Cryptocurrency [loss] $11M+

Tweet thread by PeckShield

2022-04-30 [vendor] Saddle Finance [chain] ethereum
Primary Source ↗
Financial Loss $11.1M (11,078,985 USD)
Blockchain(s) Ethereum

Incident Details

An exploiter used a flash loan attack to pull 3,933 ETH (~$11 million) from the “decentralized automated market maker” Saddle Finance. Shortly after the attack, the hacker began moving the stolen funds through the Tornado Cash tumbler to launder the money.Saddle Finance had lost money once before, hours after it launched in January 2021. An individual was able to arbitrage Saddle Finance pools for a profit of around $275,000.

Total loss estimated at $11,078,985.

Technical Details

Initial Attack Vector
Flash loan attack on smart contract
Vendor / Product
Saddle Finance

Timeline

  1. 2022-04-30 Breach occurred
  2. 2022-04-30 Publicly disclosed