SushiSwap approval bug leads to $3.3 million exploit

Share This Post

Only users who have traded on the decentralized exchange in the last four days are apparently affected.

A bug on a smart contract on the decentralized finance (DeFi) protocol SushiSwap led to over $3 million in losses in the early hours of April 9, according to several security reports on Twitter. 

Blockchain security companies Certik Alert and Peckshield posted about an unusual activity related to the approval function in Sushi’s Router Processor 2 contract — a smart contract that aggregates trade liquidity from multiple sources and identifies the most favorable price for swapping coins. Within a few hours, the bug led to losses of $3.3 million.

According to DefiLlama pseudonymous developer 0xngmi, the hack should only affect users who swapped in the protocol in the past four days.

Sushi’s head developer Jared Grey urged users to revoke permissions for all contracts on the protocol. “Sushi’s RouteProcessor2 contract has an approval bug; please revoke approval ASAP. We’re working with security teams to mitigate the issue,” he noted. A list of contracts on GitHub with different blockchains requiring revocation has been created to address the problem.

Hours after the incident, Grey took to Twitter to announce that a “large portion of affected funds” had been recovered through a whitehat security process. “We’ve confirmed recovery of more than 300ETH from CoffeeBabe of Sifu’s stolen funds. We’re in contact with Lido’s team regarding 700 more ETH.”

The Sushi’s community has had an intense weekend. On April 8, Grey and his counsel provided comments on the recent subpoena from the United States Securities and Exchange Commission (SEC).

“The SEC’s investigation is a non-public, fact-finding inquiry trying to determine whether there have been any violations of the federal securities laws. To the best of our knowledge, the SEC has not (as of this writing) made any conclusions that anyone affiliated with Sushi has violated United States federal securities laws,” he stated.

Grey claims to be cooperating with the investigation. A legal defense fund in response to the subpoena was proposed on Sushi’s governance forum on March 21.

Magazine: Crypto audits and bug bounties are broken: Here’s how to fix them

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

MicroStrategy Overtakes Bitcoin With 1,208% Gains: Report

The post MicroStrategy Overtakes Bitcoin With 1,208% Gains: Report appeared first on Coinpedia Fintech News MicroStrategy, the largest corporate Bitcoin (BTC) holder, is gaining significant attention

Solana, XRP Record Inflows From Institutions As Bitcoin, Ethereum Bleed, What’s Going On?

In a surprising move, investment funds based on other altcoins failed to follow in the footsteps of crypto giants, with Solana, XRP, Cardano, and Litecoin witnessing inflows during the week The

Ethereum staking defies market trends with robust growth in 2024

Ethereum staking continues to grow this year despite the emergence of spot exchange-traded funds (ETFs) and the digital asset’s price relative price weakness On Oct 8, blockchain analytics firm

TON Recovery Stalls: Another Price Decline Hinders Bullish Efforts

TON is facing renewed selling pressure as its price takes another dip, putting its recovery efforts in jeopardy Despite previous attempts to regain bullish momentum, the cryptocurrency now struggles

Ethereum L2 Platform Linea Integrates Chainlink’s Cross-Chain Protocol 

The layer two platform Linea has teamed up with Chainlink’s Cross-Chain Interoperability Protocol (CCIP) to offer developers a more secure and seamless environment for creating decentralized

StanChart believes Solana will outperform Bitcoin, Ethereum under Trump administration

Standard Chartered’s latest research reveals that Solana (SOL) could see substantial valuation growth if former President Donald Trump wins the election against Vice President Kamala Harris