How This Ethereum Lending Platform Was Attacked And Made A Deal With The Hacker

BitcoinistОпубліковано о 2022-06-28Востаннє оновлено о 2022-06-28

Анотація

Ethereum lending platform XCarnival confirmed a bad actor stole $3.8 million or 3,087 ETH. According to a report from on-chain...

Ethereum lending platform XCarnival confirmed a bad actor stole $3.8 million or 3,087 ETH. According to a report from on-chain security firm Peck Shield, a hacker exploited a vulnerability on the protocol’s smart contract by borrowing ETH and creating “multiple pledge orders to pledge BAYC (Bored Ape Yacht Club NFTs) many times”.
XCarnival operates as a non-fungible token (NFT) lending pool. The platform enables NFT holders to deposit their assets in exchange for liquidity. This process involves three smart contracts: an NFT manager, a P2Controller to manage lending restrictions, and fund storage, as stated by another security firm Go+ Security.
The hacker bought item 5110 from the popular Bored Ape Yacht Club NFT collection on OpenSea. Later, he deposited this asset on XCarnival and conducted an attack to “use the same NFT for borrowing”.
In other words, the attacker was able to pledge the NFT, borrowed ETH, and then remove the NFT without paying back the loan. The bad actor completed this process several times until the pool was drained.
Go+ Security explained that the hacker created a Master smart contract and several “slaves” smart contracts to conduct the attack:
Then Slave 5338 withdrew the NFT and sent it back to Master, who then repeated this process with other Slaves. In this way they created many orderIDs, which can later be used as lending credentials. But bugged xNFT contract didn’t revoke the credential after withdrawing.
XCarnival’s operated with a vulnerability on its smart contracts, mentioned above, which enable the attack if the user stays within a certain. Go+ Security added on the attack and the smart contract vulnerability: “Collateral is still valid after withdrawing. This is a very simple & naive bug in contract implementation.”
In light of the successful attack, the Ethereum-based NFT lending protocol decided to offer the hacker a deal.
Ethereum Platform Makes Deals With Its Attacker
According to its official Twitter account, the XCarnival offered the hacker a 1,500 ETH or $1.8 million bounty. Half the stolen funds. The attacker only needed to return the other half and they got to keep the money and suffer no legal consequences.
The team behind the platform confirmed that the hacker agreed to the terms. Half the stolen funds were returned to the pool. The Ethereum lending platform claims “security agencies have tentatively determined the hacker’s geographic location”.
This statement seems to hint at possible legal consequences for the attacker, but the team behind this project is yet to provide more information.

This is not the first time a hacker agrees to return a portion or the full amount of the stolen funds. Some hackers attack decentralized finance (DeFi) platforms and often held the money hostage until they receive payment for what they considered to be a “service”. Other projects are less lucky and pay the ultimate price.
At the time of writing, Ethereum (ETH) trades at $1,180 with a 3% loss in the last 24 hours.

Ethereum ETH ETHUSD

ETH moving sideways on the 4-hour chart. Source: ETHUSD Tradingview

Пов'язані матеріали

Microsoft Announces Commercial-Grade Quantum Computer to be Completed in Three Years: Will the Boots Land?

Microsoft announces plans to build a commercially viable quantum computer by 2029, a significant acceleration from the previous industry consensus of a decade. The breakthrough is fueled by their new Majorana 2 quantum chip, which boasts a record-breaking average qubit lifetime of 20 seconds—a 1,000-fold reliability improvement over its predecessor. This leap was achieved by leveraging topological qubits, a theoretically more stable technology using Majorana zero modes, and switching the core superconducting material from aluminum to lead. Crucially, Microsoft's "Discovery" agentic AI platform accelerated the R&D process. AI agents autonomously analyzed vast experimental data, optimized manufacturing parameters (like the lead alloy composition), and solved issues like "ghost noise," dramatically speeding up experimentation. While the 20-second coherence time is a landmark, challenges remain: scaling from 12 qubits to the millions needed for practical applications, managing compilation costs, and verifying quantum results. Skeptics call for peer-reviewed data, and questions persist about whether even 20 seconds is sufficient for complex algorithms like breaking RSA encryption. The race is on with other approaches (superconducting, trapped ions), but Microsoft's confidence in its topological roadmap signals a potential shortcut to a scalable quantum future.

marsbit16 хв тому

Microsoft Announces Commercial-Grade Quantum Computer to be Completed in Three Years: Will the Boots Land?

marsbit16 хв тому

Is There Really a "World Cup Curse" in the Market?

Is there really a "World Cup Curse" affecting markets? Historical data shows global equity markets often underperform during the tournament. The S&P 500 has averaged negative returns of -1.5% to -2.11% across 19 World Cups since 1950, with declines in 58% of events. China's Shanghai Composite fell in 71% of tournaments since 1994. Studies confirm reduced trading activity during matches, with volumes dropping significantly, especially when a home nation plays. A team's loss can also lead to negative sentiment and selling pressure in its domestic market the next day. However, the "curse" may be partly attributed to seasonal weakness. Many tournaments are held in June-July, a historically weaker period for stocks ("Sell in May and go away"). The 2022 Qatar World Cup, held in November-December, saw a smaller drop in trading volume compared to summer events, suggesting timing plays a role. The cryptocurrency market's performance during World Cups has been mixed and largely driven by its own major catalysts (e.g., Mt. Gox hack, FTX collapse, halving cycles) rather than the tournament. Investment opportunities have shifted over time. Traditional beneficiaries like TV manufacturers have seen fading returns as streaming platforms become the core viewing channel. Classic consumer plays like beer and sportswear face challenges from changing consumption trends. Newer digital assets, like fractionalized collectible player cards on blockchain, have seen explosive growth. While gambling is a traditional sector, prediction markets are emerging. In conclusion, while a statistical correlation exists, the World Cup's direct impact on markets is likely limited and intertwined with seasonal patterns. With lower liquidity during the event, the simplest strategy for many might be to step back from trading and enjoy the games.

marsbit23 хв тому

Is There Really a "World Cup Curse" in the Market?

marsbit23 хв тому

Why 'AI Service Subscription' Is Destined to Die Out?

"Why 'AI Service Subscription Models' Are Doomed to Disappear" The article argues that the flat-rate subscription model for AI services is fundamentally unsustainable. It points to recent industry shifts, such as Anthropic limiting access to its flagship Claude Fable 5 model for subscribers after just 14 days, and GitHub and OpenAI moving towards credit-based or usage-based billing. The core problem is that subscription models rely on a capped human consumption limit—like watching videos or listening to music—which keeps costs predictable. However, the rise of autonomous AI agents shatters this premise. Agents can consume 5 to 30 times more computing resources (tokens) than a human chatting, and they operate continuously without user presence. This removes the natural usage cap, making fixed-price plans financially unviable as heavy users incur massive costs. Attempts to patch the model with higher tiers or usage caps have failed, often leading to "adverse selection" where only the heaviest users subscribe. The industry's solution is to hollow out subscriptions, replacing "unlimited" access with prepaid credits charged per token, akin to a utility meter. While chat-based subscriptions may linger, the real value and revenue are shifting to pay-as-you-go models. The current period represents a final, heavily subsidized phase for users. The conclusion is that the soul of subscription—a fixed price for worry-free use—is dying, soon to be replaced by pure usage-based pricing where everyone pays for their own "electricity meter."

marsbit23 хв тому

Why 'AI Service Subscription' Is Destined to Die Out?

marsbit23 хв тому

Торгівля

Спот
Ф'ючерси
活动图片