• Advertise
  • Submit a Press Release
NewsBTC
Bitcoin & cryptocurrency news today, price & technical analysis
Price & Market
Cap Data from
Nomics Logo
  • News
    • Bitcoin
    • Ethereum
    • Ripple
    • Cardano
    • Tezos
    • EOS
    • Chainlink
    • Sponsored
    • Press Releases
  • Analysis
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Cardano (ADA)
    • Chainlink (LINK)
    • Litecoin (LTC)
    • Tezos (XTZ)
    • Zcash (ZEC)
    • EOS
    • YearnFinance (YFI)
  • Education
    • Accepting Bitcoin payments
    • Using Bitcoin
    • What is Bitcoin Mining
    • How to Trade Bitcoin
    • How to Buy Bitcoin
    • Digital Currency Exchange
    • Proof of Existence
    • Is Bitcoin legal?
    • Bitcoin Books
  • Trading Course
  • Directory
    • Crypto Businesses
    • Bitcoin Brokers
    • Casinos
    • Sportsbooks
  • TradeeToro
  • Buy SilverTry
No Result
View All Result
  • News
    • Bitcoin
    • Ethereum
    • Ripple
    • Cardano
    • Tezos
    • EOS
    • Chainlink
    • Sponsored
    • Press Releases
  • Analysis
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Cardano (ADA)
    • Chainlink (LINK)
    • Litecoin (LTC)
    • Tezos (XTZ)
    • Zcash (ZEC)
    • EOS
    • YearnFinance (YFI)
  • Education
    • Accepting Bitcoin payments
    • Using Bitcoin
    • What is Bitcoin Mining
    • How to Trade Bitcoin
    • How to Buy Bitcoin
    • Digital Currency Exchange
    • Proof of Existence
    • Is Bitcoin legal?
    • Bitcoin Books
  • Trading Course
  • Directory
    • Crypto Businesses
    • Bitcoin Brokers
    • Casinos
    • Sportsbooks
  • TradeeToro
  • Buy SilverTry
No Result
View All Result
NewsBTC
No Result
View All Result
Price & Market
Cap Data from
Nomics Logo
Home Cryptocurrency news Company News

Security Flaw in Balancer Pools Leads to Massive $450K Crypto Hack

Two pools on Balancer, an automated market maker protocol, lost more than $450,000 to a hacking incident that mainly attacked deflationary tokens.

Yashu Gola by Yashu Gola
8 months ago
in Company News
Reading Time: 2min read
balancer, crypto, ethereum, defi, STA, STONK

Security Flaw in Balancer Pools Leads to Massive $450K Crypto Hack

Advertisement
  • Automated market maker protocol Balancer lost over $450,000 in a hacking incident on Sunday.
  • The firm’s co-founder and CTO, Mike McDonald, confirmed that hackers drained at least two of their pools that contained deflationary tokens STA and STONK.
  • He admitted that hackers exploited security vulnerabilities in those tokens to trick their pools into selling them Ether, WBTC, LINK, and SNX at cheaper rates.

Two pools on Balancer, an automated market maker protocol, lost more than $450,000 to a hacking incident that mainly attacked deflationary tokens.

Mike McDonald, the co-founder & CTO of Balancer, confirmed in a Medium post on Sunday that hackers launched the attack in two installments. The first one took place at 0603 UTC, while the other happened about 30 minutes later at 0649 UTC.

Both the attacks exploited STA and STONK, deflationary tokens with 1 percent transfer fees.

5 BTC + 300 Free Spins for new players & 15 BTC + 35.000 Free Spins every month, only at mBitcasino. Play Now!

Anatomy of the Attack

As Mr. McDonald noted, the attackers designed a special smart contract that could perform multiple actions in a single transaction.

At first step, they secured a loan of 104,000 WETH from the dYdX crypto lending platform. Then they swapped the amount for STA tokens back and forth 24 times. Each transaction drained 1 percent of the STA fund from the Balancer’s pool.

So on every transaction, Balancer received less and less STA tokens as fees.

The pool did not detect the drainage due to its own limitations. DEX aggregator 1inch wrote in its Medium post that Balancer does not record the number of STA burnt after a transaction. It only keeps a tab on the token transfer.

Eventually, the STA balance on the pool declined to 1 weiSTA, an equivalent of 0.000000000000000001 STA. That led Balancer to rebalance its pool by automatically transferring the value of other tokens, including Ether, WBTC, LINK, and SNX, to STA.

How to make money exploiting DeFi protocols: do it all in one transaction ?

The attacker involved in today's exploit also used @TornadoCash to fund their initial wallet which shows that DeFi attackers are getting more sophisticated and creative. pic.twitter.com/tOX7e214tN

— Anthony Sassano | sassal.eth ?‍? (@sassal0x) June 29, 2020

The re-balancing made other tokens cheaper to purchase. Hackers exploited the event to swap their STA tokens for others, eventually draining 601.3 ETH (~$135K), 11.36 WBTC (~$103.5K), 22,593 LINK (~$103K), and 60,915 SNX (~$111k) from the pool. That amounted to nearly $452,000.

