• bitcoinBitcoin (BTC) $ 97,502.00
  • ethereumEthereum (ETH) $ 3,398.18
  • tetherTether (USDT) $ 0.999740
  • xrpXRP (XRP) $ 2.26
  • bnbBNB (BNB) $ 667.78
  • solanaSolana (SOL) $ 185.92
  • dogecoinDogecoin (DOGE) $ 0.327122
  • usd-coinUSDC (USDC) $ 1.00
  • staked-etherLido Staked Ether (STETH) $ 3,392.21
  • cardanoCardano (ADA) $ 0.921691
  • tronTRON (TRX) $ 0.245726
  • avalanche-2Avalanche (AVAX) $ 38.67
  • chainlinkChainlink (LINK) $ 22.88
  • wrapped-stethWrapped stETH (WSTETH) $ 4,018.74
  • the-open-networkToncoin (TON) $ 5.35
  • suiSui (SUI) $ 4.64
  • shiba-inuShiba Inu (SHIB) $ 0.000022
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 97,056.00
  • stellarStellar (XLM) $ 0.361933
  • polkadotPolkadot (DOT) $ 7.10
  • hyperliquidHyperliquid (HYPE) $ 32.16
  • hedera-hashgraphHedera (HBAR) $ 0.257031
  • wethWETH (WETH) $ 3,398.13
  • bitcoin-cashBitcoin Cash (BCH) $ 453.91
  • leo-tokenLEO Token (LEO) $ 9.28
  • uniswapUniswap (UNI) $ 13.49
  • litecoinLitecoin (LTC) $ 100.91
  • pepePepe (PEPE) $ 0.000018
  • wrapped-eethWrapped eETH (WEETH) $ 3,584.78
  • nearNEAR Protocol (NEAR) $ 5.17
  • bitget-tokenBitget Token (BGB) $ 4.24
  • ethena-usdeEthena USDe (USDE) $ 0.999972
  • aptosAptos (APT) $ 9.92
  • usdsUSDS (USDS) $ 0.999364
  • internet-computerInternet Computer (ICP) $ 10.47
  • aaveAave (AAVE) $ 308.44
  • crypto-com-chainCronos (CRO) $ 0.162504
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.483744
  • mantleMantle (MNT) $ 1.19
  • ethereum-classicEthereum Classic (ETC) $ 26.50
  • vechainVeChain (VET) $ 0.046776
  • render-tokenRender (RENDER) $ 7.31
  • mantra-daoMANTRA (OM) $ 3.80
  • moneroMonero (XMR) $ 193.14
  • whitebitWhiteBIT Coin (WBT) $ 24.43
  • bittensorBittensor (TAO) $ 467.08
  • daiDai (DAI) $ 1.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.30
  • arbitrumArbitrum (ARB) $ 0.765497
  • ethenaEthena (ENA) $ 1.07
  • kaspaKaspa (KAS) $ 0.122706
  • filecoinFilecoin (FIL) $ 5.07
  • fantomFantom (FTM) $ 1.02
  • algorandAlgorand (ALGO) $ 0.338828
  • okbOKB (OKB) $ 45.42
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 2.68
  • cosmosCosmos Hub (ATOM) $ 6.70
  • blockstackStacks (STX) $ 1.72
  • ondo-financeOndo (ONDO) $ 1.73
  • optimismOptimism (OP) $ 1.82
  • bonkBonk (BONK) $ 0.000032
  • immutable-xImmutable (IMX) $ 1.39
  • celestiaCelestia (TIA) $ 5.08
  • movementMovement (MOVE) $ 1.00
  • theta-tokenTheta Network (THETA) $ 2.21
  • injective-protocolInjective (INJ) $ 21.17
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,394.35
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 97,571.00
  • the-graphThe Graph (GRT) $ 0.212387
  • dogwifcoindogwifhat (WIF) $ 2.01
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.029798
  • sei-networkSei (SEI) $ 0.434753
  • worldcoin-wldWorldcoin (WLD) $ 2.25
  • thorchainTHORChain (RUNE) $ 5.15
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,496.32
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999070
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,791.46
  • flokiFLOKI (FLOKI) $ 0.000173
  • jasmycoinJasmyCoin (JASMY) $ 0.034027
  • quant-networkQuant (QNT) $ 112.15
  • gatechain-tokenGate (GT) $ 12.93
  • tokenize-xchangeTokenize Xchange (TKX) $ 20.05
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,576.27
  • lido-daoLido DAO (LDO) $ 1.73
  • galaGALA (GALA) $ 0.036693
  • flare-networksFlare (FLR) $ 0.027690
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 97,705.00
  • makerMaker (MKR) $ 1,651.64
  • beam-2Beam (BEAM) $ 0.027693
  • fasttokenFasttoken (FTN) $ 3.32
  • usual-usdUsual USD (USD0) $ 0.999882
  • the-sandboxThe Sandbox (SAND) $ 0.575503
  • kucoin-sharesKuCoin (KCS) $ 11.29
  • pyth-networkPyth Network (PYTH) $ 0.375681
  • nexoNEXO (NEXO) $ 1.35
  • kaiaKaia (KAIA) $ 0.225023
  • tezosTezos (XTZ) $ 1.29
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 97,336.00
  • based-brettBrett (BRETT) $ 0.130826
  • raydiumRaydium (RAY) $ 4.43
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,493.70
  • eosEOS (EOS) $ 0.820334
  • heliumHelium (HNT) $ 6.93
