The Blockchain startup company MonoX Finance said on Wednesday that a hacker stole $31 million by exploiting a bug in the software the service uses for drafting smart contracts.

See also: Ukraine arrests hackers from the "Phoenix" group
The company uses a decentralized finance protocol known as MonoX that allows users to exchange digital currency tokens without some of the requirements of traditional exchanges.
An accounting bug built into the company’s software allowed an attacker to inflate the price of the MONO token and then use it to cash out all other deposited tokens, MonoX Finance revealed in a post. The pump amounted to $31 million worth of tokens on the Ethereum or Polygon blockchains – both of which are backed by the MonoX protocol.
Specifically, the hack used the same token for tokenIn and tokenOut, which are methods for exchanging the value of one token for another. MonoX updates the prices after each swap by calculating new values for both tokens. When the swap is completed, the price of tokenIn —that is, the token sent by the user— decreases and the price of tokenOut—the token received by the user— increases.
See also: Hackers exploited flaw in popular e-commerce software

Using the same token for both tokenIn and tokenOut, the hacker inflated the price of the MONO token because the tokenOut update replaced the tokenIn price update. Then the hacker swapped the token for tokens worth 31 million dollars on the Ethereum and Polygon blockchains.
See also: Hackers deploy Linux malware on e-commerce servers
There is actually no reason to exchange a token for the same token, and therefore the software that conducts the transactions should not have allowed such transactions. Unfortunately, it happened, despite the fact that MonoX performed three security checks this year.
Source of information: arstechnica.com
