Hacker Exploits Sturdy Finance, Drains $800,000 From The Lending Protocol

Share This Post

DeFi lending protocol, Sturdy Finance has lost nearly $800,000 in ETH to an attack. The protocol confirmed the incident in a June 12 tweet after receiving an alert from blockchain security firm, PeckShield. According to the report, the hacker exploited a vulnerability in Sturdy Finance’s price oracle, gaining access to drain funds from the protocol’s liquidity pool. 

The DeFi protocol said it had suspended all market transactions while taking further actions to analyze the situation.

Hacker Moves 442 ETH Stolen From Sturdy Finance To Tornado Cash

According to security firm BlockSec, Sturdy Finance’s hacker leveraged read-only reentrancy on the protocol’s price Balancer to manipulate the BstETH-STABLE price. As a result, the hacker carted away 442 ETH worth approximately $800,000 at the time of writing. 

Related Reading: Venture Firm Andreessen Horowitz To Open 1st UK Office Amid Crypto Scrutiny In US

PeckShield was the first to alert the protocol about the price manipulation-related transaction on its platform on June 12. In response, Sturdy Finance suspended its markets, assuring users of the safety of the remaining funds. The protocol also said users need not take any actions, adding that it will share more updates regarding the issue soon.

Regardless of the swift response from Sturdy Finance, PeckShield confirmed the attacker moved nearly all ETH through the currency mixer Tornado Cash. According to the security firm, the hackers have already transferred 442 ETH to Tornado Cash.

ETHUSD PRICE CHART

Other Crypto Scams And Hack Exploitations

Over the past few months, several DeFi protocols have lost millions of dollars in digital assets to exploits. The price manipulation method used by the Sturdy Finance hackers is prevalent among DeFi hack exploitations as hackers have repeatedly employed similar methods to drain funds from decentralized finance protocols in the past months.

Through price oracle exploitations, hackers can use a single transaction to call a function multiple times before the initial call is complete. The strategy enables them to withdraw more funds than is possible with a single transaction.

These are not the only ways hackers have stolen funds from crypto users though. According to a recent report, scammers hijacked Twitter accounts belonging to prominent crypto community members, using them to promote scam projects. 

On-chain sleuth ZachXBT reported that scammers stole nearly $1 million in crypto assets after hijacking a Twitter account belonging to influential DJ Steve Aoki, Pudgy Penguins founder Cole Villemain, and Peter Schiff.

Also, prominent pro-XRP lawyer and founder of CryptoLaw, John E. Deaton, reported that scammers hijacked his account. The hackers used Deaton’s account to promote a scam token dubbed $LAW. 

Related Reading: Bitcoin Diamond Hands Unfazed By Recent FUD As Exchange Inflows Remain Very Low

In another development, the US Department of Justice charged two Russian nationals allegedly involved in the 2014 Mt. Gox hack exploitation. 

The Mt. Gox exploitation, which resulted in the loss of thousands of Bitcoins, remains one the largest single hack in the history of crypto. According to the DOJ, Alex Bilyuchenko, aged 43, and Aleksandr Verner, aged 29, conspired to steal and launder 647,000 BTC from Mt. Gox.

Read Entire Article
spot_img

Related Posts

NFT Market Sees Over 30% Decline in Weekly Sales

From April 27 to May 4, 2024, non-fungible token (NFT) sales amassed $1644 million, reflecting a 3016% decrease compared to the previous week Leading the field in blockchain sales, Bitcoin-based NFT

PEPE Primed For A Big Leap: 80% Price Increase Incoming?

The cryptocurrency market may be experiencing a cool down, but one meme coin is refusing to catch a cold PEPE, a token emblazoned with the internet’s famous frog, has defied recent bearish

Friend.tech Fiasco: Token Tanks 98% After Airdrop Fails To Deliver

Friendtech, a social media platform built on the Ethereum blockchain, aimed to celebrate the launch of its version 2 protocol with an airdrop of its native token, FRIEND However, the well-intentioned

Grayscale’s Bitcoin Trust Halts 78-Day Outflow Streak With $63M Inflow

Statistics indicate that after a prolonged period of 78 days, Grayscale’s Bitcoin Trust has ceased experiencing outflows, observing an infusion of $63 million on Friday, equating to around

Injective (INJ) Price In Danger If It Falls To Crucial Support Level: Analyst

INJ, the native token of the Injective Network, commenced May with a fluctuating price action marked by a series of significant losses and gains As INJ attempts to establish a stable price

Investor Falls Victim To $71 Million Address Poisoning Scam

In a concerning turn of events, an anonymous crypto trader has lost approximately $71 million worth of assets in an address poisoning scam This incident has roused much tension in the crypto
- Advertisement -spot_img