Latest

Transaction batching protocol Furucombo suffers $14 million “evil contract” hack

img-ads

The latest “evil contract” exploit has netted an attacker over $14 million in stolen funds. 

Furucombo, a tool designed to help users “batch” transactions and interactions with multiple protocols at once, fell victim to the attack which centered on token approvals from users.

The attacker’s address currently has $14 million worth of various cryptocurrencies, but the attack appears to be larger as they have been transferring ETH to privacy mixer Tornado Cash in batches over the last hour.

This attack is conceptually similar to the $20 million “evil jar” attack that struck Pickle Finance last year, as well as the $37 million “evil spell” exploit that hit Alpha Finance earlier this month. In these “evil contract” exploits, an attacker creates a contract that fools a protocol into believing it belongs there, giving them access to protocol funds.

In this case, the attacker ‘tricked’ the Furucombo protocol into thinking that their contract was a new verison of Aave. From there, instead of draining funds from the protocol as in previous evil contract exploits, the attacker instead leveraged the ability to transfer the funds of every user who had given the protocol token permissions. 

“Infinite permissions means you can wipe everyone who interacted with Furucombo,” said whitehat hacker and co-founder of DeFi Italy Emiliano Bonassi in a statement to Cointelegraph.

This type of exploit appears to be growing increasingly popular, now accounting for over $70 million in user funds lost in just a few months.

The team confirmed the attack in a Tweet, saying that they “believed” they’d mitigated the exploit but recommended revoking permissions “out of an abundance of caution:”

Users can leverage tools like revoke.cash to do so. 

The attack comes during a period of wider reflection in the DeFi world on security and the utility of auditing companies. In the last three months, three different auditing and code review services have emerged, each with a different incentive model designed to encourage more thorough and dynamic security practices.

img-ads

Leave a Comment

Your email address will not be published.

You may also like

Blockchain Markets

NBA Top Shot leads NFT explosion with $230M in sales

Dapper Labs, the creator of the CryptoKitties game, is helping the National Basketball Association, or NBA, become a magnet for digital collectibles. 

NBA Top Shot, a marketplace for non-fungible tokens, or NFTs, has generated over $230 million in sales, according to Dapper Labs. NBA Top Shot is built on Dapper’s Flow blockchain, allowing users to purchase “packs” that feature in-game moments. With packs almost always sold out, a secondary marketplace is the only way for users to access specific moments.

Recently, a LeBron James highlight sold for $200,000. A Zion Williamson spotlight sold for around the same amount.

NFTs, which exist entirely on the blockchain, are revolutionizing the traditional model of trading cards. In the case of NFTs, the value of a particular moment is governed by the same laws of supply and demand, though ownership is entirely digital. The blockchain also…

View More Article
Bitcoin Business

OLB Group enables crypto payments for thousands of US merchants

OLB Group (OLB), a New York-based e-commerce merchant service provider, is making it easier for businesses to accept cryptocurrency payments.

OLB’s more than 8,500 merchants are now able to accept Bitcoin (BTC), Ethereum (ETH), USDC and DAI at the point-of-sale through the company’s OmniSoft business management platform. Customers wishing to pay with cryptocurrency in-store or through their mobile phones can simply elect to do so with their cryptocurrency wallets. All payments are processed through SecurePay, a payment gateway that authenticates the transaction, converts the cryptocurrency to U.S. dollars and approves the final sale.

The decision to integrate cryptocurrency payments was partly driven by the growth of contactless and online orders during the Covid-19 pandemic. With the OmniSoft platform already providing merchants with several options to facilitate payments, cryptocurrencies were the next logical step. 

Ronny Yakov, OLB Group’s CEO, says the payment gateway and point-of-sale architecture are “familiar territory for…

View More Article
Bitcoin Blockchain Opinion Policy & Regulation Tech

Transparent stablecoins? Conclusion of Tether vs. NYAG raises new questions

A long-standing legal drama finally found resolution on Feb. 23, with the New York Attorney General’s office announcing that it had come to a settlement with cryptocurrency exchange Bitfinex after a 22-month inquiry into whether the company had been trying to cover up its losses — touted to be worth $850 million — by misrepresenting the degree to which its Tether (USDT) reserves were backed by fiat collateral.

According to the terms of the announced settlement, which now marks an end to the inquiry that was initiated by the NYAG back in Q1 2019, Bitfinex and Tether will pay the government body a fixed sum of $18.5 million but will not be required to admit to any wrongdoing. That being said, the settlement clearly states that henceforth, Bitfinex and Tether can no longer service customers in the state of New York.

Furthermore, over the course of the…

View More Article
Bitcoin Business Investment Opinion Tech

Dogecoin hasn’t always been a ‘fun meme coin’

Dogecoin (DOGE) might look like a fun meme coin, particularly as its price has absolutely skyrocketed in 2021.

But behind the innocent Shiba Inu dog cartoon are some horrific stories. Those buying the cryptocurrency due to shilling and jokes from Tesla and SpaceX CEO Elon Musk, most likely have no idea of DOGE’s early days.

DOGE/USD 1-day candle chart (HitBTC). Source: Tradingview

The early days

Introduced by software engineers Billy Markus and Jackson Palmer in December 2013, Dogecoin’s protocol followed Luckycoin and Litecoin (LTC) proof-of-work algorithm using Scrypt technology.

It all started back on Christmas day, 2013, when Dogewallet announced that its webpage had been compromised, causing users to send funds to the hacker’s address. The $12,000 worth of users’ coins lost was fully reimbursed by Dogecoin Foundation Board Member Ben Doernberg, which included community-funded donations.

How many times have you heard about…

View More Article
Bitcoin Latest Markets

Bitcoin sell-off over? Strong ‘buy the dip’ signal flashes for the first time in 5 months

The price of Bitcoin (BTC) has dropped to the key $44,000-$45,000 support level on Feb. 28 for the third time in the past week.

BTC/USD 1-hour candle chart (Bitstamp). Source: Tradingview

The BTC/USD pair briefly dipped below $44,000 on Bitstamp before paring some of the losses, bouncing back above $45,000 at the time of writing. 

‘Full rest’ for SOPR, funding rates

Some analysts have pointed out an uptick in miners’ selling as the reason behind the latest drop in price. 

Fortunately, the third retest of this key support level may have a silver lining for…

View More Article
Bitcoin Blockchain Investment Markets Opinion Policy & Regulation Tech

Professional traders need a global crypto sea, not hundreds of lakes

Coinbase’s IPO announcement has been hailed as “a milestone for the crypto industry” by Fortune Magazine. Similar to the Netscape IPO announcement that signaled the legitimacy of the internet, Coinbase’s impending public offering signals to the public at large that cryptocurrency trading is legitimate, legal and secure in the eyes of the Securities and Exchange Commission. And now, investors have an opportunity to own stock on the largest crypto trading platform in the United States.

As a result, many see an investment in Coinbase as an investment in the future of crypto trading. It is the highest volume U.S. crypto exchange, with three times the volume of its next closest U.S. competitor. The largest of anything in the U.S. must be the world leader. Except, it’s not. And conventional wisdom and current market realities are very far apart.

In order to understand…

View More Article
%d bloggers like this: