Belt Finance loses millions in latest BSC-based DeFi exploit

Belt Finance loses millions in latest BSC-based DeFi exploit

Belt Finance has become the latest Binance Smart Chain-based decentralized finance, or DeFi, protocol to lose millions to an opportunistic hacker.

The Rekt Blog, which post mortems DeFi exploits, stated that an attacker exploited a flaw in the way the protocol’s vaults calculates the value of its collateral which helped to “add another notch to the now infamous flash loan exploit season on the BSC,” adding:

Our top trading bots

“Yet another fork of a fork has rolled off the conveyor belt with $6.3M falling straight into the hands of the hacker.”

Rekt revealed that a total of eight flash loans were made on PancakeSwap for $385 million BUSD. The beltBUSD vault's “Elipsis” strategy was exploited as it was the most undersubscribed strategy on the platform.

Belt Finance uses an optimal yield aggregator to offer passive yield generation to depositors. Elipsis is a decentralized exchange that enables swapping of stablecoins with low slippage on the Binance Smart Chain. The beltUSD vault also deploys capital on the BSC-based protocols Venus, Alpaca, and Fortube for yield generation.

On May 30, SushiSwap core developer Mudit Gupta posted a Twitter thread examining the incident, describing the flash loan attack as one of the “more complex hacks.”

Belt’s vaults operate with a target balance for each strategy employed, he explained. When a user deposits money into a vault, the capital is allocated to the most undersubscribed strategy. When someone withdraws money from the vault, it withdraws it from the most oversubscribed strategy.

Gupta asserted the attacker exploited this system to make several transactions across multiple strategies, inflating the value of its pools before repaying the flash loan and pocketing more than $6 million in profits. Gupta concluded:

“Basically, the issue happened because Belt incorrectly integrated with Elipsis. A similar issue happened last month as well in belt finance but at that time, the problem was a buggy integration with Venus. I wonder if belt has any bug-free integration.”

Venus is another BSC protocol for lending and borrowing via the minting of synthetic stablecoins.

Belt Finance is the latest in a lengthening list of BSC DeFi protocols to get exploited. On May 28, the BurgerSwap DEX was attacked resulting in the draining of $7.2 million.

So far this year, Cream Finance, bEarn, Bogged Finance, Uranium Finance, Meerkat Finance, SafeMoon, and Spartan Protocol have all suffered exploits on Binance Smart Chain. Binance has now turned to blockchain intelligence company CipherTrace for analytics support in a bid to mitigate further incursions.

Read on relating to Cointelegraph
OpenSea smart contract upgrade to delist inactive NFTs on Ethereum
OpenSea, one of the most popular nonfungible token (NFT) marketplace, has rolled out an upgrade to its smart contract, a proactive measure to weed out inactive...
Iran to reportedly pilot central bank digital currency soon
The Central Bank of Iran (CBI) is reportedly planning to launch a central bank digital currency (CBDC) pilot soon.According to a report by the Iranian Labour...
Centralized systems are here to stay, says Binance CEO CZ
In a tongue-in-cheek hot seat video to round off 2021, Binance CEO Changpeng Zhao, or “CZ,” responded to a series of curated Tweets from the Binance community.The...
UK advertising watchdog bans crypto ads for Coinbase and Kraken
The Advertising Standards Authority, or ASA, the United Kingdom’s independent advertising regulator, has taken down another batch of cryptocurrency-related...
Alexandria Ocasio-Cortez says US lawmakers shouldn't hold crypto to 'remain impartial'
Democratic lawmaker Alexandria Ocasio-Cortez said Monday that she avoids any and all investments which could potentially represent a conflict of interest,...
India’s top payment firm Paytm reportedly considers Bitcoin services
Paytm, India's leading digital payments company, said Thursday that it would consider Bitcoin services if the country's regulatory framework for cryptocurrencies...
Vitalik talks DAOs, Ethereum and NFTs in new interview
In a recent podcast interview with The Stakeborg Talks, co-founder of Ethereum Vitalik Buterin spoke candidly on a wide range of issues, including his early...
Institutional demand for Bitcoin evaporates as BTC struggles below $31K
The rocky road that Bitcoin (BTC) has been on for the past two months continued on July 19 as a widely predicted move downwards materialized in the early...
Grayscale Bitcoin premium rebounds as BTC price falls below $35K — What does it mean?
Bitcoin (BTC) has crashed by around 44% from its all-time high of $64,899, signaling an end to its second-largest bull run that started in March 2020. Many...
Cardano Jumps 21% In Rally
Investing.com - Cardano was trading at $1.643326 by 13:55 (17:55 GMT) on the Investing.com Index on Sunday, up 20.84% on the day. It was the largest one-day...
Fact check: Has Coinbase launched a decentralized fact checking portal?
Coinbase CEO Brian Armstrong has announced the launch of what he’s calling a “Fact-Check" via the company’s blog. In a May 27 post titled “Announcing Coinbase...
UK ad organization bans crypto exchange’s ‘time to buy’ Bitcoin advert
A major advertising industry organization in the United Kingdom has ruled on an ad campaign telling people “it’s time to buy” Bitcoin (BTC).The Advertising...
After a remarkable run, social media sentiment sours on DOGE
It was a Shiba Inu shooting across the sky: Dogecoin’s run over the past week will be one for the history books. However, for all the fireworks social media...
JPMorgan, Mastercard, UBS lead $65M ConsenSys raise
ConsenSys, a prominent blockchain software company, has raised $65 million in strategic investments from major financial institutions including JPMorgan...
Six South Korean Banks To Open Crypto Accounts in A Week, Exchanges Fined For Poor Security
Finally, things are getting better in South Korea. Within a week six country’s banks will be able to permit contemporary opening of accounts, withdrawals,...