Cryptocurrency Report
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Altcoin
  • Blockchain
  • Analysis
  • DeFi
  • NFT
  • ICO
  • Videos
What's Hot

Cointelegraph Store: Introducing Bitcoin Pizza Day merch for crypto OGs

May 22, 2022

6 Questions for Sonali Giovino of Defiyield – Cointelegraph Magazine

May 22, 2022

NFTs: Empowering artists and charities to embrace the digital movement

May 22, 2022
Facebook Twitter Instagram
  • Advertise
  • Privacy
  • Contact
  • Terms
Facebook Twitter Instagram LinkedIn
Cryptocurrency Report
  • Home
  • News
    1. Bitcoin
    2. Ethereum
    3. Altcoin
    4. View All

    Russian Crypto Regulation Can’t Be Delayed any Longer, Claims Top MP

    May 21, 2022

    G7 Keeps Pushing for Crypto Regulation, Here’s What’s Already Happening

    May 20, 2022

    Terra Honeypot Scam, Blocked Bored Ape NFT Sale, FTX Offers Stocks + More News

    May 20, 2022

    Bitcoin and Ethereum Hold Gains, Altcoins Accelerate

    May 20, 2022

    Crypto Payments on Shopify, Cloudflare Plays With Ethereum, EY & Polygon + More News

    May 20, 2022

    Contradictory Vitalik Buterin Says He Wants a More Bitcoin-like Ethereum

    May 19, 2022

    Bitcoin and Ethereum Look for Direction, ADA and SOL Trim Gains

    May 18, 2022

    Bitcoin and Ethereum Consolidate, ADA, APE, and Multiple Altcoins Rally

    May 18, 2022

    A Curious Coincidence – Major Terra Backers Break Silence on Same Day

    May 20, 2022

    Tether in the Spotlight After USD 9B Worth of Redemptions

    May 20, 2022

    South Korean LUNA Buying Skyrockets, Token Trading at Huge Premium on Domestic Exchanges

    May 20, 2022

    From Silence to Humbling Hell – Major Terra Backers Keep Low Profile as the Small Guy Is ‘the Biggest Loser’

    May 19, 2022

    Cointelegraph Store: Introducing Bitcoin Pizza Day merch for crypto OGs

    May 22, 2022

    6 Questions for Sonali Giovino of Defiyield – Cointelegraph Magazine

    May 22, 2022

    NFTs: Empowering artists and charities to embrace the digital movement

    May 22, 2022

    Bitcoin targets record 8th weekly red candle while BTC price limits weekend losses

    May 22, 2022
  • Blockchain
  • Analysis
  • DeFi
  • NFT
  • ICO
  • Videos

    The Crypto Metaverse is Growing RAPIDLY! (INSANE MICROSOFT BUY)

    January 18, 2022

    BEST Crypto Safety Guide 101 (Keep Your $$ SAFE with Passphrases)

    January 18, 2022

    SHOCKING: Microsoft Enters the CRYPTO METAVERSE!!! (HUGE $69 Billion CASH Buy)

    January 18, 2022

    URGENT NEWS For Cardano Holders!! (MUST Watch Before Jan 20)

    January 17, 2022

    ⚠️ WARNING To All Bitcoin Holders ⚠️ (Time is RUNNING OUT!!!)

