Hacker Drains Over $450,000 from Balancer Pools

Monday, 29/06/2020 | 08:44 GMT by Arnab Shome
  • The protocol developers were unaware of the possibility of such type of attacks.
Hacker Drains Over $450,000 from Balancer Pools
FM

Hackers siphoned more than $450,000 in deflationary tokens on Monday from two multi-token pools on Balancer, an automated market maker protocol.

Two separate transactions were made within 45 minutes to exploit the STA and STONK pools with transfer fees.

First, the attacker received $23 million in flash loan from dYdX and then converted them to WETH, then started to repeatedly convert WETH to STA and vice versa for 24 times. With 1 percent transaction on each trade, almost all the STA balance in the pool was drained with only 0.000000000000000001 STA remaining.

According to the Blockchain data, the attacker drained a total of around $452,000 in digital currencies - 601.3 ETH worth around $134,800; 11.36 WBTC valued at $103,500; 22,593 LINK worth $102,800; and 60,915 SNX worth around $110,900.

In an official statement, Balancer said that the protocol developers were not aware of the possibility of any such attacks.

“This is explicitly why STA was not included in the BAL mining whitelist that was recently put together,” the official Medium post read. “The system is designed for compliant ERC20’s and when tokens behave unintended ways, bad things can happen. Balancer is a permission-less protocol and broken or malicious tokens will always be able to be added at the contract level.”

A sophisticated Smart Contract engineer

DEX Aggregator 1inch in a post stated that the hacker “very sophisticated smart contract engineer with extensive knowledge and understanding of the leading DeFi protocols.”

The DeFi ecosystems saw exponential growth recently, with a total locked-in value of around $1.63 billion in various platforms, according to DeFi Pulse. But attacks on such platforms also increased. bZx and dForce, two leading DeFi platforms were attacked earlier this year, showing the vulnerability of these platforms.

These platforms are also vulnerably to sharp market movement as one almost collapsed the Maker protocol.

Hackers siphoned more than $450,000 in deflationary tokens on Monday from two multi-token pools on Balancer, an automated market maker protocol.

Two separate transactions were made within 45 minutes to exploit the STA and STONK pools with transfer fees.

First, the attacker received $23 million in flash loan from dYdX and then converted them to WETH, then started to repeatedly convert WETH to STA and vice versa for 24 times. With 1 percent transaction on each trade, almost all the STA balance in the pool was drained with only 0.000000000000000001 STA remaining.

According to the Blockchain data, the attacker drained a total of around $452,000 in digital currencies - 601.3 ETH worth around $134,800; 11.36 WBTC valued at $103,500; 22,593 LINK worth $102,800; and 60,915 SNX worth around $110,900.

In an official statement, Balancer said that the protocol developers were not aware of the possibility of any such attacks.

“This is explicitly why STA was not included in the BAL mining whitelist that was recently put together,” the official Medium post read. “The system is designed for compliant ERC20’s and when tokens behave unintended ways, bad things can happen. Balancer is a permission-less protocol and broken or malicious tokens will always be able to be added at the contract level.”

A sophisticated Smart Contract engineer

DEX Aggregator 1inch in a post stated that the hacker “very sophisticated smart contract engineer with extensive knowledge and understanding of the leading DeFi protocols.”

The DeFi ecosystems saw exponential growth recently, with a total locked-in value of around $1.63 billion in various platforms, according to DeFi Pulse. But attacks on such platforms also increased. bZx and dForce, two leading DeFi platforms were attacked earlier this year, showing the vulnerability of these platforms.

These platforms are also vulnerably to sharp market movement as one almost collapsed the Maker protocol.

About the Author: Arnab Shome
Arnab Shome
  • 6654 Articles
  • 102 Followers
About the Author: Arnab Shome
Arnab is an electronics engineer-turned-financial editor. He entered the industry covering the cryptocurrency market for Finance Magnates and later expanded his reach to forex as well. He is passionate about the changing regulatory landscape on financial markets and keenly follows the disruptions in the industry with new-age technologies.
  • 6654 Articles
  • 102 Followers

More from the Author

CryptoCurrency

!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|} !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}