Lodestar Finance exploited in flash loan attack

Share This Post

The main vulnerability behind the attack was within GLP oracle and how it conducts its price.

Arbitrum-based lending protocol Lodestar Finance was exploited in a flash loan attack on Dec. 10. According to Lodestar, the attacker manipulated the price of the plvGLP token before borrowing all platform liquidity using the inflated token.

In a Twitter thread, Lodestar explained the attack flow. The attacker first manipulated the exchange rate of the plvGLP contract to 1.83 GLP per plvGLP, “an exploit that by itself would be unprofitable”, said the company.

Then, the attacker supplied plvGLP collateral to Lodestar and borrowed all available liquidity, cashing out part of the funds “until the collateralization ratio mechanism prevented a full liquidation of the plvGLP.”

Following the hack, “several plvGLP holders also took advantage of the opportunity and also cashed out at 1.83 glp per plvGLP.” The hacker was able to burn a little over 3 million in GLP, making profit on the “stolen funds on Lodestar – minus the GLP they burned.”, noted the DeFi platform.

The attacker made around $5.8 million in profit. Lodestar states that nearly 2.8 million of the GLP (about $2.4 million) was recoverable, which should be used to repay depositors. The company is trying to negotiate a bug bounty with its exploiter:

The main vulnerability that led to the attack is inside GLPOracle and how it conducts its price. In an analysis, Solidity Finance audit team said the event highlighted “that utilizing oracles resistant to manipulation is a critically important piece of DeFi, especially in protocols which lend out user assets.”

In a statement, governance aggregator PlutusDAO noted that its “products and platform functioned exactly as intended through the entire event. All funds on Plutus are completely safe. The exploit was solely a result of Lodestar’s oracle implementation.” It also stated:

“We want to take responsibility for promoting an unaudited protocol. While the exploit is in no way Plutus’ fault, we recognize the fact that we were too eager to promote a protocol integrating plvGLP. With plvGLP gaining significant traction, we’ve wanted to highlight all plvGLP integrations to our community to emphasize the adoption and opportunities the integrations have presented both to individual users and protocols. For this, we apologize. We jumped the gun, and going forward we will no longer be promoting protocols that are not audited.”

The Lodestar attack was similar to the Mango Markets exploit on Oct. 11, when over $100 million was stolen through an attacker manipulating price oracle data, allowing the hackers to take out under-collateralized cryptocurrency loans.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Diamond Hand Ethereum Whale Moves 15,000 ETH, Here’s The Destination

A “Diamond Hand” Ethereum (ETH) whale has suddenly emerged, transferring a massive 15,000 ETH token to a major exchange Given the sheer size of the transaction, this whale has caught the

‘Worst Airdrop in History’: Hamster Kombat to Reach 131M Users Amid Token Allocation Criticism

Hamster Kombat, the sensation game on Telegram, is on the verge of embarking on one of the largest token distributions in history The Hamster Kombat team disclosed that the airdrop will reach 131

AI tokens lead weekly gains after Fed’s interest rate cut

Artificial intelligence (AI) tokens are leading the weekly gains in crypto, registering an average return of 37% over the past seven days, according to Artemis’ data The performance shown by AI

Bitcoin Hash Rate Dominance Shifts To US Mining Pools, China Still Leads

As Ki Young Ju notes, Bitcoin mining activity is shifting to the United States, though Chinese miners still dominate In a post on X, Ju, the founder of CryptoQuant, a crypto analytics platform,

Polkadot Stalls Below $4.5 Even After Agile Coretime Launch: What’s Going On?

Polkadot (DOT) needs help at spot rates When writing, DOT is still trading below $45 despite the broader recovery Bitcoin and Ethereum, for example, are trading above local resistances now support,

Exploring Web3 Farming With Pixels

Join Regina as she plays Pixel If you’re a fan of digital farming games like Farmville, Pixels might be your next obsession Set in a vibrant pixelated world and powered by the Ronin blockchain,