• Contact Us
  • Homepages
Newsletter
Today Bitcoin News
Advertisement
  • Home
    • Home – Layout 1
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
  • Contact Us
No Result
View All Result
Today Bitcoin News
No Result
View All Result
Home NEWS Hackers

Lodestar Finance exploited in flash loan attack

news by news
December 11, 2022
in Hackers, Hacks
0
Lodestar Finance exploited in flash loan attack
198
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

The main vulnerability behind the attack was within GLP oracle and how it conducts its price.

Arbitrum-based lending protocol Lodestar Finance was exploited in a flash loan attack on Dec. 10. According to Lodestar, the attacker manipulated the price of the plvGLP token before borrowing all platform liquidity using the inflated token.

In a Twitter thread, Lodestar explained the attack flow. The attacker first manipulated the exchange rate of the plvGLP contract to 1.83 GLP per plvGLP, “an exploit that by itself would be unprofitable”, said the company.

Related articles

FTX suspends user accounts amid Kroll cyber breach concerns

FTX suspends user accounts amid Kroll cyber breach concerns

August 27, 2023
Curve Finance vows to reimburse users after $62M hack

Curve Finance vows to reimburse users after $62M hack

August 12, 2023

Then, the attacker supplied plvGLP collateral to Lodestar and borrowed all available liquidity, cashing out part of the funds “until the collateralization ratio mechanism prevented a full liquidation of the plvGLP.”

Following the hack, “several plvGLP holders also took advantage of the opportunity and also cashed out at 1.83 glp per plvGLP.” The hacker was able to burn a little over 3 million in GLP, making profit on the “stolen funds on Lodestar – minus the GLP they burned.”, noted the DeFi platform.

The attacker made around $5.8 million in profit. Lodestar states that nearly 2.8 million of the GLP (about $2.4 million) was recoverable, which should be used to repay depositors. The company is trying to negotiate a bug bounty with its exploiter:

If you are the hacker, reach out to us so we can find a white-hat agreement and move on.

Recovering the funds of our users is the main priority and we will generously reward your collaboration.#Hack #whitehat #Arbitrum $LODE #Exploit #DEFI https://t.co/SWlCr3KMib

— Lodestar Finance (,) (@LodestarFinance) December 10, 2022

The main vulnerability that led to the attack is inside GLPOracle and how it conducts its price. In an analysis, Solidity Finance audit team said the event highlighted “that utilizing oracles resistant to manipulation is a critically important piece of DeFi, especially in protocols which lend out user assets.”

In a statement, governance aggregator PlutusDAO noted that its “products and platform functioned exactly as intended through the entire event. All funds on Plutus are completely safe. The exploit was solely a result of Lodestar’s oracle implementation.” It also stated:

“We want to take responsibility for promoting an unaudited protocol. While the exploit is in no way Plutus’ fault, we recognize the fact that we were too eager to promote a protocol integrating plvGLP. With plvGLP gaining significant traction, we’ve wanted to highlight all plvGLP integrations to our community to emphasize the adoption and opportunities the integrations have presented both to individual users and protocols. For this, we apologize. We jumped the gun, and going forward we will no longer be promoting protocols that are not audited.”

The Lodestar attack was similar to the Mango Markets exploit on Oct. 11, when over $100 million was stolen through an attacker manipulating price oracle data, allowing the hackers to take out under-collateralized cryptocurrency loans.

Share79Tweet50

Related Posts

FTX suspends user accounts amid Kroll cyber breach concerns

FTX suspends user accounts amid Kroll cyber breach concerns

by news
August 27, 2023
0

FTX took the decision as a proactive measure to prevent any potential future incidents or additional harm following the recent...

Curve Finance vows to reimburse users after $62M hack

Curve Finance vows to reimburse users after $62M hack

by news
August 12, 2023
0

The platform said it would assess each impacted user for reimbursement. Decentralized finance (DeFi) platform Curve Finance has officially stated...

Curve Finance opens bounty after exploiter’s return deadline expires

Curve Finance opens bounty after exploiter’s return deadline expires

by news
August 7, 2023
0

Curve Finance is extending a $1.85 million bug bounty offer to anyone who can identify the exploiter of its stable...

Alchemix reports return of all stolen funds from Curve pools

Alchemix reports return of all stolen funds from Curve pools

by news
August 6, 2023
0

The attacker started returning stolen funds after accepting nearly $7 million in bug bounty. Funds had been returned to Alchemix...

Curve, Metronome and Alchemix offering 10% bug bounty on Vyper hack

Curve, Metronome and Alchemix offering 10% bug bounty on Vyper hack

by news
August 4, 2023
0

The exploit on July 30 resulted in the theft of roughly $70 million in cryptocurrencies, bringing the bounty close to...

Load More
  • Trending
  • Comments
  • Latest
ETHDenver 2023: Cointelegraph afterparty delivers a ‘packed house’ and other notable events

ETHDenver 2023: Cointelegraph afterparty delivers a ‘packed house’ and other notable events

March 15, 2023
Bitcoin faces do-or-die weekly, monthly close with macro bull trend at stake

Bitcoin faces do-or-die weekly, monthly close with macro bull trend at stake

February 18, 2023
Ethereum price resistance at $1,750 could reflect traders’ anxiety over the Shanghai upgrade

Ethereum price resistance at $1,750 could reflect traders’ anxiety over the Shanghai upgrade

March 1, 2023
Silvergate stock plunges 31% after delayed filing raises doubts over future

Silvergate stock plunges 31% after delayed filing raises doubts over future

March 2, 2023

US Commodities Regulator Beefs Up Bitcoin Futures Review

0

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Bitcoin shorts keep burning as BTC price seeks to hold $27K

Bitcoin shorts keep burning as BTC price seeks to hold $27K

September 29, 2023
How long could Sam Bankman-Fried go to jail for?

How long could Sam Bankman-Fried go to jail for?

September 29, 2023
The metaverse is real: Zuck’s ‘incredible’ photorealistic tech wows crypto twitter

The metaverse is real: Zuck’s ‘incredible’ photorealistic tech wows crypto twitter

September 29, 2023
Median Web3 developer salary stands at $128K in 2023

Median Web3 developer salary stands at $128K in 2023

September 28, 2023
Today Bitcoin News

© 2022

Navigate Site

  • 2022
  • 2023
  • 5G
  • 5G network
  • Altcoin
  • bank of china
  • bank of england
  • Bank of Japan
  • Bank of Russia
  • Binance Academy
  • BingChatGPT
  • Bitcoin
  • Changpeng Zhao
  • ChatGPT Web3
  • coinbase
  • CoinDesk
  • CoinMarketCap

Follow Us

No Result
View All Result
  • Contact Us
  • Homepages

© 2022