„Platypus Finance“ įsilaužė į „Avalanche“ už 9 mln

The DeFi application Platypus Finance has suffered a $9 million attack, according to a series of tweets from the blockchain security firm CertiK on Feb. 16.

That report states that an užpuolikas used flash loans on the Avalanche (AVAX) blockchain to exploit a function in one of Platypus’ smart contracts.

The attacker deposited $44 million of stablecoins into the application. With the assets obtained, the attacker could mint a similar amount of Platypus’ USP stablecoin (41.79 million USP). The attacker then exploited an emergency withdrawal function to access the original $44 million deposit and the minted USP. Finally, the attacker swapped the USP for other assets before paying back the loan.

The final difference, and the estimated loss for Platypus, was $9 million. Most of the stolen funds reportedly remain in the attacker’s contract address, though some have been sent to certain pools. Presumably, a portion of that amount can be returned or recovered.

Platypus confirmed the flash loan attack in a message on Telegram and Discord. It wrote that it is assessing the situation and will pause operations.

This line of attack is not unique to Platypus. Several other DeFi platforms have been targeted by flash loans in recent months, including „Mango“ rinkos Spalyje, New Free DAO rugsėjį, „Nirvana“ finansai last July, and Deus DAO praėjusį balandį.

Prijunkite savo piniginę ir prekiaukite naudodami „Orion Swap Widget“.

Tiesiogiai iš šio valdiklio: populiariausi CEX + DEX, sukaupti per „Orion“. Nėra paskyros, visuotinė prieiga.

Source: https://cryptoslate.com/platypus-finance-hacked-for-9m-on-avalanche/