it, because they are the ones who can reach it the easiest, and there are many other possibilities.

Now the question is whether it is wise not to trust an exchange with all your coins. Indeed, this is an easy target for bandits and no matter how strong the security system created by the exchange, it will still be searchable and this year 2023 the cryptocurrency market is very unstable.


Title: Re: DeFi hacks [history]
Post by: zasad@ on November 29, 2023, 03:33:45 PM
https://twitter.com/KyberNetwork/status/1728800315955437743

"The KyberSwap team has been in contact with the owners of the frontrun bots that extracted about $5.7M* worth of funds from KyberSwap pools on Polygon and Avalanche during the exploit.
We have negotiated with the owners of the frontrun bots to return 90% of the users’ funds taken by them to: 0x8180a5CA4E3B94045e05A9313777955f7518D757,
in return for a 10% bounty as described in this on-chain message: https://polygonscan.com/tx/0x8a0880f1662e39fa838e89fa751669e4a1eee5c15586dc447453274f7b8ce746
.."


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 06, 2023, 02:42:41 PM
https://beincrypto.com/florence-finance-loses-1-45-million-hackers/
"Scammers have stolen $1.45 million in USDC from the real-world asset lending project, Florence Finance, via a phishing attack.
The Florence Finance attack involved address poisoning, a common phishing technique where a fraudulent, similar-looking address is used.
Co-founder and CEO of Cyvers, Deddy Lavid, has emphasized the need for heightened security measures in the digital finance sector."


Title: Re: DeFi hacks [history]
Post by: zasad@ on December 13, 2023, 08:45:31 PM
https://invezz.com/news/2023/12/13/okx-dex-losses-370k-in-hack-users-assured-reimbursement/

"OKX Dex has faced a suspected hacking incident, resulting in losses exceeding $370,000.
OKX Dex swiftly responded to the breach by removing the compromised proxy address.
OKX also deactivated the affected contracts and reassured users of asset safety.

OKX‘s decentralized exchange and cross-chain bridge aggregator OKX Dex has fallen victim to a suspected hacking incident, resulting in losses exceeding $370,000. The breach raised alarms among users who noticed unauthorized transactions from wallets previously authorized on the platform.

The hacker is said to have exploited the vulnerability in OKX Dex’s authorization process as users exchange their crypto assets."


Title: Re: DeFi hacks [history]
Post by: FP91G on December 27, 2023, 04:23:51 PM
Thunder Terminal claims funds safe after $240K attack, hacker says otherwise
The on-chain trading platform confirmed a 3rd party compromise has led to funds being drained from 114 wallets but claims it has already fixed the issue. The hacker has a different take.
On-chain trading platform Thunder Terminal says user funds are now safe after thwarting a $240,000 exploit that compromised 114 wallets on its platform. The hacker, however, says it’s "all lies" and is demanding an additional ransom for user data.

https://cointelegraph.com/news/thunder-terminal-hack-exploit-wallet-compromise-hacker-demands-ransom


Title: Re: DeFi hacks [history]
Post by: safar1980 on December 28, 2023, 10:34:20 AM
Scammers stole $880k  (https://coinmarketcap.com/community/articles/658a85a56342662e6d2293c1/)via fake Discord server for Across Protocol
Crypto sleuth ZachXBT warned in a Telegram channel that Across Protocol’s documentation was linked to a fake Discord server.
In a Telegram post on Dec. 26, crypto sleuth ZachXBT raised concerns about a potential security breach related to Across Protocol’s documentation.

The warning highlighted a link within the protocol’s documentation leading users to a fake Discord server, suggesting the protocol’s vanity invite address might have been compromised. The incident reportedly led to a loss of $880,000 worth of crypto tied to one unknown blockchain entity.


Title: Re: DeFi hacks [history]
Post by: zasad@ on January 03, 2024, 09:25:24 AM
https://www.theblock.co/post/269809/orbit-chains-bridge-reportedly-hacked-for-81-5-million
Orbit Chain's bridge reportedly hacked for $81.5 million

"Orbit Chain’s cross-chain bridge has reportedly been hacked for $81.5 million in cryptocurrencies and stablecoins.
The exact nature of the hack is unknown.

