8 hack event(s)
Description of the event: The stablecoin trading project Platypus encountered a flash loan attack on AAVE, resulting in a total asset loss of approximately $9 million. According to the analysis, the vulnerability seems to lie in the verification of the MasterPlatypusV4 contract by the emergencyWithdraw function, which will only fail when the borrowed assets exceed the borrowing limit. The function then proceeds to transfer all of the user's deposit assets regardless of the value of the user's borrowed assets.
Amount of loss: $ 9,000,000 Attack method: Flash Loan Attack
Description of the event: On December 23, Defrost Finance V2, the Avalanche ecological native stablecoin project, was attacked by a flash loan, and the hackers made a profit of $173,000. On December 25th, Defrost Finance V1 went wrong again, hackers managed to steal the owner’s key, the protocol was added with fake collateral tokens, and a malicious price oracle was used to liquidate current users, with losses estimated at more than $12 million. On December 27, the hackers who carried out the attack on Defrost Finance V1 have returned the stolen funds.
Amount of loss: $ 12,173,000 Attack method: Private Key Leaked
Description of the event: Avalanche lending protocol Blizz Finance tweeted that Chainlink suspended LUNA oracles, allowing several attackers to deposit millions of LUNA and borrow all collateral at $0.1 per Chainlink oracle. Due to the timelock mechanism, the protocol assets are exhausted before the team is suspended. According to DeFi Llama data, the agreement’s TVL was $8.28 million yesterday, and it is now 0.
Amount of loss: $ 8,300,000 Attack method: Price update question
Description of the event: This weekend, the biggest rug pull in Avalanche history shocked the network and its users. SDOG is the first meme coin launched on Avalanche, with a price of up to 10 million U.S. dollars, and the team admitted that they "smashed it up." On the other hand, however, what they called a "game theory experiment" went wrong. Snowdog DAO is the protocol behind the SDOG token, and as of press time, its value has lost more than 90%. This is a complex plan that involves insiders using a "key" in a smart contract that only they can access.
Amount of loss: $ 30,000,000 Attack method: Rug Pull
Description of the event: SnowdogDAO, an Avalanche-based decentralized reserve memecoin, suffered a severe failure yesterday after only 8 days of operation. Snowdog created its own AMM based on Uniswap V2 to move all SDOG liquidity from DEX Avalanche Trader Joe. However, the redemption failed miserably within seconds of launch, with hundreds of users losing most of their funds.
Amount of loss: $ 30,000,000 Attack method: Rug Pull
Description of the event: Avalanche ecological stability income aggregation agreement Avaterra Finance was attacked by hackers. The security company Rugdoc analyzed that the contract of the agreement is a fork of Goose, but their token contains custom elements, and anyone can call its minting function. In the end, the hacker called the contract and minted and dumped thousands of tokens.
Amount of loss: - Attack method: The mint function has no permission control
Description of the event: According to official sources, the loan agreement Vee.Finance officially released an explanation about the attack. The content is as follows: On September 20, the Vee.Finance team noticed multiple abnormal transfers. After further monitoring, a total of 8804.7 ETH and 213.93 BTC were stolen (total Worth more than 35 million U.S. dollars). The attacker's address is: 0xeeeE458C3a5eaAfcFd68681D405FB55Ef80595BA. After investigation, the suspected attacker launched the attack through the above address and has obtained the stolen assets from this address. In order to ensure the safety of more users' assets, the team has suspended the platform contract and suspended the deposit and withdrawal functions. The stablecoin part is not affected by this attack.
Amount of loss: $ 35,000,000 Attack method: Contract Vulnerability
Description of the event: The Zabu Finance project on the Avalanche chain suffered a flash loan attack. Officially, the attackers withdrew 4.5 billion ZABU tokens from the Zabu Farm Contract, bringing the supply to 5 billion and dumping all of it to ZABU’s Pangolin LPs and Trader Joe LPs. According to DeFi analytics provider DeFiprime, the total was estimated at $3.2 million in exploits.
Amount of loss: $ 3,200,000 Attack method: Contract Vulnerability