From COVER to OVER, review of attack incidents
If there is a problem with some DeFi projects, the loss can be recovered through insurance. But what if the insurance company is attacked?
Tonight, the DeFi insurance project Cover Protocol was hacked, resulting in the issuance of more than one trillion tokens. Hackers successively cashed out on SuShiSwap, Uniswap and other DEXs, which directly caused the price of the token COVER to plummet by more than 90% from $800. As of press time, Cover on Uniswap was temporarily quoted at $23.
After the incident, centralized exchanges such as OKEx and Matcha immediately closed the deposit and withdrawal of Cover, and Binance suspended Cover trading.
According to data from OKLink, the attack also led to a short-term sharp drop in the total lock-up volume of Cover Protocol. The current total lock-up volume of Cover is about 31.12 million U.S. dollars, a drop of 31.17%.
On November 28 this year, Cover Protocol merged with Yearn Finance (YFI). As of press time, Banteg, a core developer of Yearn Finance, stated that they are investigating the issue,secondary title
1. Event review: additional issuance of contract loopholes
Tonight at 18:00,Although it has not been confirmed, after the news came out, the price of COVER once dropped by 50%, from $800 to around $370.
In the community, many investors also think that this is just a rumor, and they began to gradually buy bottoms around $400. However, it didn't take long for many users to find that the price of COVER in some decentralized exchanges began to plummet. Among them, Uniswap and SushiSwap were the main ones. The price once fell to the line of 20 US dollars, which was almost zero. Compared with today's opening price Plunged more than 90%.
The block explorer shows that the total amount of Cover Protocol native token COVER has been issued to 40,796,131,214,802,600,000 (4000 Beijing, which is basically equal to unlimited issuance), and an address labeled Grap Finance has issued these tokens, and they continue to be issued in the DEX sell off.
Where did these additional "counterfeit coins" come from?
Based on information from various parties, Odaily summarized the hacking process as follows, which involved two waves of hackers:
The first wave of hackers first constructed counterfeit coins themselves (Contract address2), and then took the bpt of the counterfeit currency to pledge (Contract address 3Contract addressContract address4); Repeatedly, the hacker obtained a total of more than 11,000 real COVER coins, and finally cashed out to make a profit.
The attacker’s address was created two days ago with an initial capital of about 200 ETH. Currently, the address’ assets exceed 1400ETHand $1 million in other tokens. This address has been labeled CoverExploiter1 (Cover exploiter 1) on Etherscan.
The second wave is to use a loophole in the Cover Protocol reward contract called "Unlimited Mining BUG" to issue 40 trillion more Covers; due to the same smart contract, these coins are also mistaken for "real coins" by the trading platform. ”; Hackers used Uniswap and other DEXs to cash out in batches. According to DeFi developer @banteg, the attackers eventually gained more than 4,374 ETH, which is about 3.2 million U.S. dollars.
The identity of the first wave of hackers is currently unknown, but the address of the second wave of additional hackers is marked by the network as the address of the developer of Grap Finance. After making a profit, the attacker returned the proceeds to the Cover team, destroyed the remaining additional COVER, and gaveYield Farming Insurance Address(Predecessor of the Cover Protocol) Message: Next time, mind your own business.
"Sure enough, the founder of grap.finance is a DeFi hero. Just swiped, and 4350 eth has been called to the cover team." Encrypted KOL "Super Bitcoin" commented.
It sounds like no name or profit, and the COVER attacker seems to be a just "white hat". But through smashing the market, many investors lost their money. Is such a "chivalrous spirit" really worth advocating?
At present, YFI founder Andre Cronje has not made any comment on this matter, and Cover Protocol has not given an explanation for the accident. After the attack, Binance and other centralized exchanges immediately suspended the deposit and withdrawal of COVER.
2. DeFi is risk-free and insurable
COVER is not the first DeFi project to be attacked this year.
On the afternoon of December 14th, Beijing time, the account of Hugh Karp, the founder of Nexus Mutual, a leading DeFi insurance project, was hacked and 370,000 NXM (8.33 million U.S. dollars) was stolen. The hacker first sold 102000 NXM on 1inch and 16000 NXM on Matcha. Then Nexus Mutual officially stated that the hacker address sold about 35,000 WNXM through 1inch.
According to the official disclosure details, after gaining remote control of Hugh Karp’s personal computer, the attacker modified the Metamask plug-in used on the computer and misled him to sign the transaction in Figure 1—this transaction eventually transferred a huge amount of tokens to the attack in the account of the recipient.
For DeFi insurance projects, the original intention is to reduce risk losses for other DeFi projects. It was already coveted by hackers, so security protection should be strengthened. Now, because of its own loopholes, it is repeatedly attacked by hackers and suffers losses. Can such an insurance program really help users resist risks?
Since in the world of DeFi, "Code is Law" is advocated, then the code should be done well to the extreme, leaving no opportunity for hackers.
Finally, I hope that the development of DeFi will get better and better, and there will be fewer and fewer vulnerability incidents.



