‘Unlucky’: Agave and Hundred Finance DeFi protocols exploited for $11M

‘Unlucky’: Agave and Hundred Finance DeFi protocols exploited for $11M

A hacker has made off with approximately $11 million in Wrapped ETH, Wrapped BTC, Chainlink, USDC, Gnosis, and Wrapped XDAI after using a “re-entrancy” attack on DeFi lending protocol applications Agave and Hundred Finance.

The attack comes within 24 hours of news breaking of the Deus Finance exploit, where hackers stole over $3 million in Dai and Ethereum from the lending contract platform.

Our top trading bots

Agave’s token, AGVE, dropped by 20 per cent following the attack, according to data from CoinGecko. Hundred Finances’ token HND fell 3.5 per cent after it announced the exploit, however it’s since recovered to hit a 24-hour-high.

“Agave is currently investigating an exploit on the agave finance protocol”, Agave tweeted on Tuesday 15th at 1:30pm UTC, “We will update you as soon as we know more.” It noted that the contracts have been paused until the situation is resolved.

The Hundred Finance team also tweeted it was exploited on Gnosis chain, and has paused its markets whilst it pursued investigations.

According to on-chain analysis, the address associated with the attacker has sent over 2,100 ETH, worth over $5.5 million, to a crypto mixer in an attempt to launder the stolen tokens.

Related:Deus Finance exploit: Hackers get away with $3M worth of DAI and Ether

Solidity developer and creator of an NFT liquidity protocol app, Shegen (@shegenerates) tweeted that she lost $225,000 in the exploit, and that her investigations revealed the attack worked by exploiting a wETH contract function on Gnosis Chain that allowed the attacker to continue borrowing crypto before the apps could calculate the debt, which would prevent further borrowing.

The attacker ran this exploit, continually borrowing against the same collateral they were posting until the funds were drained from the protocols.

Shegen told Cointelegraph that while the smart contract on Agave is essentially the same as Aave, which secures $18.4B, “every security researcher has audited it,” she said “so it’s reasonable to assume the contract is safe.”

“I think this hack stands out more than some bigger ones,” Shegen said, noting that even if it's a smaller hack compared to others that stole millions more, the similarity to Aave meant “it seems top tier safe, but wasn't, and that break of trust hurts.”

“It’s like you can't even trust “safe” code.”

Blockchain security researcher Mudit Gupta says the difference between Aave and Agave is that “Aave actively checks for re-entrancy before listing tokens on the main net to avoid similar attacks.”

Shegen stated that she did not blame the Agave developers for failing to prevent the attack.

“Agave was used in an unsafe way”, she said, “maybe the developer should not have allowed tokens with callbacks in them to be used in the platform, or added more re-entrancy guards.”

“Curve, for example, was not hacked today, because it has extra re-entrancy guards, but I don't really blame Luigy and the Agave team because it's so unlikely that this would have happened, and slipped past many people.”

Shegen also didn’t point the blame at Gnosis for creating tokens with a callback function which the hacker exploited, saying that the feature stops users from accidentally losing their crypto.

“That's actually a great feature for bridged tokens, it's just a really unfortunate, and unlucky circumstance in my opinion.”

Keep reading with Cointelegraph
Self-made wealth more likely to flow into crypto than inherited: Report
Self-made wealthy individuals worldwide appear more likely to invest in cryptocurrencies like Bitcoin (BTC) as opposed to those whose wealth is mostly inherited,...
Here’s a clever options strategy for cautiously optimistic Bitcoin traders
Bitcoin (BTC) entered an upward channel in early January and despite the sideways trading near $40,000, order book analysts cited "significant buying pressure" and...
Trudeau revokes emergencies act powers but the case for crypto grows
Prime Minister of Canada Justin Trudeau has announced he will repeal emergency powers used to freeze $8 million from 210 bank accounts connected to Canadian...
Russia’s Finance Ministry introduces digital currency bill, brushes off Central Bank’s objections
Russia’s Ministry of Finance has upped the stakes in its drawn-out showdown against the country’s Central Bank (CBR) by formally introducing a bill that...
First DEX on Internet Computer launches, others coming soon
The first decentralized exchange on the Dfinity Foundation’s Internet Computer blockchain went live this week, following up on the recent release of a new...
Engineer hacks Trezor wallet, recovers $2M in 'lost' crypto
A computer engineer and hardware hacker has revealed how he managed to crack a Trezor One hardware wallet containing more than $2 million in funds.Joe Grand...
FTX founder urges regulators to create a unified crypto framework
Sam Bankman-Fried, the founder and CEO of crypto exchange FTX, reportedly called out regulators to create a single framework for digital assets in the Asian...
Fractal: 110K join Discord of Twitch founder’s new NFT gaming marketplace
Twitch co-founder Justin Kan launched a new blockchain gaming-focused NFT marketplace yesterday dubbed Fractal.Fractal’s Discord group has since amassed...
Gamer-hate: Ubisoft's new NFT project vid gets 96% dislike ratio
French gaming giant Ubisoft Entertainment SA’s new nonfungbile token (NFT) project Quartz is facing strong pushback from the gaming community. Ubisoft unveiled...
One more Bitcoin price dip? BTC may fall again before 'slow grind up,' warns analyst
Bitcoin (BTC) rebounded to near $50,000 on Dec. 5 as traders continued to take stock of recent events.BTC/USD 1-hour candle chart (Bitstamp). Source: TradingViewData...
Long-term Bitcoin bulls hodl strong despite five-month price high
On-chain analytics provider glassnode reports that long-term Bitcoin holders are refusing to sell despite the BTC markets rallying to a five-month price...
Digital turns physical: Top NFT galleries to visit in-person in 2021
As restrictions seem to be easing for many, people who are looking to leave their houses and discover their region or country can ride the nonfungible token...
Major US trading platform Interactive Brokers to offer cryptocurrency trading
United States foreign exchange company Interactive Brokers will offer direct cryptocurrency trading to clients within months, a report says.Speaking at...
Bitcoin ticks back in Asia after Musk tweet sent price down 17%
By Kevin Buckland and Alun JohnTOKYO/HONG KONG (Reuters) - Bitcoin rebounded to about $50,000 in Asian trading on Thursday after plunging as much as 17%...
Fresh wave of interest pushes Cardano near all-time highs
Cardano (ADA) made a run at its all-time price high on March 18, following renewed retail interest in the asset. It ultimately hit a price of $1.47 on Thursday,...