Cryptocurrency [loss] $13M+

Tweet thread by PeckShield Inc.

2022-04-28 [vendor] Deus Finance [chain] fantom
Primary Source ↗
Financial Loss $13.4M (13,400,000 USD)
Blockchain(s) Fantom

Incident Details

The defi project Deus Finance was hit with a flash loan attack that netted the hacker $13.4 million. The loss to the protocol was likely larger than what the hacker was able to withdraw, though Deus announced that no users had been liquidated and that “the loss is on the protocol”.Deus had suffered a similar attack in March, with an attacker using a flash loan attack to steal more than $3.1 million. Deus reimbursed users who were liquidated in the incident.According to Deus’ CEO, the exploit in this incident was not the same one used in the previous attack. He wrote on Twitter that the exploit was “the first of its kind, a zero-day exploit on Solidly [decentralized crypto exchange] swaps”.

Total loss estimated at $13,400,000.

Technical Details

Initial Attack Vector
Flash loan attack on smart contract
Vendor / Product
Deus Finance

Timeline

  1. 2022-04-28 Breach occurred
  2. 2022-04-28 Publicly disclosed