Orbit Bridge, a cross-chain bridge protocol, has seen unusual outflows of $81.5 million in several cryptocurrencies in what appears to be a major hack.

In five separate transactions, each to a fresh wallet, the Orbit Bridge sent $50 million in stablecoins (30 million Tether, 10 million DAI, and 10 million USDC), 231 wBTC (about $10 million), and 9,500 eth (about $21.5 million). The hack was first noticed by X user Kgjr. "


Title: Re: DeFi hacks [history]
Post by: FP91G on January 03, 2024, 02:25:30 PM
Levana Protocol, a platform known for its blockchain-based perpetual futures swap protocol, has fallen victim to a devastating crypto hack.
The exploit led to the loss of more than $1 million worth of cryptocurrency tokens from Levana's liquidity pools. This incident highlights the growing challenges blockchain platforms face in ensuring the security of user funds and the need for robust security measures.

https://www.econotimes.com/Blockchain-Based-Levana-Protocol-Falls-Victim-to-1-Million-Crypto-Hack-1668721


Title: Re: DeFi hacks [history]
Post by: zasad@ on January 04, 2024, 09:10:15 AM
First hack in 2024
https://ambcrypto.com/radiant-capital-falls-prey-to-this-security-hack-details-here/
Radiant Capital falls prey to this security hack.

"Radiant Capital faced a cyber attack, resulting in a loss of over $4.4 million.
The breach prompts a temporary pause, leading to a decline in sentiment for both Radiant Capital and Arbitrum.
Radiant Capital [RDNT] is a platform that seeks to unify fragmented liquidity across various lending protocols and chains in the decentralized finance (DeFi) space. However, recent events have cast a shadow on its integrity as the platform fell victim to a malicious attack."


Title: Re: DeFi hacks [history]
Post by: The Watcher of All on January 04, 2024, 09:07:25 PM
Great topic, love this list! Thanks

I hope DeFi will have less and less of those as DEX improves.


Title: Re: DeFi hacks [history]
Post by: zasad@ on January 17, 2024, 11:49:45 AM
https://coingape.com/socket-loses-3-3-million-in-hack-due-to-input-validation-flaw/

Socket Loses $3.3 Million in Hack Due to Input Validation Flaw

"Blockchain interoperability protocol Socket reported a security breach on Tuesday that resulted in over $3.3 million in losses. The incident impacted wallets that had granted infinite approvals to Socket contracts. It was attributed to a vulnerability in user input validation.

The exploit was linked to a specific route in the system that had been added just three days before the attack. As per blockchain security firm PeckShield, the problematic route has since been deactivated to prevent further misuse."


Title: Re: DeFi hacks [history]
Post by: FP91G on January 24, 2024, 10:33:01 AM
DeFi protocol Concentric.fi suffered a hacker attack and lost approximately US$1.6 million, reminding not to interact for now
CertiK Alert monitors that the DeFi protocol Concentric Finance platform built based on the Camelot v3 protocol has been attacked by vulnerabilities, and the initial loss is estimated to be US$1.6 million. Concentric Finance reminds you not to interact with this protocol for the time being.

https://www.coinlive.com/news-flash/424934


Title: Re: DeFi hacks [history]
Post by: john1010 on January 24, 2024, 03:30:31 PM
Observing the numerous incidents you've shared within the DeFi space, it's evident that security remains a significant challenge. The frequency and scale of these hacks highlight the vulnerabilities inherent in the current decentralized financial ecosystem. As the space continues to evolve, addressing these security concerns and implementing robust measures to safeguard users' funds will be crucial for the sustained growth and adoption of DeFi. The community's response and ability to learn from these incidents will play a pivotal role in shaping a more secure and resilient decentralized financial landscape.


Title: Re: DeFi hacks [history]
Post by: zasad@ on January 25, 2024, 12:32:08 PM
john1010,this is the price of freedom.
___
https://beincrypto.com/gamee-loses-millions-to-hack/
How This Crypto Gaming Project Lost $7 Million to Hackers
Gamee, a subsidiary of Animoca Brands, lost $7 million in a hacking attack involving unauthorized access to its token contracts.
The hackers stole 600 million GMEE tokens, converted them into Ethereum and Polygon, causing a 45% drop in GMEE's price.
In response, Gamee transferred token contracts ownership to a secure address, halted liquidity provisioning, and initiated legal proceedings.


Title: Re: DeFi hacks [history]
Post by: safar1980 on February 23, 2024, 06:56:16 PM
Sky Mavis Co-Founder Jeffrey Zirlin’s wallets hacked for $9.7 million in ETH  (https://www.theblock.co/post/278745/sky-mavis-co-founder-jeffrey-zirlins-wallets-hacked?)
Zirlin wrote on X that he had a “tough morning” as two of his addresses were compromised.

Jeffrey Zirlin, co-founder of Sky Mavis that created the Axie Infinity game, said that two of his wallets were hacked on Friday morning Asia time and that Ronin was not affected, according to his X post.

Blockchain security firm PeckShield identified that a “whale wallet” had been compromised with about 3,248 Ether, worth around $9.7 million, withdrawn from the Ronin Bridge and moved to crypto mixer Tornado Cash.

“The attack is limited to my personal accounts, and has nothing to do with validation or operations of the Ronin chain,” Zirlin said on X. “Additionally, the leaked keys have nothing to do with Sky Mavis operations.”


Title: Re: DeFi hacks [history]
Post by: zasad@ on February 28, 2024, 09:18:19 AM
https://cointelegraph.com/news/microstrategy-x-account-hacked-phishing-scam
"MicroStrategy’s X account hacked, shilling Ethereum token phishing scam
Hackers took over the official MicroStrategy X account, posting a series of malicious links to a fake airdrop for a so-called Ethereum-based MSTR token.
Scam Sniffer said just one user had lost over $420,000 to the phishing scam at approximately 12:43 am UTC, only several minutes after the first malicious link was posted to MicroStrategy’s account on X. "


Title: Re: DeFi hacks [history]
Post by: FP91G on March 02, 2024, 06:32:08 PM
@SenecaUSD exploited for 1,900 $ETH (worth ~$6.5M).
The attacker used constructed calldata parameters to call transferfrom and transfer tokens that were approved to the project's contracts to the attacker's address.
The stolen funds are now held across 3 addresses.
Revoke approvals🔽

https://twitter.com/BeosinAlert/status/1763024503452611038


Dear Whitehat,
Please return the funds to the following Ethereum wallet address: 0xb7aF0Aa318706D94469d8d851015F9Aa12D9c53a
We are collaborating with third-party security providers and law enforcement to trace the funds and identify recipient wallets. Acting promptly is crucial, so we kindly request that you return the funds as soon as possible to avoid any further legal action.
A 20% bounty may be kept as per whitehat efforts.

https://twitter.com/SenecaUSD/status/1762999045109248461



We're happy to see 80% of funds have been returned.
Transaction link: https://etherscan.io/address/0xb7aF0Aa318706D94469d8d851015F9Aa12D9c53a
The exploit involved assets held in users' wallets. The exploit didn't involve funds directly deposited into Seneca (Seneca's TVL).
The recovery of funds through a whitehat request was an extremely optimistic scenario.
It's important to note that Seneca's Chamber contract was audited prior to deployment (@HalbornSecurity).

https://twitter.com/SenecaUSD/status/1763181438113865960


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 06, 2024, 10:18:55 AM
https://unchainedcrypto.com/ordizk-team-allegedly-steals-1-4-million-in-exit-scam/
OrdiZK Team Allegedly Steals $1.4 Million in Exit Scam
"The team behind cross-chain bridging protocol OrdiZK appear to have stolen $1.4 million worth of ether from users, after allegedly draining tokens from the project contract and deleting its website and social media accounts."


Title: Re: DeFi hacks [history]
Post by: FP91G on March 06, 2024, 05:32:05 PM
WOOFi Lost $8 Million in Hack on Its Arbitrum Lending Market

"WOOFi, a decentralized exchange, suffered significant financial losses due to an exploit in its Arbitrum lending market, as revealed by the company on Wednesday.

