|

Hacker drains DeFi protocol Warp Finance, nearly $8 million lost

  • Warp Finance got hacked via a flash loan attack.
  • The hacker used a complicated scheme based on multiple protocols and swaps.
  • The team has a plan to compensate users for losses.

Another DeFi project got hacked and lost about $8 million of user funds in DAI and USDC. The attacker exploited a sophisticated multi-protocol flash loan scheme and Tornado Cash to hide the digital trace. 

Warp Finance is a DeFi platform that claims to offer "an optimized lending solution powering a liquidity engine." In other words, they allowed users to take cryptocurrency loans using stablecoins as collateral. The project was launched in October 2020. 

What happened to Warp Finance money

Late on Thursday, the community members noticed irregular activity on Warp Finance protocol. Someone used multiple transactions within the flash loan scheme to drain USDC and DAI vaults of the protocol. 

Flash loan is a handy DeFi feature that allows anyone to get an instant loan without the collateral provided that it is repaid within the same block. In the case of Warp Finance, the hacker used a complex scheme to loan more than their collateral value, which led to a lender losing money.

The project team confirmed the hack and recommended to refrain from depositing stablecoins to the protocol until the situation was investigated.

The exploiter got away with $7.7 million in DAI and USDC; however, the team claims that there are approximately $5.5 million that can be recovered from a collateral vault and used to cover the losses.

We will post a more detailed analysis and next steps for http://warp.finance in the coming days when we have a more robust understanding of the exploit that took place.

Emiliano Bonassi, a founder of  DeFi Italy and a white hacker, noticed that hackers tend to launch complicated attacks with multiple loans and swaps on several protocols.

This is the second attack, which uses multiple flash liquidity, flash swaps via Uniswap, and flash loans via dYdX. We will see very complicated things via AaveAave V2 batch flash loans :)

The hack turned out to be costly

Meanwhile, another DeFi expert Nick Chong noted that hackers got away only with $1 million in ETH, while the rest went to paying fees. 

What I immediately find interesting here is that it appears that much of the attacker's bounty went to fees. There was 3.85m DAI and 3.92m USDC in the Warp contracts. The attacker (seemingly) left with $1 million in ethereum (1,462 ETH).

He further explained that the attacker pumped millions through illiquid Uniswap pairs, which resulted in significant slippage on the flash swaps.

The DeFi industry is vulnerable to hack attacks, and Wrap Finance is not the first victim. FXStreet previously reported that Pickle Finance lost nearly $20  of users' funds in DAI tokens. The attacker found and exploited a vulnerability in a smart contract to drain the money. Since the start of the year, the industry lost over $100 million due to hack attacks.

Author

Tanya Abrosimova

Tanya Abrosimova

Independent Analyst

 

More from Tanya Abrosimova
Share:

Editor's Picks

XRP ticks up as risk-off mood, weak ETF demand cap recovery

Ripple (XRP) rebounds above $1.23 from support at $1.20 at the time of writing on Wednesday, as the broader cryptocurrency market pares losses triggered by escalating tensions in the Middle East.

Crypto Today: Bitcoin, Ethereum pare losses as XRP rebounds amid escalating tensions in the Middle East

The cryptocurrency market remains largely under pressure on Wednesday amid escalating tensions in the Middle East. After plunging from its May high of $82,823, Bitcoin (BTC) is showing signs of stabilization, consolidating above the key $67,000 support level.

Bitcoin takes a breather above $65,000 amid swelling institutional pressure

Bitcoin hovers above $67,000 as of Wednesday, taking a breather after over 6% loss the previous day. Whales are reducing their BTC holdings, likely influenced by the 12-day streak of ETF outflows.

Ondo extends gains, defying the broader market crash

ONDO extends gains on Wednesday, after rising 9% the previous day. Early access to Ondo Perps, offering 24/7 perpetual futures on US stocks, ETFs, and commodities, fuels the recovery.

Billions in ETF outflows don’t bode well
Bitcoin (BTC) remains under pressure, trading below $74,000 on Friday, and is set to post its third consecutive week of losses. The institutional sell-off continues, with spot BTC Exchange-Traded funds (ETFs) recording billions in outflows. In addition, sticky inflation and macroeconomic headwinds suppress the Crypto King’s upside potential. Institutional demand continues to weaken so far this week.