BonqDAO protocol suffers $120M loss after oracle hack

Share This Post

An oracle hack allowed the exploiter to manipulate the price of the AllianceBlock token, leading to an estimated $120 million loss, according to Peckshield.

A small-scale decentralized autonomous organization (DAO) has suffered a rather sizeable smart contract exploit leading to an estimated $120 million being stolen from its protocol.

BonqDAO, which is behind the Bonq protocol, told its Twitter followers on Feb. 1 that its protocol was exposed to an oracle hack that allowed the exploiter to manipulate the price of the AllianceBlock (ALBT) token.

An independent analysis from blockchain security firm PeckShield has estimated the loss from the Bonq hack to be around $120 million, comprising $108 million from 98.65 million BEUR tokens, and $11 million from 113.8 million wrapped-ALBT (wALBT) tokens.

While the exploit took effect over several transactions, the largest was $82.19 million at 6:32pm UTC time on Feb. 1, according to multi-chain portfolio tracker DeBank.

Most of the high-scale transactions took place on the Polygon network.

How it happened

PeckShield explained that the exploiter was able to change the updatePrice function of the oracle in one of BonqDAO’s smart contracts which meant that they were able to manipulate the price of the wALBT token.

This triggered the exploitation of the wALBT and BEUR. The hacker then swapped about $500,000 worth of BEUR for USDC on Uniswap before burning all 113.8 million wALBT to unlock ALBT.

On-chain security observer “Spreek” — who was one of the first to spot the exploit — stated to his 18,800 Twitter followers that the exploiter later dumped more BEUR and ALBT tokens for some USDC ($500,000) and 144 ETH (236,000).

PeckShield and others noted that the price of the BEUR and ALBT tokens went down considerably in a short period of time:

In a follow up tweet, BonqDAO said it has paused the protocol and is working on a recovery solution.

“Other troves remain unaffected. Bonq protocol has been paused. We’re working on a solution that will allow users to withdraw all remaining collateral without repaying BEUR in the troves. It will be released tomorrow morning CET,” it said.

AllianceBlock — the token issuers of ALBT — also shared the news on Feb. 1, explaining to its 51,300 Twitter followers that an exploiter managed to gain access to 113.8 million ALBT tokens.

The team is in the process of removing all liquidity on Bonq and has halted exchange trading, it said, adding that no smart contracts were exploited on AllianceBlock.

The announcement from AllianceBlock also added that they would mint new ALBT tokens to those impacted by the exploit up until the time of the announcement.

Related: Tribe DAO votes in favor of repaying victims of $80M Rari hack

BonqDAO is a decentralized autonomous organization (DAO) which aims to provide self-soverign financial services to individuals and businesses interest-free without giving up ownership of their assets.

AllianceBlock is a decentralized infrastructure platform that connects traditional financial institutions to Web3 applications.

Read Entire Article
spot_img

Related Posts

Republic First Bank Fails, Triggers Minor Crypto Market Downturn Amid Banking Sector Concerns

The United States witnessed its first banking failure of 2024 with the closure of Philadelphia-based Republic First Bank, creating ripples within the cryptocurrency community as Bitcoin, Ether, and

New UK Law Empowering Authorities to Seize and Destroy Crypto Assets Takes Effect Today

A new law enabling the National Crime Agency and police to seize, freeze, and destroy crypto assets is now in effect in the UK Under this law, police can seize crypto from suspects without needing to

New Data Reveals Bitcoin Mining May No Longer Be Profitable – Here’s Why

New data has revealed that Bitcoin (BTC) mining might no longer be as lucrative as it used to be Bloomberg has reported that the profitability of Bitcoin mining is nearing a record low, not seen

Forbes Unveils 20 Crypto ‘Zombies,’ Declares Ripple And XRP Among The Undead

In a controversial report, Forbes unveiled a list of 20 “crypto billion-dollar zombies,” Layer 1 (L1) tokens, which the news outlet defines as crypto assets with substantial valuations

Stablecoins Gain Ground as Global Financial Asset

According to Chainalysis’ “Crypto Spring Report,” stablecoin adoption and market importance are seeing a rapid increase in 2024, with a significant rise in the number of addresses holding them

Ethereum Sell Side Liquidity Thinning On CEXes: Time For $4,000?

Taking to X on April 26, one analyst notes that there is a high probability of Ethereum spiking in the sessions ahead because of thinning sell-side liquidity across major centralized exchanges like
- Advertisement -spot_img