• Contact Us
  • Homepages
Newsletter
Today Bitcoin News
Advertisement
  • Home
    • Home – Layout 1
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
  • Contact Us
No Result
View All Result
Today Bitcoin News
No Result
View All Result
Home NEWS Hackers

Platypus attack exploited incorrect ordering of code, auditor claims

news by news
February 18, 2023
in Hackers, Hacks, loans, Smart Contracts
0
Platypus attack exploited incorrect ordering of code, auditor claims
275
SHARES
2.1k
VIEWS
Share on FacebookShare on Twitter

Related articles

FTX suspends user accounts amid Kroll cyber breach concerns

FTX suspends user accounts amid Kroll cyber breach concerns

August 27, 2023
Curve Finance vows to reimburse users after $62M hack

Curve Finance vows to reimburse users after $62M hack

August 12, 2023

The misordered lines caused a solvency check to be performed before the user’s amount, factor, and rewardDebt had been set to zero

The $8m Platypus flash loan attack was made possible because of code that was in the wrong order, according to a post mortem report from Platypus auditor Omniscia. The auditing company claims the problematic code didn’t exist in the version they saw.

In light of the recent @Platypusdefi incident the https://t.co/30PzcoIJnt team has prepared a technical post-mortem analysis describing how the exploit unravelled in great details.

Be sure to follow @Omniscia_sec to receive more security updates!https://t.co/cf784QtKPK pic.twitter.com/egHyoYaBhn

— Omniscia (@Omniscia_sec) February 17, 2023

According to the report, the Platypus MasterPlatypusV4 contract “contained a fatal misconception in its emergencyWithdraw mechanism” which made it perform “its solvency check before updating the LP tokens associated with the stake position.”

The report emphasized that the code for the emergencyWithdraw function had all of the necessary elements to prevent an attack, but these elements were simply written in the wrong order, as Omniscia explained:

“The issue could have been prevented by re-ordering the MasterPlatypusV4::emergencyWithdraw statements and performing the solvency check after the user’s amount entry has been set to 0 which would have prohibited the attack from taking place.”

Omnisia admitted that they audited a version of the MasterPlatypusV4 contract from Nov. 21 to Dec. 5, 2021. However, this version “contained no integration points with an external platypusTreasure system” and therefore did not contain the misordered lines of code. From Omniscia’s point of view, this implies that the developers must have deployed a new version of the contract at some point after the audit was made.

Related: Raydium announces details of hack, proposes compensation for victims

The auditor claims that the contract implementation at Avalanche (AVAX) C-Chain address 0xc007f27b757a782c833c568f5851ae1dfe0e6ec7 is the one that was exploited. Lines 582-584 of this contract appear to call a function called “isSolvent” on the PlatypusTreasure contract, and lines 599-601 appear to set the user’s amount, factor, and rewardDebt to zero. However, these amounts are set to zero after the “isSolvent” function has already been called.

The Platypus team confirmed on Feb. 16 that the attacker exploited a “flaw in [the] USP solvency check mechanism,” but the team did not initially provide further detail. This new report from the auditor sheds further light on how the attacker may have been able to accomplish the exploit.

The Platypus team announced on Feb. 16 that the attack had occurred. It has attempted to contact the hacker and get the funds returned in exchange for a bug bounty. The attacker used flashed loans to perform the exploit, which is similar to the strategy used in the Defrost Finance exploit of Dec. 25.

Share110Tweet69

Related Posts

FTX suspends user accounts amid Kroll cyber breach concerns

FTX suspends user accounts amid Kroll cyber breach concerns

by news
August 27, 2023
0

FTX took the decision as a proactive measure to prevent any potential future incidents or additional harm following the recent...

Curve Finance vows to reimburse users after $62M hack

Curve Finance vows to reimburse users after $62M hack

by news
August 12, 2023
0

The platform said it would assess each impacted user for reimbursement. Decentralized finance (DeFi) platform Curve Finance has officially stated...

Curve Finance opens bounty after exploiter’s return deadline expires

Curve Finance opens bounty after exploiter’s return deadline expires

by news
August 7, 2023
0

Curve Finance is extending a $1.85 million bug bounty offer to anyone who can identify the exploiter of its stable...

Alchemix reports return of all stolen funds from Curve pools

Alchemix reports return of all stolen funds from Curve pools

by news
August 6, 2023
0

The attacker started returning stolen funds after accepting nearly $7 million in bug bounty. Funds had been returned to Alchemix...

Curve, Metronome and Alchemix offering 10% bug bounty on Vyper hack

Curve, Metronome and Alchemix offering 10% bug bounty on Vyper hack

by news
August 4, 2023
0

The exploit on July 30 resulted in the theft of roughly $70 million in cryptocurrencies, bringing the bounty close to...

Load More
  • Trending
  • Comments
  • Latest
ETHDenver 2023: Cointelegraph afterparty delivers a ‘packed house’ and other notable events

ETHDenver 2023: Cointelegraph afterparty delivers a ‘packed house’ and other notable events

March 15, 2023
Bitcoin faces do-or-die weekly, monthly close with macro bull trend at stake

Bitcoin faces do-or-die weekly, monthly close with macro bull trend at stake

February 18, 2023
Ethereum price resistance at $1,750 could reflect traders’ anxiety over the Shanghai upgrade

Ethereum price resistance at $1,750 could reflect traders’ anxiety over the Shanghai upgrade

March 1, 2023
Silvergate stock plunges 31% after delayed filing raises doubts over future

Silvergate stock plunges 31% after delayed filing raises doubts over future

March 2, 2023

US Commodities Regulator Beefs Up Bitcoin Futures Review

0

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Bitcoin shorts keep burning as BTC price seeks to hold $27K

Bitcoin shorts keep burning as BTC price seeks to hold $27K

September 29, 2023
How long could Sam Bankman-Fried go to jail for?

How long could Sam Bankman-Fried go to jail for?

September 29, 2023
The metaverse is real: Zuck’s ‘incredible’ photorealistic tech wows crypto twitter

The metaverse is real: Zuck’s ‘incredible’ photorealistic tech wows crypto twitter

September 29, 2023
Median Web3 developer salary stands at $128K in 2023

Median Web3 developer salary stands at $128K in 2023

September 28, 2023
Today Bitcoin News

© 2022

Navigate Site

  • 2022
  • 2023
  • 5G
  • 5G network
  • Altcoin
  • bank of china
  • bank of england
  • Bank of Japan
  • Bank of Russia
  • Binance Academy
  • BingChatGPT
  • Bitcoin
  • Changpeng Zhao
  • ChatGPT Web3
  • coinbase
  • CoinDesk
  • CoinMarketCap

Follow Us

No Result
View All Result
  • Contact Us
  • Homepages

© 2022