Telegram (AI) YouTube Facebook X
Ру
Hackers Exploit Old Vulnerability to Breach Onyx for $3.8 Million

Hackers Exploit Old Vulnerability to Breach Onyx for $3.8 Million

On September 26th, the DeFi protocol Onyx suffered an attack, resulting in a loss of $3.8 million. This marks the second breach of the platform this year, both times using the same exploit.

According to PeckShield, hackers exploited a known flaw in the Compound Finance v2 code and took advantage of a vulnerability in the NFT liquidation contract.

On November 1, 2023, unknown attackers withdrew approximately $2.1 million from Onyx using a similar attack method.

Analysts assert that the Compound Finance v2 flaw can only be exploited in a “nearly empty market” or when liquidity is absent.

The faulty NFT contract allowed the perpetrator to “inflate the self-liquidation reward amount,” as it “did not properly validate user input.”

The Onyx team confirmed the incident, stating that the primary cause of the exploit was the non-fungible token contract.

The DAO is initiating a vote on relaunching the protocol and rethinking its governance structure. Developers have proposed launching an open-source financial network, Onyx Core, which will underpin the compromised Onyx Protocol.

“This proposal will close the Ethereum-based lending market and reimburse all affected users in full, at a 1:1 ratio of the assets they provided,” the statement reads.

Previously, hackers stole $2 million from the Bitcoin restaking protocol Bedrock due to a vulnerability in the synthetic token uniBTC.

Earlier, between July and September, cryptocurrency companies faced 34 incidents of hacks and fraud, resulting in losses exceeding $413 million, according to Immunefi.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK