HomeSecurityDeFi platform Beanstalk victim of attack - lost $182 million

DeFi platform Beanstalk victim of attack – lost $182 million

DeFi platform Beanstalk revealed on Sunday that it suffered a security breach that resulted in financial losses of $182 million, while the attacker stole $80 million in crypto assets.

Beanstalk

As a result of this attack, trust in the Beanstalk market has been compromised, and the value of the decentralized stablecoin BEAN has collapsed from just over $1 on Sunday to $0.11 currently.

The decentralized finance (DeFi) platform reported on its Discord channel that the attacker took a “flash loan” on Aeve, a liquidity protocol, and used their voting power from holding a large amount of its native governance token Stalk to pass a malicious proposal.

Normally, funds used for voting in the governance section of the system remain locked for some time after a proposal is voted on. The Beanstalk protocol used the Diamond EIP-2535 standard which meant that the various assets stored in the protocol would exist in a single address.

The Beanstalk Protocol supported protocol upgrades through the Beanstalk-Improvement-Proposal (BIP) governance mechanism and as such, it was possible for an upgrade to perform arbitrary code execution, thus allowing the attacker to recover their locked funds as part of the malicious update.

An analysis of the attack by smart contract auditors and developers at Omniscia explains that the hacker managed to steal the assets through a malicious proposal:

Beanstalk Protocol faced a flash-loan attack due to a flaw in the recently introduced Curve LP Silos, which compromised the protocol's governance mechanism, ultimately allowing the attacker to perform an emergency execution of a malicious proposal that siphons off the project's funds.

Essentially, the attacker allowed himself to drain all of the protocol's funds into a private Ethereum in one instance, having the power to vote for the action.

A flash loan allows users to borrow large amounts of stablecoins from other merchants without providing collateral , and the process of approving a loan and repaying it is done in a single transaction on the blockchain, within seconds.

Some hackers have identified vulnerabilities in various DeFi platforms that are exploitable within these short time frames, performing malicious actions immediately after a flash loan is approved.

DeFi platforms are defending against this threat using decentralized price oracles and other protection systems, but not all have built a strong defense.

The Beanstalk attack exploited the lack of a robust measure to stop governance manipulation via Stalk flash loans, which was the point of failure that made the attack successful.

DeFi platform Beanstalk victim of attack - lost $182 million

What's happening now?

Beanstalk has not announced what it will do from now on, so compensating investors remains an uncertain action.

The platform is still investigating the incident and has openly called on the DeFi community and blockchain analysis experts to help salvage what they can. At the same time, it has also called on the exploiter to negotiate.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS