• bitcoinBitcoin (BTC) $ 66,465.00
  • ethereumEthereum (ETH) $ 3,596.72
  • tetherTether (USDT) $ 0.999107
  • bnbBNB (BNB) $ 608.67
  • solanaSolana (SOL) $ 148.91
  • staked-etherLido Staked Ether (STETH) $ 3,595.62
  • usd-coinUSDC (USDC) $ 0.999972
  • xrpXRP (XRP) $ 0.489451
  • dogecoinDogecoin (DOGE) $ 0.135848
  • the-open-networkToncoin (TON) $ 8.04
  • cardanoCardano (ADA) $ 0.415422
  • shiba-inuShiba Inu (SHIB) $ 0.000021
  • avalanche-2Avalanche (AVAX) $ 29.85
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 66,499.00
  • tronTRON (TRX) $ 0.116289
  • chainlinkChainlink (LINK) $ 15.12
  • polkadotPolkadot (DOT) $ 6.38
  • uniswapUniswap (UNI) $ 11.57
  • bitcoin-cashBitcoin Cash (BCH) $ 426.93
  • nearNEAR Protocol (NEAR) $ 5.64
  • litecoinLitecoin (LTC) $ 78.69
  • matic-networkPolygon (MATIC) $ 0.619028
  • wrapped-eethWrapped eETH (WEETH) $ 3,738.23
  • leo-tokenLEO Token (LEO) $ 5.89
  • daiDai (DAI) $ 0.999733
  • pepePepe (PEPE) $ 0.000012
  • internet-computerInternet Computer (ICP) $ 9.45
  • kaspaKaspa (KAS) $ 0.157032
  • ethereum-classicEthereum Classic (ETC) $ 25.43
  • fetch-aiFetch.ai (FET) $ 1.47
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,579.90
  • aptosAptos (APT) $ 7.85
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • moneroMonero (XMR) $ 177.10
  • render-tokenRender (RNDR) $ 8.31
  • hedera-hashgraphHedera (HBAR) $ 0.085697
  • filecoinFilecoin (FIL) $ 5.24
  • mantleMantle (MNT) $ 0.897362
  • stellarStellar (XLM) $ 0.098860
  • cosmosCosmos Hub (ATOM) $ 7.20
  • blockstackStacks (STX) $ 1.90
  • okbOKB (OKB) $ 45.86
  • arbitrumArbitrum (ARB) $ 0.921370
  • crypto-com-chainCronos (CRO) $ 0.098357
  • dogwifcoindogwifhat (WIF) $ 2.57
  • immutable-xImmutable (IMX) $ 1.69
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998305
  • injective-protocolInjective (INJ) $ 25.01
  • suiSui (SUI) $ 0.952724
  • optimismOptimism (OP) $ 2.10
  • makerMaker (MKR) $ 2,426.74
  • the-graphThe Graph (GRT) $ 0.235336
  • bittensorBittensor (TAO) $ 307.15
  • vechainVeChain (VET) $ 0.029404
  • notcoinNotcoin (NOT) $ 0.020089
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,992.62
  • flokiFLOKI (FLOKI) $ 0.000206
  • lido-daoLido DAO (LDO) $ 2.17
  • arweaveArweave (AR) $ 28.47
  • jasmycoinJasmyCoin (JASMY) $ 0.036792
  • fantomFantom (FTM) $ 0.633085
  • ondo-financeOndo (ONDO) $ 1.18
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,726.51
  • theta-tokenTheta Network (THETA) $ 1.69
  • bonkBonk (BONK) $ 0.000025
  • bitget-tokenBitget Token (BGB) $ 1.15
  • thorchainTHORChain (RUNE) $ 4.65
  • celestiaCelestia (TIA) $ 8.07
  • based-brettBrett (BRETT) $ 0.155806
  • coredaoorgCore (CORE) $ 1.63
  • whitebitWhiteBIT Coin (WBT) $ 9.62
  • eosEOS (EOS) $ 0.651572
  • pyth-networkPyth Network (PYTH) $ 0.362001
  • aaveAave (AAVE) $ 85.20
  • sei-networkSei (SEI) $ 0.413669
  • algorandAlgorand (ALGO) $ 0.153959
  • ethenaEthena (ENA) $ 0.761126
  • jupiter-exchange-solanaJupiter (JUP) $ 0.908477
  • starknetStarknet (STRK) $ 0.929969
  • quant-networkQuant (QNT) $ 82.91
  • galaGALA (GALA) $ 0.032891
  • cheeleeCheelee (CHEEL) $ 20.47
  • flare-networksFlare (FLR) $ 0.027051
  • gatechain-tokenGate (GT) $ 8.57
  • flowFlow (FLOW) $ 0.718487
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,629.22
  • beam-2Beam (BEAM) $ 0.020128
  • kucoin-sharesKuCoin (KCS) $ 10.40
  • axie-infinityAxie Infinity (AXS) $ 6.70
  • bitcoin-svBitcoin SV (BSV) $ 49.33
  • bittorrentBitTorrent (BTT) $ 0.00000100
  • ordinalsORDI (ORDI) $ 45.46
  • zebec-protocolZebec Protocol (ZBC) $ 0.018567
  • tokenize-xchangeTokenize Xchange (TKX) $ 11.66
  • dydx-chaindYdX (DYDX) $ 1.52
  • elrond-erd-2MultiversX (EGLD) $ 33.09
  • neoNEO (NEO) $ 12.71
  • chilizChiliz (CHZ) $ 0.100462
  • pendlePendle (PENDLE) $ 5.67
  • the-sandboxThe Sandbox (SAND) $ 0.381186
  • gnosisGnosis (GNO) $ 330.23
  • roninRonin (RON) $ 2.57
  • worldcoin-wldWorldcoin (WLD) $ 3.44
  • wormholeWormhole (W) $ 0.453215
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,589.41
  • akash-networkAkash Network (AKT) $ 3.38
  • oasis-networkOasis Network (ROSE) $ 0.118733
  • tezosTezos (XTZ) $ 0.809582
  • singularitynetSingularityNET (AGIX) $ 0.616340
  • msolMarinade Staked SOL (MSOL) $ 177.92
  • conflux-tokenConflux (CFX) $ 0.190386
  • ethereum-name-serviceEthereum Name Service (ENS) $ 24.08
  • nexoNEXO (NEXO) $ 1.34
  • livepeerLivepeer (LPT) $ 22.72
  • mina-protocolMina Protocol (MINA) $ 0.656487
  • usddUSDD (USDD) $ 0.999121
  • ecasheCash (XEC) $ 0.000036
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.007172
  • havvenSynthetix Network (SNX) $ 2.19
  • decentralandDecentraland (MANA) $ 0.384078
  • dexeDeXe (DEXE) $ 12.53
  • book-of-memeBOOK OF MEME (BOME) $ 0.010354
  • frax-etherFrax Ether (FRXETH) $ 3,574.12
  • fasttokenFasttoken (FTN) $ 2.21
  • lido-staked-solLido Staked SOL (STSOL) $ 175.74
  • safeSafe (SAFE) $ 1.59
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.52
  • aioz-networkAIOZ Network (AIOZ) $ 0.615522
  • apecoinApeCoin (APE) $ 1.06
  • klay-tokenKlaytn (KLAY) $ 0.179198
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,859.86
  • fraxFrax (FRAX) $ 0.997390
  • swethSwell Ethereum (SWETH) $ 3,799.68
  • iotaIOTA (IOTA) $ 0.190380
  • mantra-daoMANTRA (OM) $ 0.751851
  • kavaKava (KAVA) $ 0.557649
  • nervos-networkNervos Network (CKB) $ 0.013118
  • tether-goldTether Gold (XAUT) $ 2,332.03
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000104
  • rocket-poolRocket Pool (RPL) $ 28.18
  • heliumHelium (HNT) $ 3.40
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,911.15
  • constitutiondaoConstitutionDAO (PEOPLE) $ 0.110011
  • magaMAGA (TRUMP) $ 11.90
  • axelarAxelar (AXL) $ 0.781638
  • theta-fuelTheta Fuel (TFUEL) $ 0.081494
  • aevo-exchangeAevo (AEVO) $ 0.626566
  • illuviumIlluvium (ILV) $ 79.68
  • 1inch1inch (1INCH) $ 0.419579
  • blurBlur (BLUR) $ 0.309047
  • ioio.net (IO) $ 5.45
  • xdce-crowd-saleXDC Network (XDC) $ 0.034126
  • bitcoin-goldBitcoin Gold (BTG) $ 28.38
  • true-usdTrueUSD (TUSD) $ 0.996816
  • iotexIoTeX (IOTX) $ 0.050396
  • woo-networkWOO (WOO) $ 0.248381
  • corgiaiCorgiAI (CORGIAI) $ 0.001362
  • stader-ethxStader ETHx (ETHX) $ 3,707.92
  • ether-fiEther.fi (ETHFI) $ 4.01
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.11
  • raydiumRaydium (RAY) $ 1.74
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000022
  • astarAstar (ASTR) $ 0.078369
  • arkhamArkham (ARKM) $ 1.89
  • pax-goldPAX Gold (PAXG) $ 2,327.11
  • memecoin-2Memecoin (MEME) $ 0.021301
  • apenftAPENFT (NFT) $ 0.00000043
  • golemGolem (GLM) $ 0.427445
  • polymeshPolymesh (POLYX) $ 0.400113
  • aerodrome-financeAerodrome Finance (AERO) $ 0.849234
  • manta-networkManta Network (MANTA) $ 1.28
  • paypal-usdPayPal USD (PYUSD) $ 0.997504
  • curve-dao-tokenCurve DAO (CRV) $ 0.328593
  • ocean-protocolOcean Protocol (OCEAN) $ 0.627646
  • stepnGMT (GMT) $ 0.193302
  • dydxdYdX (ETHDYDX) $ 1.52
  • compound-ethercETH (CETH) $ 72.25
  • usdbUSDB (USDB) $ 0.999744
  • osmosisOsmosis (OSMO) $ 0.608273
  • echelon-primeEchelon Prime (PRIME) $ 9.92
  • kusamaKusama (KSM) $ 26.58
  • wemix-tokenWEMIX (WEMIX) $ 1.09
  • pepecoin-2PepeCoin (PEPECOIN) $ 3.31
  • biconomyBiconomy (BICO) $ 0.471892
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.004238
  • mx-tokenMX (MX) $ 3.83
  • safepalSafePal (SFP) $ 0.807941
  • compound-governance-tokenCompound (COMP) $ 53.69
  • aragonAragon (ANT) $ 9.18
  • radixRadix (XRD) $ 0.034866
  • holotokenHolo (HOT) $ 0.002048
  • zilliqaZilliqa (ZIL) $ 0.019639
  • superfarmSuperVerse (SUPER) $ 0.801231
  • dymensionDymension (DYM) $ 2.04
  • celoCelo (CELO) $ 0.664872
  • terra-luna-2Terra (LUNA) $ 0.516982
  • jito-governance-tokenJito (JTO) $ 2.88
  • altlayerAltLayer (ALT) $ 0.228871
  • ankrAnkr Network (ANKR) $ 0.034810
  • 0x0x Protocol (ZRX) $ 0.410610

Lending protocol Sturdy Finance drained of $800,000 in security attack

0 187

Lending protocol Sturdy Finance drained of $800,000 in security attack

Sturdy Finance, a decentralized lending protocol, fell victim to a security attack today, which led to a loss of 442 ether or about $800,000. The unknown attacker took advantage of a reentrancy vulnerability that later facilitated manipulation of a faulty price oracle, thereby enabling them to siphon off funds.

In decentralized finance (DeFi) applications, price oracles are pivotal as they provide real-world price data. However, they also represent a potential target for hackers who can exploit them for security breaches.

The attack on Sturdy Finance was initiated by a reentrancy attack, a method typically used to illicitly withdraw funds from DeFi protocols. This type of attack takes advantage of the ability to call a function repeatedly within a single transaction before the original function call is completed. This, in turn, allows the attacker to withdraw more funds than they would legitimately be entitled to.

After the attacker established the ability to manipulate the function calls, they then proceeded to exploit the price oracle. Sturdy Finance’s price oracle, derived from a separate “read-only” smart contract, was manipulated. This oracle was designed to determine the accurate market value of assets in a liquidity pool managed by Sturdy’s team on the Balancer decentralized exchange, thus facilitating the trading of staked ether (stETH). However, the exploitation of the oracle enabled the attacker to drain funds from Sturdy.

BlockSec, a security firm, stated, «The root cause is due to the typical Balancer’s read-only reentrancy, while the price of B-stETH-STABLE was manipulated.»

Sturdy pauses markets

Sturdy Finance reacted to the attack by suspending all of its markets to prevent further potential losses, assuring its users that no other funds were in danger as a result of the breach.

“All markets have been paused; no additional funds are at risk, and no user actions are required at this time,” said the team. “We will be sharing more information as soon as we have it.”
After the attack, on-chain data shows that the attacker used the Tornado Cash mixer to obscure the activity.

In 2022, Sturdy Finance raised $3 million in a series of rounds to construct an interest-free borrowing and lending platform. The funding was lead by Pantera and also saw participation from Y Combinator, SoftBank’s Opportunity Fund, and KuCoin Ventures.

Source

Leave A Reply

Your email address will not be published.