RateLimited°C
09-22-2024
BSV
$48.55
Vol 15m
-1.93%
BTC
$63180
Vol 16196.48m
-0.01%
BCH
$341.19
Vol 163.16m
-0.69%
LTC
$67.81
Vol 284.14m
1.38%
DOGE
$0.1
Vol 509.1m
-2.14%

It has been revealed that 371,260 USDC was lost during the August 4 exploit of the DeFi protocol Opyn. According to the official announcement from the Opyn team, a “double exercise” attack took place.

During the attack, the attacker was able to exploit the platform in a way that allowed them to receive ETH put option contract collateral as well as the ETH put option contract settlement money—when they really should have only had access to the settlement money. This is the sixth DeFi protocol exploit to take place since the beginning of this year. In total, the six exploits have resulted in the loss of over $31 million dollars.

How it happened

What’s interesting about every DeFi exploit that has taken place this year is that none of them involved a hack or a breach of a database. According to an analysis of the Opyn exploit by the blockchain analytics firm PeckShield, the attacker was able to exploit Opyn because they had a strong understanding of the protocol and the functions that could be used to interact with the protocol.

“This hack was done by calling exercise() with more than two vaults with ETH as the underlying assets. Since the implementation treats the same batch of ETH received as multiple batches of ETH receptions, the hacker re-uses that batch of ETH to retrieve the collateral USDC and make profits.”

In its notice, Opyn confirmed that “439,170 USDC from outstanding vaults was successfully recovered by a white hat hack that the Opyn team conducted on the Convexity Protocol to mitigate further loss… [and by] working with [Twitter user] @samczsun, we were able to whitehack an additional 132,995 USDC.”

At the moment, it is unclear how the open team was able to recover a total of 572,165 USDC when only 371,260 USDC was exploited during the hack. When CoinGeek reached out to the Opyn team for more insight, we did not hear back at press time.

Recommended for you

Latvia to offer pre-licensing consultations to VASPs
With MiCA taking effect in December, Latvia’s central bank is offering free pre-licensing consultation to VASPs seeking to apply for...
September 16, 2024
RockWallet gets another money transmitter license in US
Following its money transmitter license in Alabama, RockWallet said regulatory compliance is a cornerstone of its business strategy, and it's...
September 13, 2024
Advertisement