{"id":88350,"date":"2023-12-16T20:49:58","date_gmt":"2023-12-16T18:49:58","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=88350"},"modified":"2025-09-13T17:31:28","modified_gmt":"2025-09-13T14:31:28","slug":"defi-bulletin-tvl-tops-50-billion-yearn-finance-loses-1-4-million","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/defi-bulletin-tvl-tops-50-billion-yearn-finance-loses-1-4-million\/","title":{"rendered":"DeFi Bulletin: TVL tops $50 billion, Yearn Finance loses $1.4 million"},"content":{"rendered":"<p>The decentralised finance (DeFi) sector continues to attract heightened attention from crypto investors. ForkLog has compiled the key developments and news from recent weeks in this digest.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Key DeFi sector metrics<\/strong><\/h2>\n<p>The value of total value locked (TVL) in DeFi protocols rose to $51.5 billion. Led by Lido with $20.7 billion, the second and third spots are held by Maker ($8.4 billion) and JustLend ($6.5 billion), respectively.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"581\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-12.47.33-1024x581.png\" alt=\"Snimok-ekrana-2023-12-16-v-12.47.33\" class=\"wp-image-222301\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-12.47.33-1024x581.png 1024w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-12.47.33-300x170.png 300w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-12.47.33-768x436.png 768w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-12.47.33-1536x872.png 1536w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-12.47.33-2048x1162.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Data: <a href=\"https:\/\/defillama.com\/\">DeFi Llama<\/a>.<\/figcaption><\/figure>\n<p>TVL in Ethereum applications <a href=\"https:\/\/defillama.com\/chain\/Ethereum?tvl=true\">\u0432\u044b\u0440\u043e\u0441<\/a> to $28.4 billion. Trading volume on decentralised exchanges (DEX) over the last 30 days <a href=\"https:\/\/dune.com\/hagaetc\/dex-metrics\">\u0441\u043e\u0441\u0442\u0430\u0432\u0438\u043b<\/a> $77.1 billion.<\/p>\n<p>Uniswap continues to dominate the non-custodial exchange market \u2014 it accounts for 55.7% of total turnover. The second DEX by volume is PancakeSwap (15.1%), the third is Trader Joe (8%).<\/p>\n<h2 class=\"wp-block-heading\"><strong>OKX DEX <a href=\"https:\/\/forklog.com\/en\/news\/okx-dex-loses-430000-in-hack\">suffered an exploit worth $2.76 million<\/a> in what PeckShield analysts described as damage stemming from an alleged leak of the proxy-server administrator private key.<\/strong><\/h2>\n<p>According to SlowMist, during a swap on the platform users authorize a TokenApprove contract, which then transfers the user&#8217;s tokens.<\/p>\n<p>The ClaimTokens function enables a trusted DEX proxy server to call it. The servers are run by administrators who can modify the smart contract at will.<\/p>\n<p>On December 12, the owner of one of the servers updated it, allowing direct invocation of ClaimTokens to transfer users&#8217; tokens. The attacker exploited this vulnerability.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Yearn Finance loses $1.4 million due to a transaction error<\/strong><\/h2>\n<p>As a result of an &#8216;erroneous scenario&#8217; <a href=\"https:\/\/forklog.com\/en\/news\/what-is-a-multisignature-what-is-a-ring-signature\">multisig<\/a>-transaction, DeFi protocol Yearn Finance <a href=\"https:\/\/forklog.com\/en\/news\/yearn-finance-loses-1-4-million-due-to-a-transaction-error\">lost<\/a> 63% of treasury funds in the yCRV LP pool.<\/p>\n<p>The incident occurred during the &#8216;routine process of converting fee tokens&#8217; and led to the exchange of 3,794,894 yCRV for 779,958 yvDAI. The team clarified that losses amounted to $1.4 million.<\/p>\n<p>The yCRV <a href=\"https:\/\/forklog.com\/en\/news\/what-is-liquid-staking\">liquid-staking<\/a> token presents Curve CRV in the protocol&#8217;s pool. The project allocates funds within the structure to maintain liquidity and earn revenue from fees.<\/p>\n<p>However, due to a glitch in the exchange script for the DEX CoW Swap, all treasury funds were sent to a single one of the protocol&#8217;s largest pools. The trade caused significant price slippage, which &#8216;arbitrageurs and other market participants&#8217; exploited.<\/p>\n<p>Developers explained that the erroneous transfer of the entire Yearn Finance balance in the pool was one of 30 orders executed via multisig <a href=\"https:\/\/forklog.com\/en\/news\/yearn-finance-loses-1-4-million-due-to-a-transaction-error\">transaction<\/a>. This hindered manual oversight, and the swap script &#8216;lacked sufficient withdrawal checks and contained a logic error&#8217; in capping the swap size.<\/p>\n<p>To prevent similar incidents, Yearn Finance adopted a series of safeguards, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>split treasury funds in the pool into contracts managed by separate administrators;<\/li>\n<li>introduction of more readable output messages in trading scripts;<\/li>\n<li>tightening price-impact thresholds.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>DeFi project SafeMoon files for bankruptcy<\/strong><\/h2>\n<p>On December 14, SafeMoon&#8217;s attorney Mark Rose <a href=\"https:\/\/forklog.com\/en\/news\/safemoon-defi-project-files-for-bankruptcy\">filed for bankruptcy<\/a> for the DeFi project. The SFM token reacted with a sharp drop.<\/p>\n<p>Chapter 7 bankruptcy filings have been submitted to the United States District Court for the District of Utah. SafeMoon US LLC valued its assets at between $10 million and $50 million, while liabilities were between $100,001 and $500,000.<\/p>\n<p>In the wake of the news, the SFM token collapsed to around $0.000055. Over the past week the coin has fallen 22.4%, according to <a href=\"https:\/\/www.coingecko.com\/en\/coins\/safemoon\">CoinGecko<\/a>.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-14.05.51-1024x640.png\" alt=\"Snimok-ekrana-2023-12-16-v-14.05.51\" class=\"wp-image-222302\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-14.05.51-1024x640.png 1024w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-14.05.51-300x188.png 300w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-14.05.51-768x480.png 768w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-14.05.51-1536x960.png 1536w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-12-16-v-14.05.51-2048x1280.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Intraday SFM\/USDT chart on Gate.io. Data: <a href=\"https:\/\/www.tradingview.com\/symbols\/SFMUSDT\/?exchange=GATEIO\">TradingView<\/a>.<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\"><strong>Nirvana Finance hacker agrees to return $12.3 million<\/strong><\/h2>\n<p>The hacker responsible for the Nirvana Finance yield-farming protocol breach and an unnamed DEX <a href=\"https:\/\/forklog.com\/en\/news\/nirvana-finance-hacker-agrees-to-forfeit-12-3-million\">pleaded guilty<\/a> and agreed to forfeit stolen assets worth $12.3 million.<\/p>\n<p>According to the U.S. Attorney&#8217;s Office, in the summer of 2022, 34-year-old senior security engineer Shaki Ahmed exploited a vulnerability in the smart contract of an unnamed exchange.<\/p>\n<p>A few weeks later he <a href=\"https:\/\/forklog.com\/en\/news\/hackers-attacked-the-nirvana-defi-project-the-nirv-stablecoin-lost-parity-with-the-dollar\">attacked Nirvana Finance<\/a> using an <a href=\"https:\/\/forklog.com\/en\/news\/what-are-flash-loans\">instant loan<\/a> and withdrew $3.49 million in crypto from the project&#8217;s treasury. Although protocol developers offered the hacker a bounty, the parties did not reach an agreement. The stolen funds were swapped for Monero and laundered through Samourai Whirlpool mixer.<\/p>\n<p>In July Ahmed was charged with wire fraud and money laundering. In addition to forfeiture of the stolen cryptocurrency, he was ordered to pay $5 million in restitution to victims.<\/p>\n<p>The final sentence will be handed down on March 13, 2024. Ahmed faces up to five years in prison.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>Coinbase first <a href=\"https:\/\/forklog.com\/en\/news\/coinbase-lists-token-from-base-network-for-the-first-time\">listed<\/a> a token from the Base network.<\/li>\n<li>Uniswap DEX <a href=\"https:\/\/forklog.com\/en\/news\/uniswap-launches-on-bitcoin-sidechain-rootstock\">launched<\/a> on the Bitcoin-sidechain Rootstock.<\/li>\n<li>The court <a href=\"https:\/\/forklog.com\/en\/news\/court-drops-criminal-charges-against-platypus-finance-hacker\">ceased<\/a> criminal proceedings against the Platypus Finance hacker.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The decentralised finance (DeFi) sector continues to attract heightened attention from crypto investors. ForkLog has compiled the key events and news from recent weeks in this digest.<\/p>\n","protected":false},"author":1,"featured_media":88351,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1299,1233],"class_list":["post-88350","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-defi-bulletin","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"19","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/88350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=88350"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/88350\/revisions"}],"predecessor-version":[{"id":88352,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/88350\/revisions\/88352"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/88351"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=88350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=88350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=88350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}