• Advertise
  • Submit a Press Release
NewsBTC
Bitcoin & cryptocurrency news
Crypto.com Logo
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Cardano
    • Dogecoin
    • Ripple
    • DeFi
    • NFT
    • Sponsored
    • Press Releases
  • Analysis
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Cardano (ADA)
    • Chainlink (LINK)
    • Litecoin (LTC)
    • Tezos (XTZ)
    • Zcash (ZEC)
    • EOS
    • YearnFinance (YFI)
  • Trading Course
  • Directory
    • Crypto Businesses
    • Bitcoin Brokers
    • Casinos
    • Sportsbooks
  • Events
  • Play GamesTry
  • Play Casino GamesTry
No Result
View All Result
Breaking News: Dogecoin (DOGE) Soars 8%, But An Uptick In This Metric Suggests A Pullback
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Cardano
    • Dogecoin
    • Ripple
    • DeFi
    • NFT
    • Sponsored
    • Press Releases
  • Analysis
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Cardano (ADA)
    • Chainlink (LINK)
    • Litecoin (LTC)
    • Tezos (XTZ)
    • Zcash (ZEC)
    • EOS
    • YearnFinance (YFI)
  • Trading Course
  • Directory
    • Crypto Businesses
    • Bitcoin Brokers
    • Casinos
    • Sportsbooks
  • Events
  • Play GamesTry
  • Play Casino GamesTry
No Result
View All Result
NewsBTC
No Result
View All Result
Breaking News: Dogecoin (DOGE) Soars 8%, But An Uptick In This Metric Suggests A Pullback
Ethereum ETH ETHUSD

How Hackers Looted 2600 ETH In Rari Capital Cross-Chain Exploit

Reynaldo Marquez by Reynaldo Marquez
2 years ago
in Ethereum
Reading Time: 3 mins read
Advertisement

Ethereum (ETH) based yield aggregator Rari Capital was attacked this weekend by a group of bad actors. As a result, 2,600 in this cryptocurrency were stolen from the Rari Capital Ethereum Pool, as a post-mortem report released by core contributors confirmed.

The attack took place at around 1:48 PM UTC, May 8th, with a series of transactions that lasted for almost an hour. Rari Capital’s product deposits ETH into Alpha Homoras’ ibETH interest-bearing token as part of their strategy.

The protocol’s pool contract operates with the ibETH.totalETH()/ibETH.totalSupply(), used to calculate the exchange rate for the ibETH/ETH pair. A separate report from Alpha Finance Labs claims that this operation can “lead to incorrect assumption”. Rari Capital report stated the following:

Get 30 FREE SPINS at Punt Casino - NO DEPOSIT REQUIRED! Start Playing Now.
No Deposit 40 FREE SPINS at Wild.io on SIGN UP. Wheel of fortune, daily bonuses, 10 BTC in prizes monthly! Start Playing Now!

According to Alpha Finance, `ibETH.totalETH()` is manipulatable inside the `ibETH.work` function, and a user of `ibETH.work` can call any contract it wants to inside `ibETH.work`, including the Rari Capital Ethereum Pool deposit and withdrawal functions.

On Ethereum, the attack began when the bad actors took a flash loan from protocol dYdX for around 59,000 in this cryptocurrency. The funds were into Rari’s Ethereum based pool with the correct conversion rate for the aforementioned trading pair.

Then, the attackers used the function “work” which enabled them to trigger their offensive by encoding an “evil” fToken contract. This allowed the hackers to artificially inflate their ibETH/ETH rate.

At 2:29 PM +UTC, the possible root of the exploits was discovered. At 2:34 PM +UTC, actions on Alpha Homora were paused. The losses represented around 60% of all users fund in this Ethereum-based Pool. However, only Rari’s funds were lost, as Alpha Finance’s report claims. Rari Capital said:

BitStarz Player Lands $2,459,124 Record Win! Could you be next big winner?

At the end of `ibETH.work`, the value of `ibETH.totalETH()` returns to its true value, leading the Rari Capital Ethereum Pool’s balances to values lower than they were before the attack as a result of the attacker withdrawing more than they deposited while their balance was artificially inflated.

ETH Funds Stolen From Binance Smart Chain

Researcher Igor Igamberdiev revealed that the exploit was far more complex than usual. According to a separate report made by Igamberdiev, the attack on Rari Capital is the first cross-chain exploit in the crypto space.

The researcher believes that the hackers first took funds from a Binance Smart Chain yield aggregator called Value DeFi. This protocol suffers multiple attacks on its products, VSafe and VSwap, and the bad actors looted 5,346 BNB which immediately were converted into 1,000 ETH.

Ethereum ETH ETHUSD
Source: Igor Igamberdiev

On Binance Smart Chain, the hackers also created a fake token which was pool into exchange PancakeSwap. This allowed them to interact with protocol Alpaca Finance. Igamberdiev stated:

Interact with Alpaca Finance, where when calling approve() for a fake token, a payload is called, which allows an attacker to use VSafe through Codex farm to get vSafeWBNB. Convert vSafeWBNB to WBNB. All WBNB transferred to Ethereum through Anyswap.

