Milky Crypto News
  • Home
  • Live Coin Market
  • Live Exchange Market
  • Crypto News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
  • Regulation
  • Trading
  • Scams
No Result
View All Result
  • Home
  • Live Coin Market
  • Live Exchange Market
  • Crypto News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
  • Regulation
  • Trading
  • Scams
No Result
View All Result
Milky Crypto News
No Result
View All Result

Latest Ethereum DeFi exploit sees $14 million stolen from ‘Furucombo’

February 28, 2021
in Ethereum
Reading Time: 4min read
A A
0
Latest Ethereum DeFi exploit sees $14 million stolen from ‘Furucombo’
1
SHARES
4
VIEWS
ShareShareShareShareShare

DeFi exploits and attacks have become increasingly commonplace as the space evolves and attracts both money and participants. The latest of these attacks took place earlier today and saw over $14 million worth of stolen crypto.

Furucombo attacked

Furucombo, an Ethereum-based transaction “batching” protocol, said this morning that the platform had been exploited and asked all users to cease all approvals as caution.

The tool is built for end-users to optimize their DeFi strategy by using a simple ‘drag and drop’ mechanism. The tool allows users who don’t know how to code but understand DeFi markets to create and run their own strategies.

The protocol saw an exploit this morning. “We have deauthorized the relevant components and believe the vulnerability to be patched but we recommend users remove approvals out of an abundance of caution,” Furucombo said in a tweet.

We are working on the next steps and will update our community as soon as we can

Please remove your token approvals on https://t.co/jcZmbiUQOR towards our contract at the earliest.

Our smart contract:0x17e8Ca1b4798B97602895f63206afCd1Fc90Ca5f

— FURUCOMBO (@furucombo) February 27, 2021

As per The Block researcher Igor Igamberdiev, the attacker was able to conduct the exploit by tricking Furucombo’s smart contracts to trust and process a fake dataset belong to a decentralized lending service Aave—a protocol that allows users to take out loans via collateral (or flash loans with no collateral).

 “An attacker using a fake contract made Furuсombo think that Aave v2 has a new implementation, said Igamberdiev in a tweet. He added that this reason caused all interactions with “Aave v2” to be “approved” and sent to an address controlled by the hacker.

On-chain data further shows that the attacker transferred the funds of every user who had ‘approved’ Furucombo to conduct transactions on their behalf, resulting in over $14 million getting stolen. 

Over 3,900 stETH (a staked Ethereum token) and $2.4 million in stablecoin USDC were the biggest bags hit. The attacker/s have been transferring their illicitly-gained stash to privacy mixer Tornado Cash, a tool that masks addresses and allows users to swap cryptocurrencies on-chain.

Taking responsibility

Hsuan-Ting, the CEO of crypto exchange Dinngo, the firm that builds and maintains Furucombo, said the firm takes responsibility for getting attack and asked users to not “worry about any of their losses. 

We are calculating how much is lost and planning what is the mitigation plan,” Hsuan-Ting said, adding:

“Will keep everyone posted. Together we are stronger.”

Meanwhile, Curve Finance’s Julien Bouteloup said on Twitter that such “evil contract” exploits were seemingly the new “holy grail.” 

“evil contract” exploit is the new DeFi Holy Grail🔥

= a contract that fools the protocol into believing it is an existing “safe” contract

Furucombo got fooled with this new contract thinking it was aave v2 stuff. And top users with infinite allowance got rekt…

>$13.5M lost pic.twitter.com/s03egtRO7w

— Julien Bouteloup (@bneiluj) February 27, 2021

He was likely referring to previous attacks on Alpha Finance and Pickle Finance that saw a similar “evil contract” drain millions of dollars in cryptocurrencies by tricking the protocols into approving and accepting fake contracts. The projects mitigated further damage at the time and continue to live on.

Get an edge on the cryptoasset market

Access more crypto insights and context in every article as a paid member of CryptoSlate Edge.

Real-time charts

Price snapshots

More context

Join now for $19/month Explore all benefits

Secure your wealth: Invest in a Crypto Index Fund

Like what you see? Subscribe for updates.


Credit: Source link

ShareTweetSharePinShare
Previous Post

Google Teams With D-Wave in Massive Quantum Computing Leap, Cracking Simulation Problem

Next Post

Litecoin creator Charlie Lee says NFTs are like ICOs in 2017

Related Posts

Currency Markets Could Blow Up and Send Money Into Crypto, Gold, Stocks and Bonds: Raoul Pal
Ethereum

Currency Markets Could Blow Up and Send Money Into Crypto, Gold, Stocks and Bonds: Raoul Pal

March 28, 2022
Bitcoin flirting with $48,000 as hodlers kept buying throughout Q1
Ethereum

Bitcoin flirting with $48,000 as hodlers kept buying throughout Q1

March 28, 2022
Retail giant El Corte Inglés and Deloitte in cahoots to launch crypto exchange
Ethereum

Retail giant El Corte Inglés and Deloitte in cahoots to launch crypto exchange

March 28, 2022
Madonna enters Metaverse with $560,000 Bored Ape NFT purchase
Ethereum

Madonna enters Metaverse with $560,000 Bored Ape NFT purchase

March 25, 2022
Load More
Next Post
Litecoin creator Charlie Lee says NFTs are like ICOs in 2017

Litecoin creator Charlie Lee says NFTs are like ICOs in 2017

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Avid Gamers Set to Own Lands as Metagods Announces Land Sale – Press release Bitcoin News

Avid Gamers Set to Own Lands as Metagods Announces Land Sale – Press release Bitcoin News

March 25, 2022
Rare Indicator Suggests Massive Bitcoin Bull Run About To Begin, Says Popular Crypto Analyst

Rare Indicator Suggests Massive Bitcoin Bull Run About To Begin, Says Popular Crypto Analyst

March 28, 2022
One Low-Cap Altcoin Is Ready To Launch Rally To Revisit All-Time High, According to Crypto Strategist

Shark Tank Kevin O’Leary Reveals Where He Sees the Most Opportunity in Crypto Space

March 28, 2022
A Brief Introduction to the Rapid Expansion of the Gaming Industry

A Brief Introduction to the Rapid Expansion of the Gaming Industry

March 28, 2022
EU Removes Proof of Work Ban Clauses On MiCA Regulation

EU Removes Proof of Work Ban Clauses On MiCA Regulation

March 28, 2022
Acala Secures Polkadot’s First Parachain After Narrowly Edging Out Moonbeam

Acala’s New $250 Million Fund To Drive Adoption of aUSD On Polkadot

March 24, 2022
Milky Crypto News

This is an online news portal that aims to provide the latest crypto news and real-time updates around the world. Feel free to get in touch with us!

What’s New Here!

  • NFT of Nelson Mandela’s Arrest Warrant Raises $130,000 – Metaverse Bitcoin News
  • Vietnam Developing Legal Framework For Crypto
  • DeSo Blockchain Users Exceeds 1.5 Million, Decentralized Social Token up Nearly 90% within 24 hrs
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - MilkyCrypto.io - All rights reserved!

No Result
View All Result
  • Home
  • Live Coin Market
  • Live Exchange Market
  • Crypto News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
  • Regulation
  • Trading
  • Scams