PeckShield Exposes UwU Lend Hack Was The Manipulation of The Price Oracle!
coincu.com 53 m
Key Points:
- UwU Lend hack stemmed from manipulated assets in its price oracle, compromising platform integrity.
- Five assets, including FRAXUSDe and USDecrvUSD, were tampered with during the attack.
- UwU Lend is swiftly investigating and enhancing security measures to prevent future breaches.
UwU Lend hack was possible due to a root problem in its price oracle. This hack tainted the platform and related specifically to the manipulation of particular assets that were used to set pricing of sUSDe.
UwU Lend uses a system of price oracles that work through the mediation of sUSDe assets’ worth, calculated using the median prices collected from different sources. It appears that five of these sources were tampered with in the hacker attack.
Today’s @UwU_Lend hack leads to $19.4m loss.
The root cause is a price oracle issue. In particular, the sUSDe asset is priced as median from multiple sources. Five of them, i.e., FRAXUSDe, USDeUSDC, USDeDAI, USDecrvUSD, and GHOUSDe, were manipulated during the hack.
The stolen… https://t.co/4ec92zxoql pic.twitter.com/xuGGegfDpV
— PeckShield Inc. (@peckshield) June 10, 2024
In this particular case, there were five assets whose prices were tampered with: FRAXUSDe, USDeUSDC, USDeDAI, USDecrvUSD, and GHOUSDe. These are key assets in the determination of various pricing structures in the UwU Lend ecosystem. The attackers were able to manipulate the data reflecting prices for these assets and exploit the vulnerability of the ecosystem to execute malevolent attacks.
Readmore: UwU Lend Exploit Causes Platform Loss of Nearly $20 Million
Price Oracle Manipulation Exposed in UwU Lend Hack
The manipulation of those key assets derived out of the platform operation of UwU Lend hack, because from there, they manipulated the key price data and opened a Pandora’s box on the likelihood of attacks on DeFi systems. It situated ugly concerns on the credibility and integrity of price oracles in these systems.
UwU Lend hack took prompt steps to address the issue and reduce the potential risks facing its users. The platform is in close collaboration with security agencies and authorities concerned to carry out a follow-up investigation into the matter and ensure that measures are taken to curb such occurrences in the future.
Although this obviously did not restore confidence in UwU Lend and perhaps in DeFi at large, it also was, at the same time, a powerful reminder about the risks and difficulties related to decentralized finance. As the industry grows, this represents the necessity to ensure that platforms continue to be secure and transparent enough to guarantee user funds’ safety as well as the ecosystem’s integrity.
DISCLAIMER: The information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.
Source