Cryptocurrency [loss] $188,260

Tweet thread by PeckShield Inc.

2022-10-23 [vendor] QuickSwap attack [chain] polygon
Primary Source ↗
Financial Loss $188,260 (188,260 USD)
Blockchain(s) Polygon

Incident Details

Adding to the recent string of oracle manipulation attacks is an attack on the miMATIC ($MAI) market on the QuickSwap decentralized exchange. An exploiter was able to manipulate the spot price of assets to borrow funds, ultimately making off with 138 ETH ($188,000) that they mixed through Tornado Cash. The vulnerability was due to the use of a Curve LP oracle, which contains a vulnerability that was disclosed by a security firm earlier that month.Security firm PeckShield initially suggested the issue might have been with QiDAO, which creates the $MAI stablecoin. The vulnerability is not with their project, although it’s possible that the theft will impact the collateralization of their stablecoin.

Total loss estimated at $188,260.

Technical Details

Initial Attack Vector
Oracle price manipulation
Vendor / Product
QuickSwap attack

Timeline

  1. 2022-10-23 Breach occurred
  2. 2022-10-23 Publicly disclosed