To fight these types of attacks in the future, Rari Capital took additional security steps, such as place their protocol integration under review, check all invariants for potential malfunctions, and others. However, Igamberdiev concluded the following:

The interoperability between DeFi protocols is becoming more complex, which opens up new vectors of attacks. This attack was similar in difficulty to the Pickle Evil Jar and will become even more frequent in the future.

Ethereum trades at $3,918 with a 2.1% profit in the daily chart and a 31.9% profit in the weekly chart.

Ethereum ETH ETHUSD
ETH with bullish momentum in the daily chart. Source: ETHUSD Tradingview
Tags: Binance Smart ChainETHethereumethusd
Tweet123Share196ShareSend
Win up to $1,000,000 in One Spin at CryptoSlots
Reynaldo Marquez

Reynaldo Marquez

Related Posts

ethereum

Ethereum Hovers Above $1,600, What’s The Next Move?

2 days ago
Grayscale Bitcoin Trust

Here’s What Might Have Triggered Ethereum’s Decline Below $1,600

3 days ago
Number Of New Ethereum Validators Remains Flat Ahead Of Shanghai Upgrade

Number Of New Ethereum Validators Remains Flat Ahead Of Shanghai Upgrade

3 days ago
Ethereum Smart Contracts

Number of New Ethereum Smart Contracts Falls 60% in 2023

3 days ago
Ethereum

Ethereum Closes Near Its Next Profit Take Region As Bullish Momentum Continues

4 days ago
Vitalik Buterin Blockchain Ethereum Privacy

Vitalik Buterin Proposes A Privacy Fix for Ethereum

4 days ago

Premium Partners

Top Casinos

BitStarz

BitStarz

Review · Visit
Punt Casino

Punt Casino

Review · Visit
Trust Dice

Trust Dice

Review · Visit
Metaspins

Metaspins

Review · Visit
Coinplay

Coinplay

Review · Visit
CryptoSlots

CryptoSlots

Review · Visit
mBit

mBit

Review · Visit
Vave

Vave

Review · Visit

Sportsbooks

1xBit

1xBit

Review · Visit
Coinplay

Coinplay

Review · Visit

The Meta Masters Guild Presale Generates $1.5 Million So Far With Price Hike of 23% in Next 48 Hours.

January 27, 2023

Top Experts Compare Treshold (T), BNB (BNB), and Snowfall Protocol (SNW) and Decide Which Is The Best – Find Out More!

January 27, 2023

PancakeSwap To Do a V3 Upgrade In 2023 According to Roadmap Update, Kava Gets Coinbase Listing, Snowfall Protocol Releases the Long-Awaited Snowfall DEX And Promises Another Huge Announcement A Week Before Launch— Is Snowfall Wallet Coming Early Too?

January 27, 2023

Litecoin (LTC) and Polygon (MATIC) Have Been Renowned IN The Past But It’s Time For A New Crypto Project To Take The Top Ranks: Snowfall Protocol (SNW)

January 27, 2023

Binance Coin (BNB) And Orbeon Protocol (ORBN) Speculated To Make Huge Gains In 2023

January 27, 2023

About Us

NewsBTC is a cryptocurrency news service that covers bitcoin news today, technical analysis & forecasts for bitcoin price and other altcoins. Here at NewsBTC, we are dedicated to enlightening everyone about bitcoin and other cryptocurrencies.

We cover BTC news related to bitcoin exchanges, bitcoin mining and price forecasts for various cryptocurrencies.

Links

Crypto Prices from Nomics

Cryptocurrency news

  • Bitcoin
  • Ethereum
  • Ripple
  • Chainlink
  • Cardano
  • EOS
  • Tezos

Technical Analysis

  • Bitcoin (BTC)
  • Ethereum (ETH)
  • Ripple (XRP)
  • Chainlink (LINK)
  • Cardano (ADA)
  • Tezos (XTZ)

Company

  • Advertising
  • Comments Policy
  • Privacy Center
  • Sitemap
  • About Us
  • Contact

© 2022 NewsBTC. All Rights Reserved.

  • Home
  • News
    • Bitcoin
    • Ethereum
    • Cardano
    • Dogecoin
    • Ripple
    • DeFi
    • NFT
    • Sponsored
    • Press Releases
  • Analysis
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Cardano (ADA)
    • Chainlink (LINK)
    • Litecoin (LTC)
    • Tezos (XTZ)
    • Zcash (ZEC)
    • EOS
    • YearnFinance (YFI)
  • Trading Course
  • Directory
    • Crypto Businesses
    • Bitcoin Brokers
    • Casinos
    • Sportsbooks
  • Events
  • Play Games
  • Play Casino Games

© 2022 NewsBTC. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy.