Cryptocurrency [loss] $884,000

"Attacker drains $800K from DeFi protocol Sturdy Finance"

2023-06-11 [vendor] Sturdy Finance [chain] ethereum
Primary Source ↗
Financial Loss $884,000 (884,000 USD)
Blockchain(s) Ethereum

Incident Details

The Sturdy Finance defi lending protocol was exploited, with hackers taking advantage of an oracle manipulation vulnerability to make off with 442 ETH ($775,000). They subsequently transferred the funds into Tornado Cash. The total loss to the project was somewhat higher: 504 ETH ($884,000).Roughly an hour after the attack, the project tweeted that they were aware of the attack, and had paused all markets. On June 19 the project sent a message to the attacker, pleading with them to return the funds and threatening: “There are criminal organizations following the same evidence trails we are. This isn’t going away until you return funds. We are your best option out of this.”

Total loss estimated at $884,000.

Technical Details

Initial Attack Vector
Oracle price manipulation
Vendor / Product
Sturdy Finance

Timeline

  1. 2023-06-11 Breach occurred
  2. 2023-06-11 Publicly disclosed