en
Back to the list

ShadowFi Exploit Assent The $300K Liquidity Drain

source-logo  thecoinrepublic.com 07 September 2022 03:54, UTC
  • On September 3, 2022, ShadowFi noted the attack on its Twitter account.
  • The attack caused exploitation that costs around $300,000.

ShadowFi, a decentralized financial payment network, reported an attack on DeFi systems. Due to this attack, the cause costs around $300K. The information of the attack was made public when Peckshield detected the exploit. Peckshield, a popular blockchain security firm shared the details on its Twitter account regarding the attack.

Peckshield’s Report

The attacker depleted ShadowFi’s liquidity pool contract and left it at zero dollars, as ShadowFi mentioned. While the Peckshield defied that the vulnerabilities in SDF tokens made protocol exploitation easier. This process burned the token as it does not require anyone’s permission.

#PeckShieldAlert PeckShield has detected @ShadowFi_ suffered an exploit possibly due to a vulnerability of SDF token which allows the token can be burnt by anybody, the exploiter grabbed ~1,078 $BNB (~$301k). $SDF has dropped 98.5%https://t.co/O8ugq2sU3p pic.twitter.com/Ljg3RfkGFl

— PeckShieldAlert (@PeckShieldAlert) September 2, 2022

As per the report of Peckshield, the hacker stole around 1,078 BNB, or $300K. The security firm revealed the hacker as NeorderDAO and claimed the name was also recorded in its internal database.

Attacker exploits bug in ShadowFi to empty $300,000 liquidity pool

September 1, 2022https://t.co/hq33VyYcM6 pic.twitter.com/dLy88sir08

— web3 is going just great (@web3isgreat) September 2, 2022

Peckshield believes that the stolen funds were transferred to Tornado Cash. The tornado cash somewhere affects the crypto industry and the encrypted software used to send money from compromised networks. This software supported the laundering of more than $7B from different crypto exchanges in 2019.

#PeckShieldAlert PeckShield has detected @ShadowFi_ suffered an exploit possibly due to a vulnerability of SDF token which allows the token can be burnt by anybody, the exploiter grabbed ~1,078 $BNB (~$301k). $SDF has dropped 98.5%https://t.co/O8ugq2sU3p pic.twitter.com/Ljg3RfkGFl

— PeckShieldAlert (@PeckShieldAlert) September 2, 2022

It must be noted that these kinds of hacks become very harsh for crypto holders and authorities. The Tornado Cash ban by the U.S. regulatory ended the specific security gaps.

Besides this, Tornado Cash is still operating without following any prohibition. The ShadowFi used the crypto mixer that leads toward the exploit. It was then transferred to Tornado after the exchange of ~8.4 SDF tokens for 1078 BNB.

Over this ShadowFi assures finding the solution with its team and commitment to the consumer’s best interests. It requests the users to be calm while the team identifies the solution and solves the issue.

thecoinrepublic.com