BTC PULSE
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise
No Result
View All Result
Play Now
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise
No Result
View All Result
BTC PULSE
No Result
View All Result
Play Now
Home Blockchain

DeFi Platform Hacked, Users to be Compensated

by Darius Ngetich
Dec 26, 2022 - 12:00 am
in Blockchain
DeFi Platform Hacked

According to Rubic Protocol, on December 25, one of its routing contracts was breached, forcing them to suspend contracts until the issue is investigated. When the Rubic cross-chain decentralized finance (DeFi) protocol was hacked, money kept in its users’ addresses was taken out and sent to the hackers.

We're continuing to update you, Rubicans.
Our contract became compromised because the USDC address was whitelisted to interact directly with Rubic. We're investigating the reasons why, but it was required to work with some of our providers.

— Rubic (@CryptoRubic) December 25, 2022

The designers of the protocol also recommended that users utilize the revoke. Cash tool to cancel contract authorization. According to a Twitter thread from blockchain cybersecurity company PeckShield, a flaw in the Rubic protocol allowed money to be taken straight from the wallets that approved its smart contracts for $1.41 million.

Rubic @CryptoRubic is exploited (w/ ~$1.41M) https://t.co/ckAfQr9kgm
1,100 $ETH already into Tornado Cash from the exploiter https://t.co/yPkrC2hFCZ pic.twitter.com/25rLUcMbkf

— PeckShield Inc. (@peckshield) December 25, 2022

The money was sent to the exploiter address via transactions utilizing the stablecoin USD Coin (USDC) on the Uniswap decentralized exchange (DEX). According to PeckShied, the exploit was feasible when USDC was unintentionally added to compatible routers. A malicious contract usage was further made possible by “a lack of validation in ruterCallNative.”

How did this come to be?

This comes after another firm, LastPass, was previously hacked, adding to the many recent hacks being witnessed. The ruterCallNative function has several possible flaws, including invalidated input for the “_params” and “_data” arguments, according to a brief brilliant contract analysis using chatGPT. These may let an attacker send malicious information that might cause improper or undesired behavior.

Furthermore, an attacker may be able to construct a contract and have it executed by the RubicProxy agreement if the “_gateway” option given to the function is unrestricted.

The attacker employed a specially created smart contract in the attack. The 337 lines of code the attacker used to carry out the attack as effectively as possible are visible in the decoded bytecode.

The Uniswap protocol siphoned off just USDC and exchanged it for wrapped ethereum in the first two transfers to the hacker’s address, totaling 1,161.55 and 26.88 ethereum (ETH) (WETH). This WETH was transferred to Tornado Cash, an authorized on-chain mixer, to anonymize the illegally obtained monies.

The hacker’s address was the source of $1.45 million in incoming transactions submitted to the coin anonymization service, out of a total incoming value for the benefit of around $2.9 million. In other words, the exploiter sent around half of the assets to the mixer today.

Tags: DeFiPeckShieldUSDC
Darius Ngetich

Darius Ngetich

Darius Ngetich is a blockchain, crypto, and gaming enthusiast. He is also an animator, VFX Artist, and Game Developer, specializing in computers with vast experience in programs like Blender, Unity, and Unreal Engine. My passions are creating games and informing others about the latest developments in crypto, blockchain, and gaming.

Related Posts

Hong Kong police introduce CryptoTrace blockchain tracking tool at cybersecurity summit

Hong Kong Police Unveil CryptoTrace Tool to Combat Rising Web3 Crime

May 15, 2025

Hong Kong’s police reveal CryptoTrace, a blockchain tool built with HKU to track illicit crypto flows and curb...

Court documents allege NFT founder stole funds from Bitcoin mining venture

NFT Founder Sued for Allegedly Stealing Millions from Bitcoin Mining Venture

May 15, 2025

NFT project founder allegedly stole millions from partners in a Bitcoin mining venture, sparking a fraud lawsuit in...

Nexpace's NXPC token displayed on a digital exchange interface after Binance Alpha listing announcement

Nexon’s Nexpace Token NXPC Secures Binance Alpha Listing Ahead of Web3 Launch

May 14, 2025

NXPC, Nexpace's utility token, lands Binance Alpha listing May 15, gaining support from top exchanges as Nexon expands...

Tether Gold XAUt token listed on Thai crypto exchange Maxbit backed by PTG Energy

Tether Gold Debuts in Thailand with Maxbit Exchange Listing

May 13, 2025

Tether Gold debuts in Thailand on Maxbit, enabling trading of tokenized gold backed by physical reserves under SEC-regulated...

Press Releases

image2

Could XYZVerse Overtake DOGE and SHIB? Analysts Say $0.003333 Could Explode to $10!

March 30, 2025

XYZVerse aims to outpace DOGE and SHIB, with bold $10 price goals, strong community rewards, and rising demand as it...

image1 1

Massive Institutional BTC Buys Could Launch the Next Bull Market: 5 Altcoins to Watch

March 29, 2025

Institutional Bitcoin buys may trigger a market surge. Five altcoins, including $XYZ, stand to gain—early investors could see major ROI...

image1

XRP Faces Strong Resistance While XYZVerse Gains Early Investor Attention With 10 Billion $XYZ Airdrop

March 28, 2025

XRP struggles at resistance, while XYZVerse grabs early investor attention with a 10B token airdrop and rapid growth toward a...

BTC

Popular Memecoin MEW Pledges $10,000 to Pasadena Humane Organization to Aid Animals Affected by California Wildfires

January 20, 2025

MEW memecoin donates $10K to Pasadena Humane for wildfire-affected animals. Join the mission to aid pets and wildlife in crisis...

View All
BTC-Pulse LogoTransparent

© 2024 BTC-PULSE. Disclaimer: The content is for informational purposes only, you should not construe any such information or other material as legal, tax, investment, financial, or other advice.

News

  • Altcoins
  • Bitcoin
  • Ethereum
  • NFT
  • Regulation
  • WEB 3.0

Info

  • Learn
  • Price Prediction
  • Events
  • Press Releases
  • Sitemap

Company

  • About Us
  • Terms of Service
  • Privacy Policy
  • Contact Us
  • Advertise

©2024 BTC-PULSE – All right Reserved.

No Result
View All Result
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise