How This Ethereum Lending Platform Was Attacked And Made A Deal With The Hacker

Bitcoinist发布于2022-06-28更新于2022-06-28

文章摘要

Ethereum lending platform XCarnival confirmed a bad actor stole $3.8 million or 3,087 ETH. According to a report from on-chain...

Ethereum lending platform XCarnival confirmed a bad actor stole $3.8 million or 3,087 ETH. According to a report from on-chain security firm Peck Shield, a hacker exploited a vulnerability on the protocol’s smart contract by borrowing ETH and creating “multiple pledge orders to pledge BAYC (Bored Ape Yacht Club NFTs) many times”.
XCarnival operates as a non-fungible token (NFT) lending pool. The platform enables NFT holders to deposit their assets in exchange for liquidity. This process involves three smart contracts: an NFT manager, a P2Controller to manage lending restrictions, and fund storage, as stated by another security firm Go+ Security.
The hacker bought item 5110 from the popular Bored Ape Yacht Club NFT collection on OpenSea. Later, he deposited this asset on XCarnival and conducted an attack to “use the same NFT for borrowing”.
In other words, the attacker was able to pledge the NFT, borrowed ETH, and then remove the NFT without paying back the loan. The bad actor completed this process several times until the pool was drained.
Go+ Security explained that the hacker created a Master smart contract and several “slaves” smart contracts to conduct the attack:
Then Slave 5338 withdrew the NFT and sent it back to Master, who then repeated this process with other Slaves. In this way they created many orderIDs, which can later be used as lending credentials. But bugged xNFT contract didn’t revoke the credential after withdrawing.
XCarnival’s operated with a vulnerability on its smart contracts, mentioned above, which enable the attack if the user stays within a certain. Go+ Security added on the attack and the smart contract vulnerability: “Collateral is still valid after withdrawing. This is a very simple & naive bug in contract implementation.”
In light of the successful attack, the Ethereum-based NFT lending protocol decided to offer the hacker a deal.
Ethereum Platform Makes Deals With Its Attacker
According to its official Twitter account, the XCarnival offered the hacker a 1,500 ETH or $1.8 million bounty. Half the stolen funds. The attacker only needed to return the other half and they got to keep the money and suffer no legal consequences.
The team behind the platform confirmed that the hacker agreed to the terms. Half the stolen funds were returned to the pool. The Ethereum lending platform claims “security agencies have tentatively determined the hacker’s geographic location”.
This statement seems to hint at possible legal consequences for the attacker, but the team behind this project is yet to provide more information.

This is not the first time a hacker agrees to return a portion or the full amount of the stolen funds. Some hackers attack decentralized finance (DeFi) platforms and often held the money hostage until they receive payment for what they considered to be a “service”. Other projects are less lucky and pay the ultimate price.
At the time of writing, Ethereum (ETH) trades at $1,180 with a 3% loss in the last 24 hours.

Ethereum ETH ETHUSD

ETH moving sideways on the 4-hour chart. Source: ETHUSD Tradingview

你可能也喜欢

为什么「AI服务订阅制」,注定会走向消亡?

Anthropic发布最强公开模型Claude Fable 5,但宣布14天后将其从所有订阅计划中移除,转为按用量积分付费。这并非孤立事件,过去八周内,OpenAI、GitHub和Anthropic自身都采取了类似行动,将高级功能或agent用法从固定订阅中剥离,转向按实际使用量(token)计费。 其根本原因在于,传统订阅制依赖一个前提:用户的消费存在生理或时间上的自然上限。然而,AI Agent的出现彻底打破了这一限制。Agent能自主执行复杂任务,消耗的token量是普通对话的数十倍,且无需用户实时参与,导致“消费上限”不复存在。重度用户的超额用量使固定价格的订阅模式在精算上难以持续,出现了“逆向选择”——越是高价的订阅档,吸引来的越是意图“跑满”额度、导致更高补贴成本的重度用户。 行业曾尝试提价、限流等修补措施,但均告失败。如今,所谓的“订阅制”正在被掏空内核:形式上仍是每月扣款,但核心的“固定价格、放心使用”承诺已被移除。例如,GitHub Pro的月费实则为预付费积分;Claude的积分按API费率扣费。固定订阅可能仅能保留在纯聊天等消费量受限于人工时间的场景,但这类场景正被行业发展的主流边缘化。 资本市场的压力(如公司筹备上市)也加速了这一进程,公开市场投资者难以接受持续亏损的订阅模式。未来,AI支出将像云服务支出一样需要精细管理。对用户而言,这意味着“薅羊毛”的补贴期即将结束,价格信号将回归,每个人需要为自己的实际使用量付费。 文章建议,在当前订阅制仍提供高额补贴的窗口期,用户应充分利用以完成高消耗任务。订阅制的消亡不会有正式宣告,它将悄然转变为账单上一项基础的“入场费”。在此之前,且用且珍惜。

marsbit24分钟前

为什么「AI服务订阅制」,注定会走向消亡?

marsbit24分钟前

交易

现货
合约
活动图片