The exploitation of the DeFi Ankr protocol led to a loss of over $5 million, causing Binance to suspend withdrawals.
Ankr , a DeFi protocol that billed itself as the first “node-as-a-service” platform , was exploited maliciously due to a bug in its code that allowed users to mint infinite tokens . As a result, Ankr lost millions of dollars.
The code behind Ankr allowed anyone to mint an unlimited number of tokens without verification, which was discovered by PeckShield, a security research firm. This then allowed the attacker to mine six quadrillionths of the AbnbC.
See also: Accuro: 30,000 customer data compromised due to hack
After minting the quadrillion aBNBc, the attacker exchanged 20 trillion of the aBNBc tokens for BNB. He then transferred them to Tornado Cash before exchanging the BNB tokens for 5 million USDC.

After the hacker nearly emptied the liquidity pools on PancakeSwap and ApeSwap, the ANKR token lost almost all of its value, according to data from CoinGecko. Ankr tweeted that all assets staked under the protocol are currently safe.
Lookonchain , an on-chain analytics firm, reported that a trader was able to cash out the exploit and convert 10 BNB ( $2,885) into 15.5 million BUSD by exploiting the DeFi lending protocol Helio . This was because Helio did not have up-to-date pricing information on aBNBc after the crash.
The attacker was also able to use the pre-crash pricing for aBNBc to borrow $16 million of the then-barely traded stablecoin HAY , which he then exchanged for BUSD. Since then, according to CoinMarketCap, the HAY stablecoin has sunk to a price of 20 cents, but is now slowly recovering with a current price centered around 77 cents.
Binance has halted Ankr token withdrawals after CEO Changpeng Zhao stated that they have been targeted by hackers.

See also: Bugs in Hyundai and other brands' mobile apps allowed vehicle hacking
Ankr instructed decentralized exchanges to halt trading and stated that it would distribute new tokens after assessing the situation .
Zhao said the exchange had frozen about $3 million, which the hackers transferred to Binance.
Zhao wrote on Twitter that, according to initial analysis, the developer's private key had been compromised and the hacker updated the smart contract to a more malicious version .
Source: coindesk.com