The exploit, identified by several blockchain security firms, including PeckShield, Hypernative, and Chainalysis, involved flash loan attacks targeting WOOFi Swap on Arbitrum around 15:49 UTC on March 5.
In response, WOOFi swiftly halted the affected contracts at approximately 16:02 UTC and initiated an investigation revealed in a report detailing the incident, which was subsequently released on March 6.

The hacker manipulated the sPMM algorithm, which is responsible for setting prices on Arbitrum-based WOOFiSwaps. This manipulation occurred after borrowing 7.7 million WOO tokens and “some other assets.”

The company stated, “At this point WOOFi’s sPMM incorrectly adjusted WOO to an extreme price which was close to zero, and the exploiter then swapped out 10M WOO in the same transaction with almost no cost. The exploiter repeated this attack 3 times within a very short period of time, which netted about $8.75m in profits after returning the flash loans.”"

https://www.cryptotimes.io/2024/03/06/woofi-lost-8-million-in-hack-on-its-arbitrum-lending-market/


Title: Re: DeFi hacks [history]
Post by: FP91G on March 20, 2024, 12:23:28 PM
Binance-Incubated UGC Platform NFPrompt Discloses Significant Losses from Latest Hack
NFPrompt (Non-Fungible Prompt), an AI-powered User Generated Content (UGC) Platform, recently disclosed significant losses resulting from a hack. According to a post on X, NFPrompt revealed that it had fallen victim to cyber intrusion, resulting in the loss of funds from its platform, including a part of NFP treasury and ecosystem fund.
https://www.coinspeaker.com/nfprompt-losses-latest-hack/


Title: Re: DeFi hacks [history]
Post by: zasad@ on March 22, 2024, 01:27:45 PM
https://twitter.com/Cointelegraph/status/1770933644242169997
"The SSS_HQ token faced a near-total value loss after a double-spending flaw was exploited, despite efforts to save funds."

https://twitter.com/Cointelegraph/status/1770941171411386475
"According to @CertiK, this glitch was rooted in the contracts’ _update() function, which failed to accurately update token balances under specific conditions, enabling users to double their $SSS token balance by transferring it to themselves."



Title: Re: DeFi hacks [history]
Post by: zasad@ on April 03, 2024, 09:43:30 AM
https://www.theblock.co/post/284883/web3-gaming-platform-munchables-loses-62-5-million-in-exploit-zachxbt
Web3 gaming platform Munchables loses $62.5 million in exploit: ZachXBT
"Munchables, a web3 gaming platform based on the Ethereum Layer 2 Blast, lost $62.5 million in one of the biggest exploits of the year.
The exploiter’s wallet address contained nearly 17,411 ETH, crypto sleuth ZachXBT found.
Munchables reported that the platform had been compromised on the social media platform X. "



Title: Re: DeFi hacks [history]
Post by: FP91G on April 10, 2024, 05:33:28 PM
Prisma Finance Hacked; Hacker Demands Apology and Offers to Return $11M

Following a hack of Prisma Finance that caused an $11 million loot from this prominent liquid staking protocol, a hacker in the decentralized finance (defi) division has made some stunning proposals. This person called themselves to be white-hat hackers since they are good ethical hackers who try to find bugs and fix them. Under certain conditions, the money they stole can be returned according to this incident that took place on March 28.

https://www.msn.com/en-us/money/technology/prisma-finance-hacked-hacker-demands-apology-and-offers-to-return-11m/ar-BB1kOp7O


Title: Re: DeFi hacks [history]
Post by: zasad@ on April 17, 2024, 02:13:55 PM
https://www.msn.com/en-us/money/companies/prosecutors-rest-case-in-mango-markets-fraud-trial/ar-BB1lxgoP
"The government on Friday rested in its case against cryptocurrency trader Avraham Eisenberg, who is facing fraud charges.

Driving the news: Prosecutors presented very strong arguments that the defendant had a good idea he was committing a crime over a year ago, when he managed to extract over $100 million from Mango Markets.

Why it matters: In a fraud case, the government has to not only show that the defendant committed a crime, but that they were aware that what they were doing was against the law.

