CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • CryptoPotato Crypto Fund
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • bitcoin
    BTC$29,395.00
  • ethereum
    ETH$1,847.28
    • Market Updates
    • BTC Analysis
    • ETH Analysis
    • XRP Analysis
    • Interviews
    • Opinions
    CryptoPotato
    CryptoPotato
    • Crypto News
    • Margin Trading
    • Guides
      • Bitcoin & Crypto Guides 101
      • Bitcoin For Beginners
      • Editorials
    • DeFi & NFT
    • Buy
    • Language
    • Crypto News
    • Bitcoin For Beginners
    • Cryptocurrency Guides 101
    • Editorials
    • Bitcoin & Crypto Margin Trading
    • DeFi & NFT News
    • Bitcoin Price Analysis
    • CryptoPotato Crypto Fund
    • Ethereum (ETH) Price Analysis
    • Ripple (XRP) Price Analysis
    • Market Updates
    • Interviews
    • Buy Bitcoin with Card
    Home » Crypto News » DeFi Protocol Sturdy Finance Exploited for 442 ETH Worth Almost $800K

    DeFi Protocol Sturdy Finance Exploited for 442 ETH Worth Almost $800K

    Author: Jordan Lyanchev

    Last Updated Jun 12, 2023 @ 10:21

    The DeFi protocol was exploited via a reentrancy exploit and targeted Sturdy’s pricing oracles.

    Sturdy Finance – a DeFi project promising up to 10x leverage on staked assets – has been exploited by a hit-and-run attack on its pricing oracle.

    Although the amount stolen (worth about $800k at the time this article was written) pales in comparison to other, more high-profile attacks like the one on Atomic Wallet users just last week, it also ensures that laundering the profits will not be nearly as hard as it is for cybercriminals who have made off with much bigger takings.

    Price Manipulation

    The attack on Sturdy Finance was carried out via reentrancy exploit, a common method of attacking DeFi projects that entails repeatedly calling a function in a smart contract before the original call is completed.

    In order to attack Sturdy Finance, the hacker first established the vulnerability of the protocol’s price oracle – the part of Sturdy’s ecosystem that determines the current value of assets to be used in trading and loans – to reentrancy exploits. Once the vulnerability was established, a flashloan from AAVE provided the liquidity necessary for the attack.

    This allows the bad actor to withdraw more funds than the smart contract should allow them to. In this case, the price of staked Ether (stETH) was manipulated three times in a row in order to enable the bad actor to withdraw more than the loan should allow them to, pay off the original loan, and cash out the extra funds. This process was then repeated on five occasions, each time using a different smart contract.

    ADVERTISEMENT

    2/ The attack tx (https://t.co/XdAhTpE6aS) consists of the following attack steps. pic.twitter.com/EvZhYpWPDO

    — BlockSec (@BlockSecTeam) June 12, 2023

    The exploit resulted in a loss of 442 ETH for Sturdy, a takeaway already on its way to Tornado Cash.

    Post-Mortem in Progress

    The security team at Sturdy confirmed that the exploit has been noted, and their operations have been paused for the moment to conduct a proper post-mortem. The team also asserted that no other funds are currently at risk of being stolen.

    “We are aware of the reported exploit of the Sturdy protocol. All markets have been paused; no additional funds are at risk, and no user actions are required at this time. We will be sharing more information as soon as we have it.”

    Sturdy’s community is understandably upset at the news, with some users proclaiming disbelief that attacks typical of the 2017 shitcoin boom era are still happening today.

    SPECIAL OFFER (Sponsored)
    Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

    PrimeXBT Special Offer: Use this link to register & enter CRYPTOPOTATO50 code to receive up to $7,000 on your deposits.

    You Might Also Like:

    • Atomic_Wallet
      Over $35 Million Reportely Stolen From Atomic Wallet Users
    • DeFi_Hacks
      Yearn Finance Exploiter Steals Over $10M in Stablecoins: Report
    • hacker2-min
      Euler Finance Hacker Apologizes, Returns Stolen $177 Million
    Tags: DeFi Hacking
    Enjoy reading? Share with your friends
    Facebook Twitter LinkedIn Telegram

    About The Author

    Jordan Lyanchev
    More posts by this author

    Jordan got into crypto in 2016 by trading and investing. He began writing about blockchain technology in 2017 and now serves as CryptoPotato's Assistant Editor-in-Chief. He has managed numerous crypto-related projects and is passionate about all things blockchain. Contact Jordan: LinkedIn

  • bitcoin
    BTC$29,395.00
  • ethereum
    ETH$1,847.28
  • Join Our Community

    FacebookTwitter YouTubeTelegram


    Editorials
    Wall Street Traders Are Using DeFi: Interview With dYdX Foundation’s VP of Strategy, David Gogel

    Wall Street Traders Are Using DeFi: Interview With dYdX Foundation’s VP of Strategy, David Gogel

    This Will Trigger Crypto’s Mass Adoption Next Years: Animoca Brands’ Yat Siu

    This Will Trigger Crypto’s Mass Adoption Next Years: Animoca Brands’ Yat Siu

    Facebook’s Answer to Twitter: A Complete Guide on Threads

    Facebook’s Answer to Twitter: A Complete Guide on Threads

    What is a Meme Coin? The Biggest Meme Coins You Must Know About

    What is a Meme Coin? The Biggest Meme Coins You Must Know About

    The Weaknesses of Ethereum VS Modern Blockchains: Interview With Radix

    The Weaknesses of Ethereum VS Modern Blockchains: Interview With Radix

    Institutions Intend to Buy Bitcoin in Late 2023: Interview With CryptoQuant

    Institutions Intend to Buy Bitcoin in Late 2023: Interview With CryptoQuant

    Why Didn’t ETH Dump After Shanghai? Interview With Nansen

    Why Didn’t ETH Dump After Shanghai? Interview With Nansen

    Join Our Newsletter
    Become a CryptoPotato VIP
    One Weekly Email Can Change Your Crypto Life.
    Sign-up FREE to receive our extended weekly market update and coin analysis report
    We NEVER send spam. You can unsubscribe at any time.
    Invalid email address
    Thanks for subscribing!
    Footer Logo
    About
    Advertise on CryptoPotato
    About Us | Contact Us | Careers
    Editorial Policy
    Terms of service | Privacy Policy | GDPR
    More Sections
    IEO List | Evaluations
    Airdrops
    Scholarship
    Disclaimer
    Disclaimer: Information found on CryptoPotato is those of writers quoted. It does not represent the opinions of CryptoPotato on whether to buy, sell, or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk. Full disclaimer
    © Copyright CryptoPotato 2016 - 2021
    Scroll to top
    One Weekly Email Can Change Your Crypto Life.

    Sign-up FREE to receive our extended weekly market update and coin analysis report

    We never send SPAM. You can unsubscribe at any moment
    Invalid email address
    Thanks for subscribing!