[ad_1]
??
Key Findings: Over $ 600 million in cryptocurrency stolen in platform attacks in the first three weeks of December by BadgerDAO, BitMart, AscendEX, Vulcan Forged, and Grim Finance. Cross-chain trading and Tornado Cash dominated the attacking chain moves. crypto platforms at the end of 2021 due to phishing exploits and contracts.
??
The decentralized financing (DeFi) platform Grim Finance announced on the evening of December 18, 2021 that it had suffered a hack resulting in losses of more than $ 30 million. This is the third hack last week and the fifth for the month of December, bringing the total losses to more than $ 600 million.
??
Grim Finance’s official announcement (Source: Twitter)
Grim Finance’s analysis identified that the platform compromise was performed by an advanced attacker.
“The attacker attacked using the function titled beforeDeposit () of our vault policy by entering into a malicious token contract. The attacker creates a malicious token contract that executed five reentrancy loops from safeTransferFrom (), where within 5 rentrances, the _pool value is set to the current balance (). On the last safeTransferFrom (), the rentrancy loop is broken, and some wishes may be transferred to the policy, which will increase the _amount to put the safe in a state where actions can be created. At the settlement of the 5 rents, each loop will see that the _amount is not 0, and will hit the corresponding shares, hit the same share count 5x (the number of rent loops).
About an hour before the malicious token contract was created, the attacker funded Ethereum (ETH) and Binance Smart Chain (BSC) wallets from Tornado Cash. The attacker bridged Grim Finance’s stolen crypto from the Fantom mainnet to the ETH mainnet for USDC and DAI.
??
Cross-chain analysis within TRM’s Forensics platform (Source: TRM)
In addition to the incoming stolen funds transferred from the Fantom mainnet, an unknown individual sent a message to the attacker through BSC to alert that the wallets associated with the attacker were blacklisted.
??
A message sent to the attacker integrated into a BSC transaction (Source: FTMScan)
In what may be a first, the same unknown individual created a token on BSC called “BECAREFUL YOU WAS BLACKLISTED”. The attacker currently holds the “BECAFEUL YOU WAS BLACKLISTED” token.
TRM will continue to monitor the flow of attackers on the chain and update our systems so that TRM partners are automatically alerted to any exposure.
TRM Labs is the only tool with cross-chain analyzes, which allows investigators to view cross-chain trade and multiple flows in a single graph. Investigators can move seamlessly through blockchains to track fund flows, visualize multi-layered relationships and dramatically reduce investigation time with our proprietary automated tracing technology. For more information or to report leads, contact us at [email protected]. Subscribe to our weekly reviews here.
|
Sources 2/ https://www.trmlabs.com/post/grim-finance-hacked-600-million-in-crypto-stolen-in-december The mention sources can contact us to remove/changing this article |
[ad_2]