Hackers copied Mango Markets attacker’s methods to exploit Lodestar: CertiK

Share This Post

The attacker made close to $6.9 million in profits and left users with a pile of bad debt.

According to a post-mortem analysis provided by CertiK of the $5.8 million Lodestar Finance exploit that occurred on Dec. 10, 

In a similar instance, CertiK said that Lodestar Finance hackers “artificially pumped the price of an illiquid collateral asset which they then borrow against, leaving the protocol with irretrievable debt.”

“Despite some of the losses being potentially recoverable, the protocol is functionally insolvent right now, and users are being urged not to repay any loans they have taken out.”

The attack occurred through a vulnerability in the PlutusDAO’s plvGLP token on Lodestar. According to its documentation, Lodestar “uses verified, secure Chainlink price feeds for every asset it offers with the exception of plvGLP.” Instead, the exchange rate of plvGLP to GLP relied on total assets divided by total supply on Lodestar.

As explained by CertiK, the exploiter first funded their wallet with 1,500 Ether (ETH) on Dec. 8, who then took out eight flashloans for a total of approximately $70 million worth of USD Coin (USDC), wrapped Ether (wETH), and DAI (DAI) two days later. This drove the exchange rate of plvGLP to GLP to 1.00:1.83, which meant that the exploiter was able to borrow even more assets from the protocol.

The borrowings quickly consumed all liquidity on the platform, leading the hacker transfer the funds out of Lodestar and leaving users with bad debt. It is estimated that the exploiter made a total of $6.9 million in profits through the attack vector.

“While Lodestar is reaching out to the exploiter in an attempt to negotiate a bug bounty ex post facto, the funds are likely to be mostly unrecoverable. In the absence of an insurance fund that can cover the losses, users of the platform bear the cost of the exploit.”

CertiK warned that the attack “is the result of flaws in the protocol’s design rather than a bug in its smart contract code.” The blockchain security firm further highlighted that Lodestar launched without an audit, and, therefore, without a third-party review of its protocol design.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Mt. Gox Mystery: Defunct Exchange Moves Over $2 Billion In Bitcoin – Details

Mt Gox is back in the news, this time, transferring 32,371 Bitcoin, valued at $219 billion at current prices, to an undisclosed address The transaction from a defunct crypto exchange happened when

Reserves Threatened: China Urged to Dedollarize Its $3.3 Trillion Forex Stash

Economists are calling on China to curb the risks associated with holding over $33 trillion in its forex reserves The concerns are directed at the possible measures the upcoming US president might

2024’s Best Crypto to Buy for Profit: What Experts Are Watching

The post 2024’s Best Crypto to Buy for Profit: What Experts Are Watching appeared first on Coinpedia Fintech News As Bitcoin faces a significant market pullback with over $200 million in long

Analyst Reveals What The Gold Chart Says About The Possibility Of Bitcoin Price Reaching $100,000

Recent action has seen Bitcoin price retest the $67,000 price level Particularly, the Bitcoin price declined by about 89% in seven days from $73,464 on October 29 to $66,895 on November 4, as many

Ethereum Foundation’s Josh Stark highlights ETH’s ‘hardness’ as it hits 3-year low against Bitcoin

Ethereum Foundation contributor Josh Stark highlighted Ethereum’s (ETH) “hardness” as its defining quality in the digital economy, emphasizing its ability to provide unmatched

MARA Reports 2% Increase in Bitcoin Mining for October 2024; Transaction Fees Account for 5% of Total Production

MARA (NASDAQ: MARA) has released its unaudited Bitcoin production update for October 2024, reporting a total production of 717 Bitcoin, which represents a 2% increase compared to the previous month