Hacker bungles DeFi exploit: Leaves stolen $1M in contract set to self destruct

Cointelegraph發佈於 2022-04-22更新於 2022-04-22

文章摘要

In a rare comedic bungle among DeFi exploits, an attacker has fumbled their heist at the finish line leaving behind over $1 million in stolen crypto.

In a rare comedic bungle among DeFi exploits, an attacker has fumbled their heist at the finish line leaving behind over $1 million in stolen crypto.
Just after 8AM UTC on Thursday April 21st, blockchain security and analytics firm BlockSec shared it had detected an attack on a little known DeFi lending protocol called Zeed, which styles itself a “decentralized financial integrated ecosystem”.
The attacker exploited a vulnerability in the way the protocol distributes rewards, allowing them to mint extra tokens which were then sold, crashing the price to zero, but netting just over $1 million for the exploiter.
Blockchain analytics firm PeckShield noted the stolen crypto was transferred to an “attack contract”, a smart contract which automatically and quickly executes the found exploit.

However the attacker was apparently so excited by their successful heist that they forgot to transfer over $1 million worth of stolen crypto out of their attack contract before they set it to self-destruct, permanently and irreversibly ensuring the funds can never be moved.

Using a blockchain scanner to view the attack contract address shows that $1,041,237.57 worth of BSC-USD Binance-Peg token is forever stuck in the contract and the successful self-destruction of the contract was confirmed at 7:15AM UTC on April 21.
It's one of the more bizarre turns of events since the Polygon hacker did an “Ask Me Anything” using embedded messages on Ethereum(ETH) transactions after stealing $612 million from the protocol in August 2021. The question and answer session revealed the attacker hacked “for fun” and thought “cross-chain hacking is hot.”
This latest hack is on the smaller end regarding the amount stolen, and other DeFi protocol hacks have seen hundreds of millions siphoned off as with the recent Ronin bridge hack where attackers made off with over $600 million.
Other notable DeFi exploits include the $80 million worth of crypto stolen from Qubit Finance in January where attackers tricked the protocol into believing they had deposited collateral, allowing them to mint an asset representing a bridged crypto.
DeFi marketplace Deus Finance was exploited in March when hackers manipulated the price feed of a pair of stablecoins resulting in the insolvency of user funds, netting the hackers over $3 million.

你可能也喜歡

美债危机和高收益率背景下,黄金作为“金融保险”的配置价值

本文探讨了在美债危机和高收益率背景下,黄金作为“金融保险”的配置价值。文章认为,美国巨额债务、高收益率环境以及地缘政治风险等因素,削弱了投资者对传统纸币和美元资产的信心,从而凸显了黄金作为无对手方风险的价值储存手段的重要性。 核心驱动力包括:1)黄金与实际利率呈反向关系,当前低实际利率环境提供支撑;2)地缘政治紧张与能源通胀推高避险需求;3)全球央行(尤其是中国央行)持续购金,形成结构性需求;4)投资需求(如ETF)创历史新高。文章回顾了金价从2025年初约2,624美元飙升至2026年1月历史高点5,589美元的历程,并指出当前价格在约4,460-4,523美元区间。 对于投资者,获取黄金敞口的主要途径有:实物黄金、黄金ETF(如GLD、IAU)以及黄金矿业ETF(如GDX)。后者具有杠杆效应,但风险也更高。文章同时提示了黄金面临的风险,包括实际利率大幅转正、美元走强、地缘政治缓和及估值过高等。 最后,文章建议将黄金视为投资组合的保险部分,而非增长型资产,多数情况下配置比例在5%-10%为宜。投资者需密切关注美国实际利率、美伊谈判进展、央行购金数据及关键价格位(如4,500美元和5,000美元),以判断未来走势。在当前宏观环境下,持有黄金的逻辑得到了罕见的基本面支撑。

marsbit59 分鐘前

美债危机和高收益率背景下,黄金作为“金融保险”的配置价值

marsbit59 分鐘前

交易

現貨
合約
活动图片