
Detail Analysis
Website:
Twitter:
Discord:
No data
Telegram:
No data
Medium:
No data
Github:
No data
Key Indicators
Platform:
Type:
Category:
Method:
Fuse Network
Protocol
Yield
Contract Vulnerabilities
Extended Method:
Reentrancy attack
Data Sources:
Ola Finance is investigating an exploit that took place on the @Fuse_network. All other lending networks remain unaffected, and we have pre-emptively paused borrowing capabilities to mitigate any risk. The breach was originally reported by Voltage Finance - ... aware of a breach on the @voltfinance lending platform around 3 hours ago leading to the theft of $4M in $USDC, $FUSD, $BUSD, $WBTC, $WETH & $FUSE. Voiltage Finance is collaborating with our Lending-as-a-Service partner, @ola_finance, for preliminary investigation.
The initial funds to launch the hack are withdrawn from TornadoCash and tunneled to Fuse network via Fuse Bridge. The gains are tunneled via Fuse Bridge and currently funds still stay in the hacker’s account
More details of the exploit were provided by BlockSec.
https://twitter.com/BlockSecTeam/status/1509466576848064512/photo/1
In the code logic of the borrow() function, the related internal states are updated after an external call. Specifically, the doTransferOut() function will invoke the transfer() function of the ERC677-based token, which will eventually lead to an external call.
https://twitter.com/BlockSecTeam/status/1509466583781232643/photo/1
DISCLAIMER: While Zero Friction LLC has used the best efforts in aggregating and maintaining this database, Zero Friction LLC makes no representations or warranties with respect to the accuracy or completeness, and specifically disclaim any implied warranties of merchantability or fitness for any particular purpose.
Under no circumstances, shall Zero Friction LLC be liable for any loss of profit or funds, any regulatory or governmental penalties, any legal costs, or any other commercial and non-commercial damages, including but not limited to special, incidental, consequential, or other damages from any or all usage of the dataset or information derived from our database.