CertiK: Yearn.Finance exposed a vulnerability, with a total loss of about 71 million RMB

CertiK: Yearn.Finance exposed a vulnerability, with a total loss of about 71 million RMB
Original title: "CertiK: Yearn.Finance revealed a vulnerability, DeFi suffered another blow, this article will take you to find out the whole incident"
Original source: CertiK

On February 5, according to DeBank data, the actual locked amount of DeFi exceeded 47 billion US dollars, setting a historical high. At the time of writing this article, it was 47.83 billion US dollars, which is approximately equivalent to 309.5 billion yuan.

2020 is known as the "first year of DeFi". Driven by the "liquidity mining" pioneered by Compound, DeFi has achieved a historic explosion, but its security risks remain high. In the early morning of February 5th, Beijing time, the CertiK security technology team discovered that the DeFi project Yearn.Finance was attacked. The total loss of the attack was as high as about 71 million yuan, and the hacker made a profit of about 18 million yuan. The hacker obtained the attack start-up funds through flash loans and took advantage of the Yearn project code loopholes to complete the entire attack.

Screenshot of the attacker's profit

The attack included 11 transactions that took advantage of the vulnerability to make a profit and 3 transactions to convert tokens. The transaction list is as follows:

Except for 3 token conversion transactions, the remaining 11 profitable transactions all targeted the same vulnerability and used the same attack method to complete the profit. The general attack flow chart is as follows:

The specific steps are as follows:

-Use flash loans to raise the initial funds needed for the attack.

- Exploiting a loophole in the Yearn.Finance contract, DAI and USDT were repeatedly deposited and withdrawn from 3crv in order to obtain more 3Crv tokens. These tokens were converted to USDT and DAI stablecoins in the subsequent 3 conversion token transactions. After completing 5 repeated DAI and USDT deposit and withdrawal operations from 3crv, the flash loan was repaid.

-The CertiK security technical team is currently reviewing the vulnerabilities in Yearn.Finance. More details of the vulnerabilities will be explained in subsequent analysis.

Summarize

Interactions in the crypto world are often accompanied by certain risks, and investing in secure projects will bring longer-term returns.

High returns are always accompanied by high risks, and the outbreak of this vulnerability is also a warning to the DeFi field.

<<:  Virtual currency scam using the name of Cambodian prince: under the banner of "digital bank", it is actually a pyramid scheme, and the police filed a case for fraud

>>:  Binance Charity now accepts DOGE coins as donations

Recommend

The research results of IPFS mobile design are out!

We have previously introduced IPFS's research...

Hair can tell the development of fortune. Does hair affect fortune?

Hair also has a great influence on a person's...

What does it look like to marry a good wife? Which men can marry a good wife?

As men all hope that their wives can make them pr...

Analysis of a woman's personality and destiny based on her broad cheeks

Facial features can also reflect a person's ch...

Three moles form a triangle

It is said that there are no good moles on the fa...

6 Bitcoin price predictions worth watching: $500,000 cap in sight?

It has become a fairly common prediction that the...

What are the facial features of women with a "husband-killing face"?

The so-called segmented nose refers to the phenom...

Is it okay for a boy to have a mole on his left ring finger?

Everyone knows about moles because everyone has t...

The face that can always win the other person's heart in love

The face that can always win the other person'...

Palmistry reveals your unknown side

Palmistry reveals your unknown side All things in...