  • binance-staked-solBinance Staked SOL (BNSOL) $ 189.94
  • ethereum-name-serviceEthereum Name Service (ENS) $ 35.40
  • aerodrome-financeAerodrome Finance (AERO) $ 1.62
  • jupiter-exchange-solanaJupiter (JUP) $ 0.845221
  • xdce-crowd-saleXDC Network (XDC) $ 0.076478
  • flowFlow (FLOW) $ 0.720855
  • starknetStarknet (STRK) $ 0.488048
  • arweaveArweave (AR) $ 16.45
  • bitcoin-svBitcoin SV (BSV) $ 53.78
  • iotaIOTA (IOTA) $ 0.300029
  • aioz-networkAIOZ Network (AIOZ) $ 0.936272
  • dydx-chaindYdX (DYDX) $ 1.48
  • bittorrentBitTorrent (BTT) $ 0.000001
  • msolMarinade Staked SOL (MSOL) $ 231.73
  • curve-dao-tokenCurve DAO (CRV) $ 0.824395
  • coredaoorgCore (CORE) $ 1.10
  • neoNEO (NEO) $ 14.26
  • axie-infinityAxie Infinity (AXS) $ 6.32
  • elrond-erd-2MultiversX (EGLD) $ 34.89
  • matic-networkPolygon (MATIC) $ 0.484090
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 96,598.00
  • decentralandDecentraland (MANA) $ 0.482460
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 96,962.00
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,397.19
  • pendlePendle (PENDLE) $ 5.18
  • apecoinApeCoin (APE) $ 1.17
  • fartcoinFartcoin (FARTCOIN) $ 0.841190
  • zcashZcash (ZEC) $ 52.84
  • eigenlayerEigenlayer (EIGEN) $ 3.85
  • jito-governance-tokenJito (JTO) $ 2.96
  • mog-coinMog Coin (MOG) $ 0.000002
  • akash-networkAkash Network (AKT) $ 3.22
  • chilizChiliz (CHZ) $ 0.086496
  • ai16zai16z (AI16Z) $ 0.707527
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,399.96
  • conflux-tokenConflux (CFX) $ 0.161052
  • wormholeWormhole (W) $ 0.272911
  • usddUSDD (USDD) $ 0.999772
  • spx6900SPX6900 (SPX) $ 0.803233
  • popcatPopcat (POPCAT) $ 0.754660
  • mina-protocolMina Protocol (MINA) $ 0.614888
  • compound-governance-tokenCompound (COMP) $ 82.37
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 198.97
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,398.06
  • roninRonin (RON) $ 1.92
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.41
  • superfarmSuperVerse (SUPER) $ 1.57
  • havvenSynthetix Network (SNX) $ 2.05
  • ecasheCash (XEC) $ 0.000035
  • gnosisGnosis (GNO) $ 266.94
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.006802
  • chiaChia (XCH) $ 21.22
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.327869
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 96,585.00
  • dydxdYdX (ETHDYDX) $ 1.48
  • amp-tokenAmp (AMP) $ 0.007901
  • axelarAxelar (AXL) $ 0.754931
  • notcoinNotcoin (NOT) $ 0.006462
  • zksyncZKsync (ZK) $ 0.178770
  • tether-goldTether Gold (XAUT) $ 2,631.24
  • fraxFrax (FRAX) $ 0.995519
  • peanut-the-squirrelPeanut the Squirrel (PNUT) $ 0.635359
  • layerzeroLayerZero (ZRO) $ 5.68
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,583.69
  • chex-tokenCHEX Token (CHEX) $ 0.624365
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000113
  • reserve-rights-tokenReserve Rights (RSR) $ 0.011319
  • grassGrass (GRASS) $ 2.47
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,675.96
  • baby-doge-coinBaby Doge Coin (BABYDOGE) $ 0.00000000
  • vanaVana (VANA) $ 18.78
  • turboTurbo (TURBO) $ 0.008509
  • safeSafe (SAFE) $ 1.10
  • super-oethSuper OETH (SUPEROETHB) $ 3,397.02
  • usualUsual (USUAL) $ 1.19
  • oasis-networkOasis (ROSE) $ 0.083481
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.006281
  • ordinalsORDI (ORDI) $ 26.55
  • echelon-primeEchelon Prime (PRIME) $ 10.84
  • blurBlur (BLUR) $ 0.264555
  • 1inch1inch (1INCH) $ 0.391138
  • beldexBeldex (BDX) $ 0.078923
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.30
  • susdssUSDS (SUSDS) $ 1.02
  • paypal-usdPayPal USD (PYUSD) $ 0.999883
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 97,405.00
  • pax-goldPAX Gold (PAXG) $ 2,623.84
  • creditcoin-2Creditcoin (CTC) $ 1.26
  • pumpbtcpumpBTC (PUMPBTC) $ 96,936.00
  • apenftAPENFT (NFT) $ 0.00000052
  • livepeerLivepeer (LPT) $ 14.07
  • goatseus-maximusGoatseus Maximus (GOAT) $ 0.510954
  • gigachad-2Gigachad (GIGA) $ 0.052224
  • dexeDeXe (DEXE) $ 8.72
  • arkhamArkham (ARKM) $ 1.50
  • frax-etherFrax Ether (FRXETH) $ 3,342.96
  • true-usdTrueUSD (TUSD) $ 1.00

