• About Us
  • Privacy Policy
  • Contact Us
Subscribe
BitcoinCryptos - News About Bitcoin & Cryptos
  • Home
  • Bitcoin
  • Ethereum
  • Dogecoin
  • Litecoin
  • Cryptocurrency
  • Blockchain
  • Regulation
  • Market
  • Prices
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Dogecoin
  • Litecoin
  • Cryptocurrency
  • Blockchain
  • Regulation
  • Market
  • Prices
No Result
View All Result
BitcoinCryptos
No Result
View All Result
Home Ethereum

How This Ethereum Platform Was Attacked And Made A Deal With The Hacker

June 27, 2022
in Ethereum
0
Hackers Steal $80 Million From DeFi Platforms Fei Protocol And Rari Capital
Share on FacebookShare on Twitter


Ethereum lending platform XCarnival confirmed a bad actor stole $3.8 million or 3,087 ETH. According to a report from on-chain security firm Peck Shield, a hacker exploited a vulnerability on the protocol’s smart contract by borrowing ETH and creating “multiple pledge orders to pledge BAYC (Bored Ape Yacht Club NFTs) many times”.

Related Reading | Morgan Creek Said To Be In Bid To Secure $250-M To Counter FTX BlockFi Bailout

XCarnival operates as a non-fungible token (NFT) lending pool. The platform enables NFT holders to deposit their assets in exchange for liquidity. This process involves three smart contracts: an NFT manager, a P2Controller to manage lending restrictions, and fund storage, as stated by another security firm Go+ Security.

The hacker bought item 5110 from the popular Bored Ape Yacht Club NFT collection on OpenSea. Later, he deposited this asset on XCarnival and conducted an attack to “use the same NFT for borrowing”.

In other words, the attacker was able to pledge the NFT, borrowed ETH, and then remove the NFT without paying back the loan. The bad actor completed this process several times until the pool was drained.

Go+ Security explained that the hacker created a Master smart contract and several “slaves” smart contracts to conduct the attack:

Then Slave 5338 withdrew the NFT and sent it back to Master, who then repeated this process with other Slaves. In this way they created many orderIDs, which can later be used as lending credentials. But bugged xNFT contract didn’t revoke the credential after withdrawing.

XCarnival’s operated with a vulnerability on its smart contracts, mentioned above, which enable the attack if the user stays within a certain. Go+ Security added on the attack and the smart contract vulnerability: “Collateral is still valid after withdrawing. This is a very simple & naive bug in contract implementation.”

In light of the successful attack, the Ethereum-based NFT lending protocol decided to offer the hacker a deal.

Ethereum Platform Makes Deals With Its Attacker

According to its official Twitter account, the XCarnival offered the hacker a 1,500 ETH or $1.8 million bounty. Half the stolen funds. The attacker only needed to return the other half and they got to keep the money and suffer no legal consequences.

The team behind the platform confirmed that the hacker agreed to the terms. Half the stolen funds were returned to the pool. The Ethereum lending platform claims “security agencies have tentatively determined the hacker’s geographic location”.

This statement seems to hint at possible legal consequences for the attacker, but the team behind this project is yet to provide more information.

7/8 Funds returnedhttps://t.co/oRwSsGgT6U pic.twitter.com/YgXZ9DTj03

— Tal Be’ery (@TalBeerySec) June 27, 2022

This is not the first time a hacker agrees to return a portion or the full amount of the stolen funds. Some hackers attack decentralized finance (DeFi) platforms and often held the money hostage until they receive payment for what they considered to be a “service”. Other projects are less lucky and pay the ultimate price.

Related Reading | Harmony Dangles $1M Reward For Return Of $100M Stolen Funds – Is It Enough?

At the time of writing, Ethereum (ETH) trades at $1,180 with a 3% loss in the last 24 hours.

Ethereum ETH ETHUSD
ETH moving sideways on the 4-hour chart. Source: ETHUSD Tradingview





Source link

Related articles

Ethereum’s MVRV Indicator Flips Into Bullish Territory – Is A Rally On The Horizon?

