Cryptocurrency [loss] $5M+

Tweet thread by CertiKAlert

2022-11-10 [vendor] DFX Finance attack [chain] ethereum
Primary Source ↗
Financial Loss $5.0M (5,000,000 USD)
Blockchain(s) Ethereum

Incident Details

An attacker was able to use a flash loan to exploit a vulnerability in the smart contract for DFX Finance, a decentralized forex trading platform. The platform suffered a loss amounting to around $5 million. The attacker subsequently laundered the funds through the Tornado Cash cryptocurrency tumbler. The attacker didn’t make off with the entire amount lost from the platform, partly due to an MEV bot snagging a significant amount of the funds.

Total loss estimated at $5,000,000.

Technical Details

Initial Attack Vector
Flash loan attack on smart contract
Vendor / Product
DFX Finance attack

Timeline

  1. 2022-11-10 Breach occurred
  2. 2022-11-10 Publicly disclosed