Cryptocurrency

DForce Network

2023-02-13 [vendor] dForce Network [chain] ethereum
Primary Source ↗
Recovered $3.6M
Blockchain(s) Ethereum

Incident Details

An attacker using flash loans to exploit a common re-entrancy vulnerability siphoned $3.65 million from the dForce defi project on both Arbitrum and Optimism, which are Ethereum layer-2 networks. The exploit, which involves manipulating the oracle price in Curve liquidity pools, is a common one that was first reported to Curve in April 2022 and disclosed in October 2022. It has been used to attack various other projects, including QiDAO.dForce contacted the hacker via blockchain transaction, offering to negotiate a bounty. Several days later, the project tweeted that the attacker had “c[o]me forward as a whitehat”, and that the funds had been fully returned. “We have agreed to offer a bounty and will drop all on-going investigation and law enforcement actions,” they announced.

Technical Details

Initial Attack Vector
Flash loan attack on smart contract
Vendor / Product
dForce Network

Timeline

  1. 2023-02-13 Breach occurred
  2. 2023-02-13 Publicly disclosed