Lending protocol Sturdy Finance drained of $800,000 in security attack

0 292

Lending protocol Sturdy Finance drained of $800,000 in security attack

Sturdy Finance, a decentralized lending protocol, fell victim to a security attack today, which led to a loss of 442 ether or about $800,000. The unknown attacker took advantage of a reentrancy vulnerability that later facilitated manipulation of a faulty price oracle, thereby enabling them to siphon off funds.

In decentralized finance (DeFi) applications, price oracles are pivotal as they provide real-world price data. However, they also represent a potential target for hackers who can exploit them for security breaches.

The attack on Sturdy Finance was initiated by a reentrancy attack, a method typically used to illicitly withdraw funds from DeFi protocols. This type of attack takes advantage of the ability to call a function repeatedly within a single transaction before the original function call is completed. This, in turn, allows the attacker to withdraw more funds than they would legitimately be entitled to.

After the attacker established the ability to manipulate the function calls, they then proceeded to exploit the price oracle. Sturdy Finance’s price oracle, derived from a separate “read-only” smart contract, was manipulated. This oracle was designed to determine the accurate market value of assets in a liquidity pool managed by Sturdy’s team on the Balancer decentralized exchange, thus facilitating the trading of staked ether (stETH). However, the exploitation of the oracle enabled the attacker to drain funds from Sturdy.

BlockSec, a security firm, stated, «The root cause is due to the typical Balancer’s read-only reentrancy, while the price of B-stETH-STABLE was manipulated.»

Sturdy pauses markets

Sturdy Finance reacted to the attack by suspending all of its markets to prevent further potential losses, assuring its users that no other funds were in danger as a result of the breach.

“All markets have been paused; no additional funds are at risk, and no user actions are required at this time,” said the team. “We will be sharing more information as soon as we have it.”
After the attack, on-chain data shows that the attacker used the Tornado Cash mixer to obscure the activity.

In 2022, Sturdy Finance raised $3 million in a series of rounds to construct an interest-free borrowing and lending platform. The funding was lead by Pantera and also saw participation from Y Combinator, SoftBank’s Opportunity Fund, and KuCoin Ventures.

Source

Leave A Reply

Your email address will not be published.