Decentralized Web3 infrastructure provider Ankr has become the latest victim of a hacking attack targeting the defi space. The perpetrators who hit the platform were able to mint and steal a massive amount of tokens in a multimillion-dollar exploit.
Defi Protocol Ankr Hit by Unlimited Mint Bug Exploit Worth Millions
Ankr, a decentralized finance (defi) protocol based on Binance’s BNB Chain, has been exploited by a hacker who apparently used an unlimited minting bug. On-chain analysts broke the news on social media and the attack, which occurred on Dec. 1, was confirmed by Ankr.
On Friday, the Web3 infrastructure provider admitted on Twitter that its aBNB token had been exploited and announced it’s working with exchanges to suspend trading. In a follow-up tweet, it also insisted that all underlying assets on Ankr Staking are safe and infrastructure services unaffected.
Mūsų aBNB žetonas buvo išnaudotas ir šiuo metu dirbame su biržomis, kad nedelsiant sustabdytume prekybą.
- Ankr (@ankr) Gruodis 2, 2022
Initial reports by blockchain security company Peckshield revealed the unknown attacker had been able to mint and dispose of approximately 10 trillion aBNB. It also found that some of the stolen funds had been transferred to the Tornado Cash mixer. A portion was bridged through Celer and Debridgegate to ethereum.
On-chain analysis firm Lookonchain said the exploiter minted 20 trillion tokens and dumped them on Pancakeswap, obtaining at least $5 million in the stablecoin USDC. The price of the Ankr reward-bearing staked BNB (aBNBc) has since collapsed from over $300 to a little over $1.50, at the time of writing.
Peckshield explained that a smart contract for the aBNBc token had an unlimited mint bug which the hacker took advantage of. Another report suggested the attacker had managed to gain access to the Ankr deployer key.
Binance Freezes $3 Million Worth Of Moved Funds
BNB grandinė patvirtino it was aware of the attack and has blacklisted the exploiter. Binance founder and CEO Changpeng Zhao tweeted that a developer private key was hacked and the hacker used it to update the smart contract. The exchange has frozen about $3 million of funds moved to its platform.
Galimi Ankr ir Hay įsilaužimai. Pradinė analizė rodo, kad kūrėjo privatus raktas buvo nulaužtas, o įsilaužėlis atnaujino išmaniąją sutartį į labiau kenksmingą. „Binance“ pristabdė išėmimus prieš kelias valandas. Taip pat įšaldė apie 3 mln. USD, kuriuos įsilaužėliai perkelia į mūsų CEX.
- CZ 🔶 Binance (@cz_binance) Gruodis 2, 2022
Tuo tarpu, BNB Chain-based destablecoin hay, that CZ referred to in his tweet, has lost its $1 peg, also as a result of an apparent exploit which was patvirtino by the team of Helio Protocol. The token is currently trading at a little over $0.65.
The attacks come in a year of numerous security eksploatuoja targeting defi and crypto platforms. According to blockchain forensics firm Chainalysis, the resulting losses in 2022 amount to $3 billion. In early October, BNB Chain was temporarily pristabdytas following a hack that cost close to $600 million.
What are your thoughts on the latest exploit in the defi space? Share them in the comments section below.
Vaizdo kreditai: „Shutterstock“, „Pixabay“, „Wiki Commons“
Atsakomybės neigimas: Šis straipsnis skirtas tik informaciniams tikslams. Tai nėra tiesioginis pasiūlymas pirkti ar parduoti ar jo prašymas arba bet kokių produktų, paslaugų ar bendrovių rekomendacija ar patvirtinimas. Bitcoin.com neteikia patarimų investavimo, mokesčių, teisinių ir apskaitos klausimais. Nei įmonė, nei autorius nėra tiesiogiai ar netiesiogiai atsakingi už bet kokią žalą ar nuostolius, kuriuos sukėlė ar tariamai sukėlė bet koks šiame straipsnyje minimo turinio, prekių ar paslaugų naudojimas ar priklausymas nuo jų.
Source: https://news.bitcoin.com/bnb-chain-based-defi-protocol-ankr-suffers-major-exploit/