Hot News

Hot News

副标题

Founded in 2020, FameEX is a secure and globally recognized cryptocurrency exchange that has achieved significant milestones over the past few years. As they gear up for their third-year anniversar...
2023-03-08
Bored Apes Yacht Club has risen from virtual avatars to a super IP in the NFT industry with implemented commercial applications, making it a role model for many other PFP successors. Affected by su...
2023-03-08
The Ready Player One, jointly created by several internationally renowned institutions such as Golden Collar U.S.Venture Capital Inc, is a digital ecological platform for games based on blockchain ...
2023-02-01
BitPencil (https://bitpencil.xyz/), a decentralized financial derivative agreement initiated by the Access Bitcoin Foundation, its business includes funds, insurance, options and other financial de...
2023-01-31
7*24

7*24

副标题

On 13 March 2023, CyberConnect, the decentralized social graph protocol is culminating in the wrap of Connected 2023, a Web3 social hackathon organized in partnership with BNBChain, the world’s lar...
2023-03-15
Decentralized social collaboration network DreamLand will be officially launched in mid-March, and its first NFT, Chill Parrot, will be released in April. DreamLand will open Founding Member partne...
2023-03-10
BitValue announced the Investment in Spield Algorithm, which is Shaping the Future of AI Quantitative Analysis.Web3 is rapidly changing the world, and an increasing number of people are recognizing...
2023-03-08
PLXYER, pronounced "player", has announced the launch of their all-in-one Web3.0 game portal platform. This Gaming platform is designed to provide players with a thrilling gaming experience while o...
2023-03-02
iPeakoin, a fintech institution that facilitates a seamless integration between financial and crypto infrastructure, recently announced the launch of its CaaS (Card as a Service), aiming to bring c...
2023-02-27
Funversy, the first NFT ecosystem built on the BNB network, recently launches its Beta Version and updates the functions of Launchpad, Farm and Trade, is committed to creating a new NFT platform wi...
2022-10-28
dYdX said on its social platform that due to excessive user participation, the activity of depositing more than $500 to get a $25 bonus has been stopped. Yesterday's news, dYdX announced that it wi...
2022-09-02
The data on the Tokenview chain shows that the current total holdings of Grayscale is 18.276 billion US dollars, and the trust premium rates of mainstream currencies are as follows: BTC, -32.69% ET...
2022-09-02
Yuga Labs metaverse project Otherside released a new promotional video on its social platform, and hinted that the project may announce new plans in Q4.
2022-09-02
The market shows that Ethereum hit $1,600 per piece, up 1.27% on the day.
2022-09-02
Johnnie Walker, a world-renowned whisky brand, has announced a partnership with NFT marketplace BlockBar and Web3 consultancy Vayner3 to release two new limited-edition "JohnnieWalker Blue Label Gh...
2022-09-02
According to the official Twitter, Volt Protocol and external auditors completed the economic and technical review of Compound Labs v2.0. It also identified risks common to loan pools, as well as C...
2022-09-02
Former Binance Labs head Bill Qian has joined Dubai-based cryptocurrency investment firm Cypher Capital as chairman. Qian will oversee the management and operations of Cypher Capital, which he said...
2022-09-02
According to Reuters, outflow documents show that the U.S. Department of Justice’s anti-money laundering unit in 2020 asked Binance to voluntarily hand over information about Changpeng Zhao and 12 ...
2022-09-02
According to the tip of Twitter user @SomerEsat retweeted by Yearn core developer banteg, the current updated versions of the Ethereum staking consensus client are as follows, Lighthouse's v3.1.0 v...
2022-09-02
Blockchain company Stably announced the issuance of its stablecoin USDS on the XRP Ledger (XRPL), and Ripple will provide Stably with the technical support needed to integrate USDS with the XRP Led...
2022-09-02
At the 2022 World Artificial Intelligence Conference, Qualcomm President and CEO Cristiano Amon's keynote speech pointed to the Metaverse. Ammon believes that the metaverse is the future of the Int...
2022-09-01
64 Celsius escrow account holders filed petitions in bankruptcy court, asking Celsius to return their funds outside of the proceedings. On Wednesday, the panel petitioned the New York Bankruptcy Co...
2022-09-01
The NFT series Fresh Fruit by Doja Cat x JBL released by Doja Cat and JBL headphones has been launched on the music NFT platform OneOf. NFT holders will have the opportunity to get front-row seats ...
2022-09-01
Middle Eastern cryptocurrency exchange Rain Financial has carried out a round of layoffs, although the number of layoffs was not disclosed. Rain Financial said, "We have to adjust future plans to e...
2022-09-01

Inverse Finance exploited again for $1.2M in flash loan oracle attack

Issuing time:2022-07-16 11:50

No user funds have been affected by the exploit, but Inverse Finance has incurred debt and offered the attacker a bounty to return the stolen funds.


Just two months after losing $15.6 million in a price oracle manipulation exploit, Inverse Finance has again been hit with a flash loan exploit that saw the attackers make off with $1.26 million in Tether (USDT) and Wrapped Bitcoin (wBTC).


Inverse Finance is an Ethereum-based decentralized finance (DeFi) protocol and a flash loan is a type of crypto loan that is usually borrowed and returned within a single transaction. Oracles report outside pricing information.


The latest exploit worked by using a flash loan to manipulate the price oracle for a liquidity provider (LP) token used by the protocol’s money market application. This allowed the attacker to borrow a larger amount of the protocol’s stablecoin, Dola (DOLA), than the amount of collateral they posted, letting them pocket the difference.


The attack comes just over two months after a similar April 2 exploit, which saw attackers artificially manipulate collateralized token prices through a price oracle to drain funds using the inflated prices.


In response to the attack, Inverse Finance temporarily paused borrowing and removed DOLA from the money market while it investigated the incident, saying no user funds were at risk.


It later confirmed that only the attacker’s deposited collateral was affected in the incident and only incurred a debt to itself due to the stolen DOLA. It encouraged the attacker to return the funds in return for a “generous bounty.”



In total, the attackers gained 99,976 USDT and 53.2 wBTC from the attack, swapping them to ETH before sending it all through the cryptocurrency mixer Tornado Cash, attempting to obfuscate the ill-gotten gains.


The previous attack in April saw attackers make off with $15.6 million in Ether (ETH), wBTC, Yearn.Finance (YFI) and DOLA.


DeFi marketplace Deus Finance suffered from a similar exploit in March, with attackers manipulating a price pairing within an oracle leading to a gain of 200,000 Dai (DAI) and 1101.8 ETH, worth over $3 million at the time.


Beanstalk Farms, a credit-based stablecoin protocol, lost all $182 million worth of collateral in a flash loan attack caused by two malicious governance proposals, which in the end, drained all funds from the protocol.


How the latest attack went down

Blockchain security firm BlockSec analyzed that the attacker borrowed 27,000 wBTC in a flash loan, swapping a small amount to the LP token used to post collateral in Inverse Finance so users can borrow crypto assets.


The remaining wBTC was swapped to USDT, causing the price of the attacker’s collateralized LP token to rise significantly in the eyes of the price oracle. With the value of these LP tokens now worth far more due to the price rise, the attacker borrowed a larger amount than usual of the DOLA stablecoin.


The value of the DOLA was worth much more than the deposited collateral, so the attacker swapped the DOLA to USDT, and the earlier wBTC to USDT swap was reversed to repay the original flash loan.