1. Home
  2. attack

attack

Zunami Protocol confirms stablecoin pools attacked, $2.1M loss estimated

Blockchain security firm PeckShield estimates the protocol suffered more than $2.1 million from the price manipulation attack.

Decentralized finance protocol Zunami Protocol has confirmed it has encountered an attack on its “zStables” stablecoin pools.

Blockchain security firm PeckShield estimates over $2.1 million was stolen from Zumani’s Curve Pool on Aug. 13, pegging the exploit to a price manipulation issue. Fellow blockchain security firm Ironblocks arrived at a similar figure.

PeckShield detected the exploit on Curve on Aug. 13 at 10:47 UTC, which was confirmed by Zunami about 20 minutes later.

Zunami said that collateral in the pools remain secure and that the issue is now under investigation.

It is currently believed a flash loan price manipulation attack has taken place, with Zunami UZD and Zunami ETH pools impacted

Zunami is a decentralized revenue aggregator protocol that allows users to stake stablecoins for yield, with its largest stable pools situated on Curve.

Cointelegraph reached out to Zunami for comment but did not receive an immediate response.

This is a developing story, and further information will be added as it becomes available.

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering

Bitcoin Network Overwhelmed by 390,000 Unconfirmed Transactions and Surging Fees

Bitcoin Network Overwhelmed by 390,000 Unconfirmed Transactions and Surging FeesIn just under two weeks, the number of unconfirmed transactions on the Bitcoin network has skyrocketed from 134,000 to over 390,000, causing a bottleneck in the mempool. This surge in unconfirmed transactions has resulted in a staggering 343% increase in transaction fees, which have risen from $1.99 per transaction on April 26 to a current […]

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering

Euler Finance’s offer to hacker: Keep $20M or face the law

The hacker committed a $196 million flash loan attack on the Ethereum-based lending protocol on March 13.

Ethereum-based noncustodial lending protocol Euler Finance is trying to cut a deal with the exploiter that stole millions from its protocol, demanding the hacker returns 90% of the funds they stole within 24 hours or face legal consequences.

Euler Labs sent its ultimatum to the flash loan attacker who exploited the platform for $196 million by transferring the hacker 0 Ether (ETH) with an attached message on March 14:

“Following up on our message from yesterday. If 90% of the funds are not returned within 24 hours, tomorrow we will launch a $1M reward for information that leads to your arrest and the return of all funds.”

The threat of law enforcement comes as Euler sent the hacker a much more civil message the day before.

“We understand you are responsible for this morning’s attack on the Euler platform,” it read. “We are writing to see whether you would be open to speaking with us about any potential next steps.”

The request for a 90% fund return would see the hacker send back $176.4 million while holding onto the remaining $19.6 million.

However, many observers have noted that the hacker has very little to no incentive to follow through with the deal.

“If I was the hacker I’d simply say ‘to anyone who manages to track me down, I will give you $2 million not to tell Euler,’” one observer said.

“Yeh he has 200 Million they have 2 Million. He wins in a bidding war,” another Twitter user wrote in response.

Euler Labs said it was already working with law enforcement in the United States and the United Kingdom, along with engaging blockchain intelligence platforms Chainalysis, TRM Labs and the broader Ethereum community, to help track down the hacker.

Related: DeFi protocol Platypus suffers $8.5M flash loan attack, suspect identified

The lending platform added it was able to promptly stop the flash loan attack by blocking deposits and the “vulnerable” donation function.

As for the exploited code, the team explained that the vulnerability “was not discovered” in the audit of its smart contract, which had existed on-chain for eight months until bei exploited on March 13.

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering

Russian Court Sends 3 Crypto Robbers to Strict-Regime Prison

Russian Court Sends 3 Crypto Robbers to Strict-Regime PrisonThree Russians are going to spend time in high-security prison for stealing over a million U.S. dollars’ worth of cryptocurrency from another man. In addition, the court has also ordered them to fully compensate the victim for the damages, prosecutors announced. Robbers Get Prison Sentence for Cryptocurrency Theft in Russia A court in the Russian […]

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering

Court to Try 2 Russians for Stealing 86 Bitcoins From Crypto Miner

Court to Try 2 Russians for Stealing 86 Bitcoins From Crypto MinerTwo residents of the Russian city of Tomsk will be tried for “large-scale robbery” involving the theft of cryptocurrency worth millions of rubles from a local miner. The digital coins were stolen from the owner at gunpoint, authorities said, adding that both criminals are now in custody. Thieves Face Trial in Russia for Armed Robbery […]

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering

Darknet Market Solaris Hacked by Competitor, Elliptic Reveals

Darknet Market Solaris Hacked by Competitor, Elliptic RevealsA leading marketplace on the dark web, Solaris, has been hit by a rival, according to crypto analytics company Elliptic. The Russia-linked platform, which tried to occupy space vacated by the busted Hydra, is believed to have conquered up to a fifth of the illicit market before the hack. Solaris Allegedly Taken Over by Darknet […]

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering

Onchain Researchers Discover $63M in Ethereum From Harmony Bridge Attack Moved, Hackers Attempt to Launder Funds on Major Exchanges

