White hat potentially saves SushiSwap $350M by finding ‘obvious’ exploit

White hat potentially saves SushiSwap $350M by finding ‘obvious’ exploit

The SushiSwap decentralized exchange has narrowly avoided becoming the latest DeFi hack victim thanks to assistance from a white hat hacker.

A security researcher from venture capital firm Paradigm known on Twitter as “samczsun” has managed to save SushiSwap and its MISO platform from a potential loss of as much as 109,000 ETH.

Our top trading bots

In a blog post published on Aug. 17, the programmer described how he began examining the smart contract code for the BitDAO token sale at SushiSwap’s token launchpad platform, MISO.

On closer inspection, he found a flaw in the MISO Dutch auction contract whereby some of the functions lacked access controls.

“I didn’t really expect this to be a vulnerability though, since I didn’t expect the Sushi team to make such an obvious misstep.”

Upon deeper investigation, the white hat discovered a vulnerability that, if exploited, could result in all of the crypto assets in the token auction contract being drained by a malicious actor. An attacker could reuse the same ETH over and over to batch multiple calls to the contract and “bid in the auction for free.”

Samczsun tested the vulnerability with a successful exploit before contacting colleagues Georgios Konstantopoulos and Dan Robinson to take a look and double-check the findings. He also discovered that a hacker could steal the funds from the contract by triggering a refund by sending a higher amount of ETH than the auction hard cap.

“Suddenly, my little vulnerability just got a lot bigger. I wasn’t dealing with a bug that would let you outbid other participants. I was looking at a 350 million dollar bug.”

Related: Poly Network hack exposes DeFi flaws, but community comes to the rescue

It was then time to reach out to SushiSwap CTO Joseph Delong to formulate a rescue plan before the exploit was discovered in the wild. It was decided that the BitDAO team holding the token sale would manually end the auction by purchasing the remaining allocation and immediately finalizing the process and rescuing the funds.

SushiSwap noted that no funds were lost in the salvage effort, adding that it will pause the use of its MISO Dutch auction format until the smart contract can be updated. Crypto community member “DC Investor” commented:

“Everyone knows Paradigm has big UNI / Uniswap bags, but Sam from their team just helped save SushiSwap (an ostensible competitor) from a critical bug. This is the ethos of the space among the best actors.”

The BitDAO token sale went off without a hitch raising more than 112,000 ETH, valued at roughly $336 million, from over 9,200 participants according to a tweet from the protocol on Aug. 17.

Read on about Cointelegraph
Jamaican central bank to airdrop Jam-Dex CBDC to early adopters
The first 100,000 Jamaican citizens to use the country’s new central bank digital currency (CBDC) known as Jam-Dex, will be given a free $16 payment in...
Global crypto adoption could 'soon hit a hyper-inflection point': Wells Fargo report
Wells Fargo Investment Institute, the research division of Wells Fargo Wealth and Investment Management, has released a report highlighting the potential...
Cardano rockets higher as the metaverse arrives on the blockchain
By David PichodoInvesting.com – With a gain of over 12% in the last 24 hours and over 30% in the last week, Cardano, the fifth largest cryptocurrency buy...
Brave to integrate with Solana blockchain on its privacy-enabled browser
During Solana's Breakpoint conference in Lisbon, Portugal, executives at Brave and Solana Labs announced that the Brave browser would integrate with the...
Polygon pays $2M bounty on bug which could have compromised $850M in user funds
White hat hacker Gerhard Wagner has earned $2 million after reporting a solution to a potentially costly “double-spend” bug on the Polygon network.In an...
Avalanche recovers from Evergrande-led sell-off as AVAX rebounds over 30%
Avalanche (AVAX) prices recovered on Sept. 22, paring a portion of losses that hit cryptocurrencies at the beginning of this week, led by worries about...
SEC threatens to sue Coinbase over crypto yield program it considers a security
The United States Securities and Exchange Commission (SEC) has reportedly threatened to sue Coinbase over a crypto yield program it deems as a security.Coinbase...
Bitcoin sellers in 'disbelief' or BTC price wouldn't still be at $41K — Analyst
Bitcoin (BTC) closed July above $41,000 in a "bullish engulfing" candle that dramatically upends its previous downtrend.In a tweet on Aug. 1, investor and...
$25B investment firm adds 'riskier' Grayscale GBTC and ETHE for clients
Bitcoin (BTC) and Ether (ETH) exposure has come to one of the world's biggest automated investment firms.In a blog post on July 29, Wealthfront, which has...
Proposed New York Bitcoin mining ban watered down to allow green projects
A proposed crypto mining ban calling for a forced three-year hiatus on all mining operations in New York has been watered down — and will now allow green...
Rari Capital falls victim to $11 million exploit
After a $11 million attack earlier today, Rari Capital is the latest decentralized finance (DeFi) protocol to fall victim to a high-priced exploit The platform,...
Three reasons why EOS price has pumped 100% in three days
The EOS price is in double-digits for the first time since mid-2018 after a parabolic advance that began back in March.According to data from Coingecko,...
UNICEF Funds Six DLT Startups to Solve Global Issues
UNICEF is both crypto- and blockchain friendly. A few months ago the French leg of UNICEF said it was accepting donations in nine types of cyber-coins....
Visa Banned Several European Crypto Cards: Why & What to Expect?
On January 5 several crypto-payment service providers, among which are Tenx, Bitwala, and Bitpay, informed that their cards are no longer valid. The cards,...
Cryptocurrency Price Correlations
Cryptocurrency repeatedly moved in tandem during specific periods. A great example is the altcoins, the price of which went up after the SEC’s decision...