DeFi disasters: $31M drained from MonoX and BadgerDAO losses top $120M

DeFi disasters: $31M drained from MonoX and BadgerDAO losses top $120M

More than $150 million has been lost this week in separate security breaches at DeFi projects MonoX and BadgerDAO.

Multi-chain decentralized exchange (DEX) MonoX (MONO) suffered a cyber attack on Nov. 30 leading to about $31 million in losses. BadgerDAO (BADGER) suffered a front-end attack that was discovered on Dec. 2 with estimates of Badger’s losses hitting more than $120 million.

Our top trading bots

The MonoX DEX platform suffered a single attack on Nov. 30. In this attack, a bug in the smart contract allowed for a discrepancy to exist between prices of assets, when manually changed.

Rekt News explained that hackers were able to inflate the price of MONO via the smart contract, then buy up other assets from the protocol with MONO.

“The hacker created a loop in which the price of tokenOut would overwrite the price of tokenIn, pumping the price of MONO over the course of many 'swaps.'”

The MonoX team confirmed as much in a Nov. 30 tweet. In a postmortem published on Dec. 2, total losses were confirmed at about $31 million. The team added:

"Days like yesterday are horrible, there is no sugar coating the harsh reality of a contract being exploited and people losing money. Our supporters put their faith in a new project like us, and yesterday we let them down."

MONO listed on Huobi only five days before the hack on MonoX.

The Badger security breach was an ongoing threat to users interacting with Badger DAO’s platform rather than a single large exploit.

Discord users began reporting unusual spend requests from the Badger platform and alerted admins on social media and on Discord as early as Nov. 27.

Admin Blackbear responded that the request was unusual, but likely caused by a benign bug in the front-end user interface (UI).

https://twitter.com/0xMoves/status/1466275399944445952

The bug in the UI turned out to be the malicious attacker attempting to steal funds from that user’s withdrawal. The same tactic would be used on random users for days, or even weeks before it was discovered as a security breach.

Related: Hackers can use compromised Google Cloud accounts to install mining software in under 30 seconds: Report

At time of writing, losses from the Badger attack amounted to over $120 million, including 2078.76 BTC, 30.27 ibBTC, and 151.32 ETH, according to blockchain analytics company PeckShield. The Badger team has been investigating the issue and have paused all smart contracts on the protocol to avoid any further losses.

Read on about Cointelegraph
GameStop NFT Marketplace now live and powered by Loopring L2
GameStop has confirmed its integration with Loopring (LRC), an Ethereum Layer 2 zkRollup protocol designed for powering decentralized cryptocurrency exchanges,...
Internet Computer founder's $250M plan to help end the war in Ukraine
Internet Computer (ICP) and DFINITY founder Dominic Williams has conjured up an oddball plan to speed up the end of the Russian invasion of Ukraine via...
3 reasons why XRP price could drop 25%-30% in March
Ripple‘s XRP price risks dropping by more than 25% in the coming weeks due to a multi-month bearish setup and fears surrounding excessive XRP supply.XRP...
Crypto investors face more uncertainty after rocky start to 2022
By John McCrankNEW YORK (Reuters) -Investors are bracing for more gyrations in bitcoin and other cryptocurrencies, as worries over a hawkish Federal Reserve...
Love in the time of crypto: Does owning cryptocurrency make daters more desirable?
Cryptocurrency has become one of the most widely discussed topics of 2022. As such, it shouldn’t come as a surprise that mentioning “crypto” in an online...
Nifty News: The Lennon Collection, Gucci and Lamborghini NFTs, Atari's 50th anniversary
Let's start off the week with the latest nonfungible token (NFT)-related news in today's Nifty News. The following collections are either ongoing or launching...
German savings banks want to enable Bitcoin for 50M clients
German savings banks are planning to allow customers to invest in major digital currencies like Bitcoin (BTC) and Ether (ETH) directly from checking accounts.Savings...
Bitcoin hovers below peak, doubts linger over boost from U.S. ETF
By Tom Wilson and Alun JohnLONDON/HONG KONG (Reuters) -Bitcoin hovered on Thursday below its all-time high struck a day earlier after the launch of the...
SEC chair compares stablecoins to casino poker chips
United St Securities and Commission, or SEC, chair Gary Gensler has doubled down on his “Wild West” analogy for cryptocurrencies, calling stablecoins instruments...
Former SEC Chair Jay Clayton joins Fireblocks advisory board
Jay Clayton, the former chair of the United States Securities and Exchange Commission, has accepted an advisory role with blockchain infrastructure provider...
Malaysia is literally crushing thousands of illegal Bitcoin miners
Authorities in Malaysia destroyed more than $1.2 million worth of Bitcoin mining rigs after they were confiscated for operating illegally.In a video posted...
Polkadot ETP hits Swedish stock market
The mainstream financial world has taken notable strides to incorporate various crypto assets. A new exchange-traded product (ETP) for Polkadot (DOT) recently...
New 'inverse' Bitcoin ETF now lets investors short BTC price
Bitcoin (BTC) investors in Canada have two more outlets for BTC exposure this week — and can now even bet on a price crash.In a press release on April 14, Horizons...
Japan's FSA asks cryptocurrency industry group to introduce FATF travel rule
Japan has made another step toward adopting cryptocurrency Anti-Money Laundering regulations developed by the Financial Action Task Force, Cointelegraph...
Increased Supply of Altcoins Will Depress Bitcoin, Says St. Louis Fed Report
As it is known, crypto-supporters (bitcoin bulls) widely believe that the increase in the capped supply of all cyber-coins will boost bitcoin’s value to...