Onchain Researchers Discover M in Ethereum From Harmony Bridge Attack Moved, Hackers Attempt to Launder Funds on Major ExchangesOn Jan. 15, 2023, onchain researchers discovered that funds stolen during the Harmony bridge attack had been moved. The suspected thieves, who are allegedly associated with the North Korean hacking syndicate Lazarus Group, moved 41,000 ethereum, worth $63.2 million at current exchange rates. Onchain Researchers Track Stolen Ethereum From Harmony Bridge Attack and Help Major […]

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering

Hackers Hit Romanian Hospital, Demand Bitcoin Ransom

Hackers Hit Romanian Hospital, Demand Bitcoin RansomA hospital in Romania has been targeted in a ransomware attack with the perpetrators seeking payment in cryptocurrency to decrypt its database. The hack prevents the medical institution from reporting to the country’s health insurance fund in order to receive due funding. Botoşani Hospital Blackmailed for Bitcoin, Romanian Media Reports The Saint Gheorghe Recovery Hospital […]

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering

Defrost Finance breaks silence on ‘exit scam’ accusations, denies rug pull

Defrost Finance had not publicly commented on the rug-pull accusations in the media until now.

Defrost Finance, the decentralized trading platform that suffered a $12 million exploit in the days leading up to Christmas, has denied allegations that it had “rugged” its users as part of an elaborate “exit scam.”

On Dec. 23, the platform announced it suffered a flash loan attack, leading to the draining of user funds from its v2 protocol. One day later, another incident saw a hacker steal the admin key for a second “much larger” attack on the v1 protocol.

It’s understood the attacker or attackers conducted the flash loan attack by adding a fake collateral token and a malicious price oracle to liquidate users.

Observers, including blockchain security firms Peckshield and CertiK, as well as asset management platform DeFiYield, have suggested based on “community intel” that members of the team may have been behind the “exit scam” — given the fact that an admin key was required to perpetrate the exploit.

However, in an exclusive statement to Cointelegraph on Dec. 28, the team behind Defrost Finance broke its silence on the accusations, stating:

“We deny the accusations that the team rugged users. A compromised key does not equate to a rugpull, as much as the episode may raise doubts among the public.”

Defrost made two key arguments to deny its involvement.

Firstly, Defrost argued that if they had planned to orchestrate a rug pull, they would’ve done it months ago when its total value locked (TVL) neared $200 million.

According to DefiLlama, Defrost Finance’s TVL had fallen to just $13.14 million on Dec. 23, the day of the first attack.

“Anyone behind a rugpull would have probably defrauded investors when our TVL was 15 times what it is today.”

Secondly, Defrost argued that if they had been the perpetrators they would have “fled” long ago, which they haven’t done.

“[Anyone] anticipating the inevitable attention from the crypto community would have fled long ago. Yet here we are, working to get the funds back to their rightful owners,” it said.

Defrost Finance’s statement came just hours after decentralized finance investment platform DeFiYield in a Medium blog post on Dec. 27 again accused Defrost Finance of “rug pulling” its users.

DeFiYield pointed to on-chain data that it claimed suggested the creator of the multisig wallet was the same address that requested and then later approved the transactions that inserted the malicious source oracle that liquidated users.

It also alleged the developers behind Defrost Finance were the same as those of Phoenix Finance (FinNexus) which was exploited for $7.6 million in May 2021 in what some have also speculated was an “inside job.”

Related: Here's how Defrost Finance plans to refund users following $12M hack

Defrost said it regrets being unable to share more details about the attack, as its priority has been helping users retrieve their funds.

"There are several issues that we would like to address in recent reports concerning Defrost Finance. We regret we cannot get deep enough into some details — but surely the community will understand this is a sensitive matter and our priority must be to help our users retrieve their funds. All other concerns are secondary to this,” it said.

The team is certainly unhappy about the allegations and earlier on Dec. 28 warned members of its Telegram group that it will ban members that attempt to perpetrate the “false narrative” that the Defrost team is responsible for the recent attacks.

“At this point, it’s not conducive to moving forward to continue allow [sic] the public chats to operate like the Wild Wild West. Will be implementing stricter protocols.”

A post on Defrost Finance's Telegram group by a core team member. Source: Telegram

On Dec. 26, Defrost announced on Twitter it had managed to recover all the funds taken in the v1 hack, sharing in a post on Medium hours later that it has begun the process of returning funds to affected users.

The Ethereum wallet controlled by Defrost that is being used to facilitate the return of funds currently shows that $2.9 million of Ether (ETH) has been returned, along with $9.9 million worth of Dai (DAI).

“This will take a little time since we need to map who had what and where, but the wheels are turning fast and the entire process will be managed through smart contracts. It will be fully transparent and fairly swift,” Defrost told Cointelegraph in its recent statement.

No word was given about the v2 protocol as of yet, however.

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering

Ukrainian Steals Bitcoin From Russian Darknet Market, Donates to Charity

Ukrainian Steals Bitcoin From Russian Darknet Market, Donates to CharityA Ukrainian living in the U.S. has reportedly hacked a major drug market on the Russian dark web, diverting some of its crypto proceeds. The man says he donated the digital cash stolen from the illicit website to an organization delivering humanitarian aid across his war-torn homeland. Wisconsin Resident With Ukrainian Roots Hacks Russian Dark […]

Microstrategy Unleashes $2.6B Bet on Bitcoin With Convertible Notes Offering