Thread by FatMan
Primary Source ↗Incident Details
A crypto researcher who goes by “FatMan” discovered that the Mirror Protocol in the Terra ecosystem contained a serious vulnerability, that was quietly patched with no announcement on May 9. The Mirror Protocol code previously lacked a duplicate check, which meant that attackers could create a short position and then withdraw it repeatedly in the same transaction, taking many times more money than they should have been authorized to withdraw.FatMan discovered one instance where a person deposited $10,000 and later withdrew $4.3 million. According to FatMan, they found repeated exploits of this type that earned attackers “well over $30 million”. Another researcher on Terra forums estimated about $88 million had been exfiltrated from the project in this way, over the many months the bug went undiscovered and unpatched by Mirror developers.
Total loss estimated at $88,000,000.
Technical Details
- Initial Attack Vector
- Smart contract exploit / hack
- Vendor / Product
- Mirror Protocol vulnerability
Timeline
- 2022-05-26 Breach occurred
- 2022-05-26 Publicly disclosed