Mr. McDonald admitted that they were not aware of the nature of the attack, but clarified that they had earlier warned the community about vulnerabilities in deflationary tokens. At the same time, he confirmed concrete developments to mitigate the said risks.

“We will begin adding transfer fee tokens to the UI blacklist similarly to what we have done for no bool transfer tokens,” wrote Mr. McDonald. “Note that these lists will be non-exhaustive and any new tokens can be added to Balancer at any point.”

Not The First Crypto Exploit

The Balancer hack marked a fifth-of-its-kind attack on open-source protocols. The biggest heist among them took place in April 2020 after hackers drained $25 million out of the dForce protocol. Nevertheless, the attackers returned the funds for unknown reasons.

On the other hand, lending protocol bZx lost over $1 million in two consecutive hacking attempts in February 2020.

Tags: balancercryptoDeFiethereumSTASTONK
TweetShare11
Nexo Logo
BitStarz Player Lands $2,459,124 Record Win! Could you be next big winner? Win up to $1,000,000 in One Spin at CryptoSlots
Yashu Gola

Yashu Gola

Yashu Gola is a Mumbai-based finance journalist. He is profoundly active in the bitcoin space since 2014 – and has contributed to several cryptocurrency media outlets, including NewsBTC, FxDailyReport, Bitcoinist, and CCN. Academically, Yashu holds a bachelor's in information technology, with majors in data structures and C++ programming language. He has also won the 'Atulya Award' for his efforts towards raising $100,000 for an India-based farming project.

Related Posts

okex chiliz

OKEx Lists Chiliz, Enables CHZ/USDT and CHZ/BTC Spot Trading

18 hours ago
Bridge Oracle

Bridge Oracle Soon to Launch Mainnet

1 day ago
Blockchain is Finally Becoming What Was Promised

Blockchain is Finally Becoming What Was Promised

2 days ago
sovi finance

SOVI on HECO Liquidity Mining Updates

3 days ago
alfacash

Alfacash- the One-Stop Solution for All Crypto Needs

3 days ago
PIVX

PIVX, a Project that Perfects the Balance Between Privacy and Practicality

3 days ago

Premium Partners

Top Brokers

eToro

eToro

Review · Visit
Evolve Markets

Evolve Markets

Review · Visit
ArbiSmart

ArbiSmart

Review · Visit
PrimeXBT

PrimeXBT

Review · Visit
Moneta Markets

Moneta Markets

Review · Visit

Top Casinos

BitStarz

BitStarz

Review · Visit
mBit

mBit

Review · Visit
CryptoGames

CryptoGames

Review · Visit
Bonusfinder DE

Bonusfinder DE

Review · Visit
Bspin

Bspin

Review · Visit
Wolf Bet

Wolf Bet

Review · Visit

Top Sportsbooks

1xBit

1xBit

Review · Visit

Press Releases

Bittrex Global Exchange to List Ndau for Long-term Holders

March 4, 2021

Polkadex, DEX Built for Web3, Raises $3m From CMS Holdings, Outlier Ventures, OKEx Capital and More

March 4, 2021

Casino Betting Coin launches $FUN Uniswap pool

March 4, 2021

Newsletter Signup


ABOUT US

NewsBTC is a cryptocurrency news service that covers bitcoin news today, technical analysis & forecasts for bitcoin price and other altcoins. Here at NewsBTC, we are dedicated to enlightening everyone about bitcoin and other cryptocurrencies.

We cover BTC news related to bitcoin exchanges, bitcoin mining and price forecasts for various cryptocurrencies.

COMPANY

  • Advertising
  • Comments Policy
  • Privacy Center
  • Sitemap
  • About Us
  • Contact

Technical Analysis

  • Bitcoin (BTC)
  • Ethereum (ETH)
  • Ripple (XRP)
  • Chainlink (LINK)
  • Cardano (ADA)
  • Tezos (XTZ)

LINKS

Auto Trading Software ▸

Cryptocurrency news

  • Bitcoin
  • Ethereum
  • Ripple
  • Chainlink
  • Cardano
  • EOS
  • Tezos

© 2020 NewsBTC. All Rights Reserved.

  • News
    • Bitcoin
    • Ethereum
    • Ripple
    • Cardano
    • Tezos
    • EOS
    • Chainlink
    • Sponsored
    • Press Releases
  • Analysis
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Cardano (ADA)
    • Chainlink (LINK)
    • Litecoin (LTC)
    • Tezos (XTZ)
    • Zcash (ZEC)
    • EOS
    • YearnFinance (YFI)
  • Education
    • Accepting Bitcoin payments
    • Using Bitcoin
    • What is Bitcoin Mining
    • How to Trade Bitcoin
    • How to Buy Bitcoin
    • Digital Currency Exchange
    • Proof of Existence
    • Is Bitcoin legal?
    • Bitcoin Books
  • Trading Course
  • Directory
    • Crypto Businesses
    • Bitcoin Brokers
    • Casinos
    • Sportsbooks
  • Trade
  • Buy Silver

© 2020 NewsBTC. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy.