SushiSwap token allocation exploit drains $3.3M as users urged to revoke token allowances

Share This Post

A critical vulnerability has been identified in the DeFi protocol SushiSwap by security firm PeckShield this weekend, with the exploit involving the ‘RouterProcessor2’ contract used for trade routing on the SushiSwap exchange.

“It seems the SushiSwap RouterProcessor2 contact has an approve-related bug, which leads to the loss of >$3.3M loss (about 1800 eth) from 0xSifu,” PeckShield posted on Twitter. SushiSwap head developer Jared Grey confirmed the issue, urging users to revoke permissions for all contracts on SushiSwap as a security measure. The bug has resulted in a loss of over $3.3 million, primarily affecting a single user, 0xsifu, known in the Crypto Twitter community.

Grey stated,

“Sushi’s RouteProcessor2 contract has an approval bug; please revoke approval ASAP. We’re working with security teams to mitigate the issue.”

The exploit appears to have impacted users who approved SushiSwap contracts within the last four days, according to DefiLlama developer 0xngmi. Meanwhile, security teams continue to investigate the issue, track stolen funds, and work to recover affected assets.

Recovery of funds

“Recovery efforts are underway,” said Jared Grey, citing a tweet from MetaSleuth that provided a breakdown of the stolen funds. The first attacker, 0x9deff, returned 90 ETH of the 100 they had stolen, while BlockSec rescued 100 ETH and pledged to return it shortly. Negotiations between sifuvision.eth and c0ffeebabe.eth are in progress, with most stolen funds traced to “beaverbuild, rsync-builder, and Lido: Execution Layer Rewards Vault.”

sushiswap exploit
Source: MetaSleuth

BlockSecTeam acknowledged their involvement in the recovery efforts, tweeting,

“We knew that @SushiSwap RouteProcessor2 was attacked. We evaluated possible damages in the past few hours and made this public only after we think it’s safe: users’ assets are always our first priority. Btw: we rescued part of them and will release the details later.”

As developers and security teams continue to address the vulnerability and recover lost funds, users are strongly advised to revoke permissions for all SushiSwap contracts to protect their assets.

The incident underscores the importance of ongoing vigilance and security measures within the DeFi ecosystem, as the growing sector remains vulnerable to exploits and attacks targeted to the misconfiguration of accounts.

As of press time, the Sushi token is down 4.9% on the day, trading around $1.08.

The post SushiSwap token allocation exploit drains $3.3M as users urged to revoke token allowances appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Ethereum Proposal EIP-7781 Promises Network Performance Boost – Here’s What To Expect

Ethereum Improvement Proposal (EIP) 7781 aims to reduce Ethereum network slot times, expand blob capacity, enhance decentralized exchange (DEX) performance, and lower gas fees  What Is Ethereum

Solana (SOL) Flashes Breakdown Signs: Will Support Hold?

Solana trimmed gains and declined below the $146 support SOL price is consolidating and might aim for a fresh increase unless there is a break below $140 SOL price started a fresh decline below the

Latam Insights Encore: Bukele Might Orange-Pill Milei on Bitcoin

Welcome to Latam Insights Encore, a deep dive into Latin America’s most relevant economic and cryptocurrency news from last week In this edition, we examine President Nayib Bukele’s official

XRP Price Struggle Continues: Can Bulls Turn It Around?

XRP price is struggling to rise above the $0550 level The price must clear the $05450 and $05500 resistance levels to start a decent increase XRP price is still consolidating above the $05080 support

“Asia’s MicroStrategy” Metaplanet Increases Bitcoin Holdings With $6.7M BTC Purchase

Japanese investment firm Metaplanet has added another 10878 Bitcoin (BTC) to its existing holdings, bringing its total reserves to over 639 BTC Metaplanet Unfazed By Bitcoin Price Movement In an

U.S. Government Set to Auction $4.4 Billion in Bitcoin After Major Legal Win!

The post US Government Set to Auction $44 Billion in Bitcoin After Major Legal Win! appeared first on Coinpedia Fintech News The US Supreme Court has put an end to the legal battle over 69,370