Ethereum’s MVRV Indicator Flips Into Bullish Territory – Is A Rally On The Horizon?

May 19, 2025
Ethereum’s Price Explodes 97%, Hits $2,743 – Here’s The Next Target

Ethereum’s Price Explodes 97%, Hits $2,743 – Here’s The Next Target

May 18, 2025
Tags: AttackedDealEthereumHackerPlatform
Share76Tweet47

Related Posts

Ethereum’s MVRV Indicator Flips Into Bullish Territory – Is A Rally On The Horizon?

Ethereum’s MVRV Indicator Flips Into Bullish Territory – Is A Rally On The Horizon?

May 19, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ethereum’s brief upswing on Sunday was met...

Ethereum’s Price Explodes 97%, Hits $2,743 – Here’s The Next Target

Ethereum’s Price Explodes 97%, Hits $2,743 – Here’s The Next Target

May 18, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Since April 7, ETH has staged an...

Ethereum Playing Catch-Up? Bloomberg Examines ETH’s Struggles In New Report

Ethereum Looks Primed To Outperform Bitcoin In Coming Months — Altseason Incoming?

May 18, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The price of Ethereum (ETH) continued to...

Ethereum Accumulation Accelerates – Smart Money Snaps Up 450K ETH

Ethereum Accumulation Accelerates – Smart Money Snaps Up 450K ETH

May 17, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ethereum is now at a pivotal moment...

Binance’s Ethereum Reserves Drop By Nearly 300,000 ETH In A Month – Is A Massive Rally Coming?

Binance’s Ethereum Reserves Drop By Nearly 300,000 ETH In A Month – Is A Massive Rally Coming?

May 16, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Although Ethereum (ETH) is still trading nearly...

Load More

Leave a Reply

Your email address will not be published. Required fields are marked *

NYC Mayor Eric Adams launches crypto advisory council

NYC Mayor Eric Adams launches crypto advisory council

May 21, 2025
0

New York City Mayor Eric Adams says he will create a digital advisory council to attract jobs and investment to...

Attendees At First New York City Crypto Summit Implore Mayor Adams To End The BitLicense

Attendees At First New York City Crypto Summit Implore Mayor Adams To End The BitLicense

May 21, 2025
0

Today, New York City hosted its first ever Crypto Summit. The event took place at Gracie Mansion, the mayor’s residence,...

Strive targets 75,000 Bitcoin from Mt. Gox claims to build Bitcoin treasury

Strive targets 75,000 Bitcoin from Mt. Gox claims to build Bitcoin treasury

May 21, 2025
0

Vivek Ramaswamy’s Strive is looking to build its Bitcoin holdings by purchasing distressed Bitcoin claims at a discount, starting with...

Tribalism Is Not The Core Problem

Tribalism Is Not The Core Problem

May 21, 2025
0

The United States government stands mere months, if not weeks, from the passing of stablecoin legislation that will set the...

Coinbase CEO’s journey from no ‘political causes’ to hiring DOGE staff

Coinbase CEO’s journey from no ‘political causes’ to hiring DOGE staff

May 21, 2025
0

Five years ago, Brian Armstrong wanted employees of his cryptocurrency exchange to refrain from expressing political views at work. Now,...

We have all the news related to the crypto market and we make sure to bring and publish all the updates as fast as we can.

Categories

  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Litecoin
  • Market
  • Regulation

Archives

  • 2025
  • 2024
  • 2023
  • 2022
  • 2021

Newsletter

    • About Us
    • Privacy Policy
    • Contact Us

    © 2021 bitcoincryptos.com

    Please enter CoinGecko Free Api Key to get this plugin works.
    No Result
    View All Result
    • Home
    • Bitcoin
    • Ethereum
    • Dogecoin
    • Litecoin
    • Cryptocurrency
    • Blockchain
    • Regulation
    • Market
    • Prices

    © 2018 JNews by Jegtheme.