Euler Finance blocks vulnerable module, working on recovering funds

Share This Post

Euler is working with law enforcement agencies and blockchain security firms to contact the exploiter and recover the funds.

Decentralized finance (DeFi) lending protocol Euler Finance became a victim of a flash loan attack on March 13, resulting in the biggest hack of crypto in 2023 so far. The lending protocol lost nearly $197 million in the attack and impacted more than 11 other DeFi protocols as well.

On March 14, Euler came out with an update on the situation and notified its users that they had disabled the vulnerable etoken module to block deposits and the vulnerable donation function.

The firm said that they work with various security groups to perform audits of its protocol, and the vulnerable code was reviewed and approved during an outside audit. The vulnerability was not discovered as part of the audit.

The vulnerability remained on-chain for eight months until it was exploited, despite a $1 million bug bounty in place.

Sherlock, an audit group that has worked with Euler Finance in the past, verified the root cause of the exploit and helped Euler submit a claim. The audit protocol later voted on the claim for $4.5 million, which passed, and later executed a $3.3 million payout on March 14.

In its analysis report, the audit group noted a significant factor for the exploit: a missing health check in “donateToReserves,” a new function added in EIP-14. However, the protocol stressed that the attack was still technically possible even before EIP-14.

Related: More than 280 blockchains at risk of ‘zero-day’ exploits, warns security firm

Sherlock noted that the Euler audit by WatchPug in July 2022 missed the critical vulnerability that eventually led to the exploit in March 2023.

Euler has also reached out to leading on-chain analytic and blockchain security firms, such as TRM Labs, Chainalysis and the broader ETH security community, in a bid to help them with the investigation and recover the funds.

Euler notified that they are also trying to contact those responsible for the attack in order to learn more about the issue and possibly negotiate a bounty to recover the stolen funds.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Trump Courts Crypto Voters: Pledges To Free Silk Road Founder Following 2024 Elections

A recent Bloomberg report revealed that former President Donald Trump has made several new promises to the crypto community should he win the upcoming US presidential election Among these promises is

XRP Macro Charts Signal Explosive Bullish Move Despite SEC Appeal: Analyst

In a technical analysis shared with his followers on X, crypto analyst Bobby A (@Bobby_1111888) provides a bullish prediction for XRP despite the US Securities and Exchange Commission’s

Who Will HBO’s Documentary Reveal As Bitcoin Inventor? Community Reacts

The Bitcoinverse is currently buzzing with anticipation as HBO prepares to air its documentary, “Money Electric: The Bitcoin Mystery,” which claims to unveil the true identity of

Analyst: 13 of the Top 25 ETFs Launched in 2024 Are Bitcoin or Ether-Related

Data shows that bitcoin and ethereum exchange-traded funds (ETFs) have made quite an impact this year in the world of traditional finance According to Nate Geraci, co-founder of the ETF Institute,

VanEck optimistic on Bitcoin’s momentum in Q4 but wary of Ethereum’s struggles

VanEck remains optimistic about Bitcoin’s outlook heading into the fourth quarter, citing strong macroeconomic support and institutional inflows while expressing concerns over Ethereum’s

Analyst Says PEPE Bearish Continuation Is Possible For A 50% Price Crash

The PEPE price could be in trouble from here after failing to maintain its upward momentum This has led to a restart of the bearish momentum, and this could continue if bulls fail to pull up the