42DAO Oracle Exploit Crashes Balance Coin (BLC) 99% After $912K DeFi Hack

Paxful
fiverr


  • Oracle manipulation resulted in the theft of about $912,000 from 42DAO, causing Balance Coin (BLC) to drop by over 99%.
  • Lack of oracle authentication and protection mechanisms allowed the hacker to manipulate BTCB prices and initiate liquidations.

One flaw in the price-setting mechanism of 42DAO led to one of the most recent disruptions in the decentralized finance ecosystem this year. Hackers took advantage of the vulnerabilities in the oracle design of the protocol. This resulted in the theft of about $912,000 and dropping Balance Coin (BLC) by over 99%. Within no time, the exploit wiped out market confidence as BLC fell from almost a dollar to only a fraction of a cent, as reported by PeckShield Alert

The attacker used the protocol’s Spotter poke function to inject an artificially low BTCB price into the accounting contract. Without the presence of price deviation limits, minimum price requirements, and maximum drawdown limitations on the part of 42DAO, the low price became active instantly and had the effect of automating liquidation systems. This is because the wrong price was automatically used to trigger the Dog liquidation module for multiple BTCB-backed vaults.

Design Flaws in Oracle Led to Losses

It is clear from the exploit that the lack of security measures in oracles can easily lead to substantial losses when manipulated prices are used. Unlike attacks on cryptography, the attack involved design flaws in the price oracle and the liquidation process.

As the automated liquidations became prevalent within the protocol, it led to a rapid decline in the value of Balance Coins due to the selling pressure. Post the exploit, the market capitalization of BLC declined to roughly $12,000. This was due to mass withdrawals by the trades on the decentralized exchanges.

okex

Growing Oracle Security Threats in DeFi Sector

This security breach is just one of several large decentralized finance hacks that occurred in recent months. The project called Allbridge stopped its cross-chain services after hackers exploited liquidity pools ratio and stole around $1.65 million. Syscoin was hacked, allowing the minting of billions of fake coins. The Echo Protocol also had to stop its cross-chain transactions after the unauthorized minting of eBTC.

One thing connects all of these incidents. Hackers now try to find vulnerabilities in protocol architecture rather than trying to break the encryption. Security specialists keep on recommending developers to include validation of oracless. Also suggested to limit price deviations, and apply other liquidation controls before deploying their smart contracts to the mainnet. With the spread of the DeFi sector, protection from oracle attacks is now crucial for protocol stability and protection of user funds.

Highlighted Crypto News:
SecondFi Exploit Exposes Wallet Keys, Putting More Than $20M in Cardano Assets at Risk





Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*