|

DeFi is plagued by flagrant bugs leading to $10 million in losses over the past week

  • Three DeFi protocols lost nearly $10 million of user funds in a week.
  • The industry is still immature and vulnerable to exploits.

The past week brought a lot of excitement and a lot of grief at the same time. While Bitcoin traders celebrated the two-year high reached by the pioneer cryptocurrency and harboured aspirations for the new records by the end of the year, DeFi players had to grapple with numerous hacks and exploits.

FXStreet previously reported that hackers stole $100 million from the DeFi sector since the start of the year; however, nearly $10 million were lost within the last seven days.  

Percent, Acropolis and Value betray users trust

On November 12, someone hacked the DeFi yield farming project Akropolis through an exploit that involves Curve and siphoned about $2 million of users funds in DAI tokens. Notably, the project developers claimed that their smart contracts had been audited twice, but the attacker still managed to use the flash loans scheme to drain Akropolis's YCurve and USD pools. 

Akropolis (AKRO) dropped by 25% in a matter of hours and continued sliding down. At the time of writing, the token's price has settled at $0.009, down from $0.014 registered before the hack. The asset is ranked 365th, with a current market capitalization of $18 million.

Two days later, Value DeFi, another yield farming protocol, lost $6 million to hackers via the flash loan technique. Ironically, the team claimed that it had improved its vaults' security to withstand this type of attack. 

According to Emiliano Bonassi, a so-called whitehat hacker and the co-founder of DeFi Italy, the hacker launched a complicated and multi-stage exploit using two flash loans taken from different lending protocols. Namely, they took 80,000 ETH on Aave and 116 million DAI in Uniswap, deposited them to the Value DeFi's multi-stablecoin vault, and performed numerous swaps between USDT, USDC and DAI, exploiting the vulnerability of vault's withdrawal method.

Before running away with the loot, the thief sent $2 million back to the protocol. Later on, a crypto trader, aka @CryptoDeFi137, noticed that the protocol creators were in talks with the hacker, asking them to return $5 million of user funds.

Value DeFi transaction details

Value DeFi transaction details

The governing token of the project, VALUE, lost 25% immediately after the hack to trade at $2. At the time of writing, VALUE is changing hands at $2.15, having recovered 5% on a day-to-day basis. Based on the data provided on the project's official website, less than $1.5 million locked in the hacked Multistables Vault from $3 million right after the incident.

Percent Finance was not actually hacked. However, the protocol users also lost nearly $1 million in USDC, WBTC and ETH. Their tokens were irretrievably frozen on smart contracts following the interest rate model update. The users were not able to do anything with their coins while the team was working on the solutions to return the funds or compensate users for losses.

The price of the Percent Finance token (PCT) crashed by nearly 90% after the incident. At the time of writing, PCT is trading at $0.02 from $0.14 on November 4. 

Three lessons to be learned from the week of DeFi hacks

1. DeFi is an opportunity and a considerable risk at the same time

The skyrocketing popularity of the DeFi industry exposed the critical vulnerabilities of the DeFi ecosystem. Despite the explosive growth of the projects involved in the decentralized finances, most of them are highly insecure and vulnerable to hack attacks. 

Speaking in the interview with the host of Unchained Podcast Laura Shin, the co-founder of Ethereum Vitalik Buterin noted that the interest rates in the DeFi protocols are significantly higher than in traditional banks, and people tend to underestimate risks related to smart contracts. He also added that even audited and well-known platforms were not immune to hacks and errors.

2. DeFi tokens are vulnerable to losses

DeFi tokens earned by yield farmers can become useless in a matter of minutes. The experts drew parallels with the ICO boom in 2017 when the assets bought during the token sale underwent a standard boom-and-bust cycle. Most of them have zero value now, while their investors went broke.

Something similar is happening now in the DeFi industry, where even the tokens of well-established projects like Compound and Uniswap experienced a sharp price decrease from the levels registered at the launch.

3.  The industry is a Wild West territory

DeFi is often touted as a future of the global financial system that will replace the legacy system with its clumsy and costly institutions. However, at this stage, the industry is still at the early stages of its evolution. Being mostly unregulated, it offers scope for manipulations and wrongdoing. Meanwhile, users are not protected by anyone, meaning that they will be left alone with their losses in case of a hack attack, exit scam or code error. This is something to consider before rushing to a new red-hot project. 

Author

Tanya Abrosimova

Tanya Abrosimova

Independent Analyst

 

More from Tanya Abrosimova
Share:

Markets move fast. We move first.

Orange Juice Newsletter brings you expert driven insights - not headlines. Every day on your inbox.

By subscribing you agree to our Terms and conditions.

Editor's Picks

Dogecoin Price Forecast: DOGE breaks key support amid declining investor confidence

Dogecoin (DOGE) trades in the red on Thursday, following a 4% decline on the previous day. The DOGE supply in profit declines as large wallet investors trim their portfolios. Derivatives data shows a surge in bearish positions amid declining retail interest.

Cardano Price Forecast: ADA dips below $0.37, hitting two-month low as bearish momentum builds

Cardano (ADA) price trades in the red, slipping below $0.37 on Thursday after correcting more than 7% so far this week. The ongoing pullback could deepen further as ADA’s social dominance declines and dormant wallet activity rises, suggesting bearish sentiment among traders.

Top Crypto Losers: Pump.fun, SPX6900, Bittensor slide further with double-digit losses

Pump.fun (PUMP), SPX6900 (SPX), and Bittensor (TAO) are leading the losses in the cryptocurrency market over the last 24 hours amid total liquidations of over $500 million. The retail segment alleges institutional manipulation amid an early-morning Bitcoin sell-off routine in the US market.

Bitcoin, Ethereum whipsaw sparks heavy liquidations amid accusations of market manipulation

The crypto market whipsawed on Wednesday as top cryptocurrencies, including Bitcoin (BTC) and Ethereum (ETH), quickly reversed gains from the early American session.

Orange Juice Newsletter – Smart insights by real people. Every day.

A free newsletter highlighting key market trends to help traders stay a step ahead. Daily insights on the most relevant trading topics, compiled by our experts in an easy-to-read format so you never miss an important move.

Bitcoin: Fed delivers, yet fails to impress BTC traders

Bitcoin (BTC) continues de trade within the recent consolidation phase, hovering around $92,000 at the time of writing on Friday, as investors digest the Federal Reserve’s (Fed) cautious December rate cut and its implications for risk assets.