Bitcoin Forum
November 13, 2024, 08:16:19 PM *
News: Check out the artwork 1Dq created to commemorate this forum's 15th anniversary
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Defrost Finance Savage Scam  (Read 74 times)
Wapfika (OP)
Hero Member
*****
Offline Offline

Activity: 1442
Merit: 597


Bitcoin makes the world go 🔃


View Profile
January 04, 2023, 04:04:25 PM
 #1

Defrost finance claimed that their V2 smart contract was exploited, and that attacker used a flash loan to withdraw funds.

However, the V1 contracts had been hacked as well resulting in the $12M loss. The oracle address in the protocol’s collateral vaults was replaced with a malicious one, that triggered liquidations of collateralized user funds.

The creator of the multisig wallet, which has to approve the oracle replacement function before it executes, is the same address that requested the oracle replacements.

They are claiming that the wallet is compromised while they are using a multisig wallet which is impossible to be hacked.

Fun part was they they insured there company 1 month before this rug pull for an oracle failure. They are claiming that the hack is the result of an oracle failure and they are using it as an escape to this epic savage scam.


Source: https://happyblocklabs.com/v/The-MOST-EVIL-Crypto-SCAM-Boris-and-Bob-Rug-Pulled-19mln0

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Yogee
Sr. Member
****
Offline Offline

Activity: 1554
Merit: 413


View Profile
January 04, 2023, 04:54:12 PM
 #2

So they've been caught lying by different audit teams or investigators then the "hacker" suddenly returned the entire "stolen" funds in exchange of a promised 20% bounty.

Defiyield is asking good questions here,
Quote
Why has “the hacker” returned the full amount of $12M? Why haven’t they taken the proposed 20% Bounty? Or have they sent back the “stolen” $12M and hoped that the Defrost Team will return the promised 20% back (unrealistic scenario, but anyway)?

They're now in the process of "refunding" hehe. They probably did so because they've been KYC'd by the insurance platforms they partnered with.

The report also says the same people founded another platforms that was supposedly "exploited" in 2021.
cabron
Hero Member
*****
Offline Offline

Activity: 3010
Merit: 613


https://www.betcoin.ag


View Profile WWW
January 04, 2023, 05:06:44 PM
 #3

This Oracle manipulation resembles the attack that happened on Mango Market also where the attacker then returns the rest of the funds and some are kept as bounties for finding out the exploit. It's said that this is a common exploit of oracles, draining the user's funds.

This one, however, seems like the dev team is involved in scamming the users.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!