Inverse Finance exploited again for $1.2M in flashloan oracle attack

Cointelegraph發佈於 2022-06-17更新於 2022-06-17

文章摘要

Just two months after losing $15.6 million in a price oracle manipulation exploit.

Just two months after losing $15.6 million in a price oracle manipulation exploit, Inverse Finance has again been hit with a flashloan exploit that saw the attackers make off with $1.26 million in Tether (USDT) and Wrapped Bitcoin (WBTC).
Inverse Finance is an Ethereum based decentralized finance (DeFi) protocol and a flashloan is a type of crypto loan that is usually borrowed and returned within a single transaction. Oracles report outside pricing information.
The latest exploit worked by using a flashloan to manipulate the price oracle for a liquidity provider (LP) token used by the protocol’s money market application. This allowed the attacker to borrow a larger amount of the protocol’s stablecoin DOLA than the amount of collateral they posted, letting them pocket the difference.
The attack comes just over two months after a similar April 2 exploit which saw attackers artificially manipulate collateralized token prices through a price oracle to drain funds using the inflated prices.
In response to the attack, Inverse Finance temporarily paused borrowing and removed its DOLA stablecoin from the money market while it investigated the incident, saying no user funds were at risk.
Inverse has temporarily paused borrows following an incident this morning where DOLA was removed from our money market, Frontier. We are investigating the incident however no user funds were taken or were at risk. We are investigating and will provide more details soon.
— Inverse+ (@InverseFinance) June 16, 2022
It later confirmed that only the attacker's deposited collateral was affected in the incident and only incurred a debt to itself due to the stolen DOLA. It encouraged the attacker to return the funds in return for a “generous bounty”.
In total, the attacker’s gained 99,976 USDT and 53.2 WBTC from the attack, swapping them to ETH before sending it all through the cryptocurrency mixer Tornado Cash, attempting to obfuscate the ill-gotten gains.
The previous attack in April saw attackers make off with $15.6 million in ETH, WBTC, YFI and DOLA.
DeFi marketplace Deus Finance suffered from a similar exploit in March, with attackers manipulating a price pairing within an oracle leading to a gain of 200,000 Dai (DAI) and 1101.8 ETH worth over $3 million at the time.
Beanstalk Farms, a credit based stablecoin protocol lost all $182 million worth of collateral in a flash loan attack caused by two malicious governance proposals which in the end drained all funds from the protocol.
How the latest attack went down
Blockchain security firm BlockSec analyzed that the attacker borrowed 27,000 WBTC in a flashloan swapping a small amount to the LP token used to post collateral in Inverse Finance so users can borrow crypto assets.
The remaining WBTC was swapped to USDT, causing the price of the attacker's collateralized LP token to rise significantly in the eyes of the price oracle. With the value of these LP tokens now worth far more due to the price rise, the attacker borrowed a larger amount than usual of the DOLA stablecoin.
The value of the DOLA was worth much more than the deposited collateral, so the attacker swapped the DOLA to USDT, and the earlier WBTC to USDT swap was reversed to repay the original flashloan.

你可能也喜歡

比特币将涨至40万美元?分析师用黄金走势叠加做出2026年大胆预测

一位名为Vivek Sen的分析师近日发布图表分析,提出大胆预测:如果比特币(BTC)能够复制黄金历史上的突破结构,其价格可能在2026年达到40万美元。这一论断的核心依据是将比特币当前的市场走势图与黄金过去的长期突破形态进行叠加比较。 分析师认为,随着现货比特币ETF的推出,比特币作为一种数字价值储存手段,与黄金的类比更加常见,两者在投资组合配置中的角色日益接近。图表叠加展示了一种相似的宏观上升趋势。 然而,文章明确指出,这种基于图表视觉对比的预测存在重大局限。比特币和黄金在市场深度、流动性、波动性以及投资者构成上存在根本差异。黄金的历史走势并非比特币未来的可靠蓝图。比特币价格受到衍生品持仓、ETF资金流、交易所流动性和加密货币领域特有的高杠杆影响,其波动更为剧烈和敏感。 要实现如此高的价格目标,市场需要一系列条件的支持,包括持续强劲的机构资金流入、改善的流动性、有利于硬资产需求的宏观经济环境,以及整体的加密货币风险偏好上升。此外,比特币必须维持其宏观上升趋势。 因此,这篇报道强调,40万美元的目标应被视为一种基于社交媒体分析的看涨情景设想,而非严谨的概率加权预测。它更像是提供了一个讨论上行空间的框架,其实现需要实际市场资金流和价格行为的进一步确认。投资者在参考此类乐观类比时,应同时关注更实际的价格水平、资金流动数据等基本面信息。

bitcoinist1 小時前

比特币将涨至40万美元?分析师用黄金走势叠加做出2026年大胆预测

bitcoinist1 小時前

交易

現貨
合約
活动图片