BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

OKEx Insights: Harvest was stolen by hackers for $34 million. Why are there so many DeFi security incidents?

星球君的朋友们
Odaily资深作者
This article is about 2200 words, reading the full article takes about 4 minutes
Why do hackers love DeFi?
AI Summary
Expand
Why do hackers love DeFi?

Another DeFi project was unfortunately targeted by hackers.

On October 26, some users discovered that the DeFi mining project Harvest.finance was suspected of being hacked. Hackers borrowed flash loans and stole nearly $34 million.

Harvest’s official tweet explained that this arbitrage attack originated from a huge flash loan, and manipulated the price of one currency Lego (Curve y Pool) multiple times to exhaust the funds of another currency Lego (fUSDT, fUSDC). The attacker then converted the funds into renBTC and cashed out. Like other flash loan attacks, the attacker did not give a response time and continued to attack for 7 minutes. The attacker returned $2.47 million in USDT and USDC, which will be distributed pro rata to affected depositors.

Affected by the attack, the AICoin market showed that the Harvest token FARM saw pins at noon on the 26th, plummeting by nearly 60%.

Panicked users are eager to withdraw their assets from Harvest. On the other hand, the frequent operations and cash-out behaviors of attackers have caused the single-day trading volume of Uniswap and Curve to hit a new high. According to Debank data, as of October 27, Harvest’s lock-up volume also plummeted by nearly 60%, while the trading volume of Uniswap and Curve went straight to the sky.

image description

secondary title

happy farm is not happy

Harvest.finance, just like Yearn.finance, is a DeFi income aggregator. According to the official website, Harvest can automatically mine the highest output from the latest DeFi protocols, and use the latest mining technology to optimize the obtained output.

fDAI, fUSDC and fWBTC are stablecoins mortgaged in Harvest, and they automatically perform liquidity mining through Harvest's algorithm. If the user deposits USDC into the Harvest library, Harvest will mint a corresponding number of fUSDC, and the user can also use them to redeem USDC at any time.

image description

Source: harvest.finance, OKEx Insights

secondary title

DeFi becomes hacker's "cash machine"

Harvest is certainly not the first DeFi project to be attacked, and probably won't be the last. Searching the news shows that there have been many DeFi hacking incidents in the past two months alone.

On September 29, the DeFi project Eminence.finance, which was developed by YFI founder Andre Cronje, was hacked to steal 15 million DAI through a lightning loan attack due to a protocol loophole, and the hacker returned $8 million afterwards. Andre responded that the hacker used a simple loophole in the protocol itself, through which the hacker issued a lot of project tokens EMN, and then dumped the additional EMN.

The popularity of YFI made Andre sit on the altar of the currency circle, and the EMN incident poured cold water on his followers. In contrast, the results of the hack that bZx encountered were more ideal.

On September 14, the DeFi lending agreement bZx was attacked for the third time this year. Due to code duplication accidents, a total of over 8 million assets were lost. Two days later, bZx released a report stating that all the lost assets have been recovered and stored in the team's wallet, and the lending pool will be restored. In addition, the team paid a bounty of $45,000 to the vulnerability reporter MarcThelan, and is preparing to formulate a plan with PeckShield to re-examine the protocol and perform real-time monitoring on some key blockchain data indicators.

secondary title

Be wary of DeFi security risks

Why do hackers love DeFi? The reason is still the contradiction between a large amount of funds and immature technology.

This year is the year of the rise of DeFi, with new projects emerging one after another, and liquidity mining has attracted a large number of investors to enter the market. But at the same time, the current technology of DeFi projects is difficult to take into account the nature of decentralization and security and stability. There are also some projects that rush to the stage with contract loopholes in order to catch up with the trend. The result is naturally cheap for hackers.

Another reason common to the cryptoasset community is the lack of regulation and, naturally, no legal protection against holding hackers legally accountable.

Whatever the reason, it is the DeFi investors who ultimately bear the losses. It is recommended that you do not put all your eggs in one basket. In addition to DeFi, you can also deploy assets such as CEX and even traditional finance to diversify your investment; secondly, you can purchase some reliable DeFi insurance products.

Finally, before we participate in a DeFi project, we should not only focus on high returns. Although it is difficult to understand the code without a computer background, we can use our fingers to check the white paper and whether the smart contract has passed the audit of an authoritative organization. As OKEx CEO Jay Hao said: "DeFi is more dependent on smart contracts. A large number of transactions on the agreement basically rely on smart contracts for automatic execution. Smart contracts are the most important 'underlying structure' in the DeFi agreement. If there is a problem with the smart contract , then the impact would be devastating."

DeFi
Harvest
安全
Welcome to Join Odaily Official Community