DeFi protocol Arcadia Finance hacked on Ethereum and Optimism for $455k
<p> <br />
</p>
<div data-v-7c7881ea="">
<p>A hacker drained approximately $455,000 from non-custodial decentralized finance (DeFi) protocol Arcadia Finance by exploiting a code vulnerability.</p>
<p>Blockchain investigator PeckShield <a href="https://twitter.com/PeckShieldAlert/status/1678248292327763968" target="_blank" rel="noopener nofollow">alerted</a> about the hack on Arcadia Finance, pointing out the cause as “the lack of untrusted input validation.” The code supposedly lacked a validation mechanism to cross-check unverified inputs. This loophole allowed the hacker to drain funds worth roughly $455,000 from Ethereum (darcWETH) and Optimism (darcUSDC) vaults collectively.</p>
<figure><img decoding="async" src="https://s3.cointelegraph.com/uploads/2023-07/779a665c-0e9a-4e27-9204-1ac5f57d3b71.png" /><figcaption><em>Arcadia Finance code required no validation of untrusted input. Source: PeckShield</em></figcaption></figure>
<p>Arcadia Finance has not yet responded to Cointelegraph’s request for comment.</p>
<p>Arcadia Finance confirmed the hack two hours after PeckShield’s intimation and subsequently paused the contracts to prevent further bleeding of funds. </p>
<blockquote>
<p lang="en" dir="ltr">We are aware of a potential exploit in our protocol. <br />We have paused the contracts and are investigating the root-cause with security experts as we speak. More info will follow as it comes available.</p>
<p>— Arcadia Finance (@ArcadiaFi) <a href="https://twitter.com/ArcadiaFi/status/1678285634727706625?ref_src=twsrc%5Etfw">July 10, 2023</a></p></blockquote>
<p>While the investigations are underway, Arcadia’s code houses another vulnerability, which could prove catastrophic for the protocol if exploited. <a href="https://twitter.com/peckshield/status/1678265212770693121" target="_blank" rel="noopener nofollow">According</a> to PeckShield:</p>
<blockquote><p>“In addition, there is a lack of reentrancy protection, which allows for the instant liquidation to bypass the internal vault health check.”</p></blockquote>
<p>The majority of the stolen funds — approximately 180 Ether (ETH) — were from Optimism, and have been washed via Tornado Cash. However, the stolen tokens — worth over $103,000 at the time of writing — on Ethereum remain parked at the suspected wallet address.</p>
<p><strong><em>Related: </em></strong><strong><em>Multichain MPC bridge sees $100M+ outflows, sparking fears of exploit</em></strong></p>
<p>In Q2 of 2023, hacks and exploits in the crypto space resulted in a cumulative loss of over $300 million.</p>
<p>A report by blockchain security company CertiK showed that a total of 212 security incidents were recorded in the quarter, resulting in a loss of $313,566,528 from Web3 protocols.</p>
<p>When compared to the previous year’s Q2 data, CertiK found that the crypto hacks declined by 58%. Out of the lot, BNB Chain recorded the most incidents, with 119 incidents leading to $70,711,385 in losses.</p>
<p><em><strong><em>Collect this article as an NFT</em></strong><em> to preserve this moment in history and show your support for independent journalism in the crypto space.</em></em></p>
<p><strong><em>Magazine: Should you ‘orange pill’ children? The case for Bitcoin kids books</em></strong></p>
<p><template data-name="subscription_form" data-type="markets_outlook"/></div>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script><br />
<br /><br />
<br /><a href="https://cointelegraph.com/news/arcadia-finance-hacked-on-ethereum-and-optimism-for-455k">Source link </a></p><p>The post <a href="https://forextraderhub.com/defi-protocol-arcadia-finance-hacked-on-ethereum-and-optimism-for-455k.html">DeFi protocol Arcadia Finance hacked on Ethereum and Optimism for $455k</a> first appeared on <a href="https://forextraderhub.com">Forex Trader Hub</a>.</p>
Leave a Comment