Catch up fast: Eisenberg is on trial in Federal Court in Manhattan for engaging in a trade where he was able to withdraw all the capital on Solana-based Mango Markets on October 11, 2022, using a derivate of the mango (MNGO) token as collateral.

After inflating the token with strategic purchases on various exchanges, he used the inflated value of a MNGO derivative as collateral to borrow all the available deposits on the platform, over $100 million worth.
Then he withdrew those funds to a wallet he controlled, and let his loan default."

https://www.sec.gov/news/press-release/2023-13
SEC Charges Avraham Eisenberg with Manipulating Mango Markets’ “Governance Token” to Steal $116 Million of Crypto Assets


Title: Re: DeFi hacks [history]
Post by: FP91G on April 24, 2024, 11:29:50 AM
Mango Markets Exploiter Avi Eisenberg Found Guilty of Fraud and Manipulation
Eisenberg faces up to 20 years in prison for his $110 million heist.
A Manhattan jury has found crypto trader Avi Eisenberg guilty of fraud and market manipulation for his $110 million heist from decentralized finance protocol Mango Markets in October 2022.
Eisenberg was arrested in Puerto Rico in December 2022 and charged with commodities fraud, commodities manipulation, and wire fraud for the scheme. He will be sentenced on July 29 by New York District Court Judge Arun Subramanian. Eisenberg faces up to 20 years in federal prison for his crimes.
“This ground-breaking prosecution epitomizes this office’s ability to employ innovative methods and cutting-edge law enforcement tools to continue to protect all financial markets," said Damian Williams, U.S. Attorney for the Southern District of New York, in a Thursday press statement. "The career prosecutors of this office continue their expertise in prosecuting financial fraud, one of our core priorities, and would-be financial criminals should think twice before daring to engage in illicit conduct on our watch.”

https://www.coindesk.com/policy/2024/04/18/mango-markets-exploiter-avi-eisenberg-found-guilty-of-fraud-and-manipulation/


Title: Re: DeFi hacks [history]
Post by: zasad@ on May 08, 2024, 12:55:27 PM
https://cointelegraph.com/news/pike-finance-exploited-1-6-million-second-exploit-3-days

Pike Finance
exploited for $1.6M in second incident in 3 days

"Pike Finance has been exploited, resulting in the loss of $1.68 million worth of digital assets. The incident marks the protocol’s second exploit in three days.

Decentralized finance (DeFi) lending protocol Pike Finance suffered a $1.68 million exploit across the Ethereum, Arbitrum and Optimism chains on April 30, according to a report from on-chain analytics firm CertiK, shared with Cointelegraph.

The attacker used a vulnerability in Pike Finance’s smart contract to change the output address, draining the contract of over $1.4 million worth of Ether , $150,000 worth of Optimism (OP) tokens and over $100,000 worth of Arbitrum (ARB) tokens, according to CertiK."



Title: Re: DeFi hacks [history]
Post by: zasad@ on May 15, 2024, 11:42:26 AM
https://twitter.com/peckshieldalert/status/1786447590042779855
"#PeckShieldAlert #Phishing A whale 0x1E22...8FD5 lost ~1,155 $WBTC (worth ~$71 million) after falling victim to address poisoning.
The phisher has swapped the stolen $WBTC for ~23K $ETH & transferred them out"


https://twitter.com/PeckShieldAlert/status/1788880553653002311
"#PeckShieldAlert ~50% of the stolen funds (~11,446.87 $ETH worth ~$34.7m) has been returned to the victim's address"








Title: Re: DeFi hacks [history]
Post by: zasad@ on May 22, 2024, 12:00:01 PM
https://www.coindesk.com/markets/2024/05/21/gala-games-hacker-returns-23m-in-eth-founder-proposes-buy-and-burn/
"Gala Games Hacker Returns $23M in ETH; Founder Proposes 'Buy and Burn'
Gala investor DWF Labs also said that it had purchased 28 million GALA tokens "to alleviate market selling pressures."

Hacker returned $23 million worth of ether to Gala Games after Monday's exploit.
CEO Eric Schiermeyer said "will probably buy and burn."
Gala investor DWF Labs also said that it had purchased 28 million GALA tokens."