Cryptocurrency [loss] $4M+

"Onyx protocol exploited a second time for $3.8M via known bug"

2024-09-26 [vendor] Onyx [chain] ethereum
Primary Source ↗
Financial Loss $3.8M (3,800,000 USD)
Blockchain(s) Ethereum

Incident Details

The Onyx protocol was hacked for a second time by attackers taking advantage of known bugs in forks of the Compound Finance project. Projects regularly fail to patch these bugs, despite many instances of multi-million dollar hacks affecting Compound forks in the past.Onyx apparently didn’t learn their lesson the first time around, when they were exploited for $2 million in November 2023 by an attacker taking advantage of a known vulnerability affecting empty markets on the protocol. This same bug seems to have contributed to this exploit, although Onyx has claimed the hack was due to a separate vulnerability in an NFT liquidation contract.

Total loss estimated at $3,800,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Onyx

Timeline

  1. 2024-09-26 Breach occurred
  2. 2024-09-26 Publicly disclosed