[ad_1]
Blockchain startup MonoX Finance said on Wednesday that a hacker stole $ 31 million by exploiting a bug in the software the service uses to write smart contracts.
The company uses a decentralized financial protocol known as MonoX which allows users to trade digital currency tokens without some of the demands of traditional exchanges. “Project owners can list their tokens without the burden of capital requirements and focus on using the funds for project construction instead of providing cash,” MonoX company representatives wrote in November. “It works by bundling the deposited tokens into a virtual pair with vCASH, to provide a unique token pool design. “
An accounting error embedded in the company’s software allowed an attacker to inflate the price of the MONO token, then use it to cash out all other deposited tokens, MonoX Finance revealed in an article. The transport amounted to $ 31 million in tokens on the Ethereum or Polygon blockchains, both of which are supported by the MonoX protocol.
Specifically, the hack used the same token as tokenIn and tokenOut, which are methods of exchanging the value of one token for another. MonoX updates the prices after each swap by calculating new prices for both tokens. When the exchange is complete, the price of tokenIn, i.e. the token sent by the user, decreases and the price of tokenOut, or the token received by the user, increases.
By using the same token for tokenIn and tokenOut, the hacker significantly inflated the price of the MONO token because the tokenOut update overwrote the tokenIn price update. The hacker then exchanged the token for $ 31 million in tokens on the Ethereum and Polygon blockchains.
There is no practical reason to exchange a token for the same token, and therefore the software that performs the transactions should never have allowed such transactions. Alas, it did, although MonoX received three security audits this year.
The pitfalls of smart contracts
“These types of attacks are common in smart contracts because many developers did not take responsibility for setting the security properties of their code,” said Dan Guido, an expert in securing smart contracts like the one hacked here. . “They’ve had audits, but if the audits only show that an intelligent person has looked at the code for a period of time, then the results have limited value. Smart contracts need verifiable proof that they are doing what you intend to do and only what you intend to do. This means defined safety properties and the techniques used to evaluate them.
The CEO of security consultancy Trail of Bits, Guido continued:
Most software requires vulnerability mitigation. We proactively search for vulnerabilities, recognize that they may not be secure when in use, and build systems to detect when they are exploited. Smart contracts require the elimination of vulnerability. Software verification techniques are widely used to provide provable assurances that contracts are working as intended. Most security issues in smart contracts arise when developers take the first approach to security instead of the second. There are many large, complex, and very valuable smart contracts and protocols that have avoided mishaps, alongside the many that were instantly leveraged upon launch.
Blockchain researcher Igor Igamberdiev took to Twitter to break down the makeup of the drained tokens. The tokens included $ 18.2 million from wrapped Ethereum, 10.5 million MATIC tokens and $ 2 million from WBTC. The transport also included smaller amounts of tokens for Wrapped Bitcoin, Chainlink, Unit Protocol, Aavegotchi, and Immutable X.
Only the latest DeFi hack
MonoX isn’t the only decentralized financial protocol to fall victim to a multi-million dollar hack. In October, Indexed Finance said it lost around $ 16 million in a hack that exploited the way it rebalances index pools. Earlier this month, blockchain analytics firm Elliptic said so-called DeFi protocols lost $ 12 billion due to theft and fraud. Losses in the first 10 months or so of this year hit $ 10.5 billion, up from $ 1.5 billion in 2020.
“The relative immaturity of the underlying technology has allowed hackers to steal user funds, while deep pools of liquidity have allowed criminals to launder the proceeds of crime such as ransomware and fraud,” said the Elliptic report. “This is part of a larger trend towards the exploitation of decentralized technologies for illicit purposes, which Elliptic calls DeCrime.”
|
Sources 2/ https://www.wired.com/story/hackers-drain-31-million-from-crypto-service/ The mention sources can contact us to remove/changing this article |
[ad_2]