    January 17, 2022
  • bitcoinBitcoin(BTC)
    $42,304.00-0.92% 24H
    BITCOIN
    24H : -0.92%
    Volume : $18,001,823,455.00
    Marketcap : $804,136,324,461.00
  • ethereumEthereum(ETH)
    $3,187.18-1.80% 24H
    ETHEREUM
    24H : -1.80%
    Volume : $11,828,130,842.00
    Marketcap : $383,283,409,099.00
  • tetherTether(USDT)
    $1.000.020% 24H
    TETHER
    24H : 0.020%
    Volume : $42,292,952,195.00
    Marketcap : $82,566,134,570.00
  • binancecoinBNB(BNB)
    $416.19-2.16% 24H
    BNB
    24H : -2.16%
    Volume : $1,421,783,549.00
    Marketcap : $69,948,357,062.00
  • usd-coinUSD Coin(USDC)
    $0.9980.110% 24H
    USD COIN
    24H : 0.110%
    Volume : $3,215,590,549.00
    Marketcap : $50,856,931,622.00
  • solanaSolana(SOL)
    $110.52-1.25% 24H
    SOLANA
    24H : -1.25%
    Volume : $1,326,948,052.00
    Marketcap : $36,230,891,086.00
  • rippleXRP(XRP)
    $0.744-2.62% 24H
    XRP
    24H : -2.62%
    Volume : $2,611,405,064.00
    Marketcap : $35,798,721,281.00
  • cardanoCardano(ADA)
    $1.02-1.97% 24H
    CARDANO
    24H : -1.97%
    Volume : $735,911,632.00
    Marketcap : $32,692,285,870.00
  • terra-lunaTerra(LUNA)
    $87.96-7.21% 24H
    TERRA
    24H : -7.21%
    Volume : $2,091,404,457.00
    Marketcap : $31,224,000,667.00
  • avalanche-2Avalanche(AVAX)
    $79.94-4.23% 24H
    AVALANCHE
    24H : -4.23%
    Volume : $651,461,780.00
    Marketcap : $21,345,345,382.00
  • polkadotPolkadot(DOT)
    $18.98-3.96% 24H
    POLKADOT
    24H : -3.96%
    Volume : $522,492,664.00
    Marketcap : $20,904,948,600.00
  • dogecoinDogecoin(DOGE)
    $0.147-0.35% 24H
    DOGECOIN
    24H : -0.35%
    Volume : $1,709,936,369.00
    Marketcap : $19,528,083,067.00
  • binance-usdBinance USD(BUSD)
    $0.9990.100% 24H
    BINANCE USD
    24H : 0.100%
    Volume : $3,031,521,102.00
    Marketcap : $17,907,585,119.00
  • terrausdTerraUSD(UST)
    $1.000.00% 24H
    TERRAUSD
    24H : 0.00%
    Volume : $710,407,989.00
    Marketcap : $16,759,326,710.00
  • shiba-inuShiba Inu(SHIB)
    $0.000024-0.91% 24H
    SHIBA INU
    24H : -0.91%
    Volume : $622,427,689.00
    Marketcap : $13,391,607,837.00
  • wrapped-bitcoinWrapped Bitcoin(WBTC)
    $42,263.00-1.06% 24H
    WRAPPED BITCOIN
    24H : -1.06%
    Volume : $205,987,180.00
    Marketcap : $11,648,041,723.00
  • crypto-com-chainCronos(CRO)
    $0.437-1.87% 24H
    CRONOS
    24H : -1.87%
    Volume : $43,191,918.00
    Marketcap : $11,045,868,142.00
  • nearNEAR Protocol(NEAR)
    $15.96-4.67% 24H
    NEAR PROTOCOL
    24H : -4.67%
    Volume : $1,001,407,008.00
    Marketcap : $10,603,423,829.00
  • staked-etherLido Staked Ether(STETH)
    $3,182.92-1.85% 24H
    LIDO STAKED ETHER
    24H : -1.85%
    Volume : $8,945,498.00
    Marketcap : $10,259,684,260.00
  • matic-networkPolygon(MATIC)
    $1.43-2.09% 24H
    POLYGON
    24H : -2.09%
    Volume : $379,202,804.00
    Marketcap : $9,786,905,958.00
Cryptocurrency Report
Home » DeFi attacks are on the rise — Will the industry be able to stem the tide?
News

DeFi attacks are on the rise — Will the industry be able to stem the tide?

CryptoReporterBy CryptoReporterMay 14, 2022No Comments9 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

The decentralized finance (DeFi) industry has lost over a billion dollars to hackers in the past couple of months, and the situation seems to be spiraling out of control.

According to the latest statistics, approximately $1.6 billion in cryptocurrencies was stolen from DeFi platforms in the first quarter of 2022. Furthermore, over 90% of all pilfered crypto is from hacked DeFi protocols.

These figures highlight a dire situation that is likely to persist over the long term if ignored.

Why hackers prefer DeFi platforms

In recent years, hackers have ramped up operations targeting DeFi systems. One primary reason as to why these groups are drawn to the sector is the sheer amount of funds that decentralized finance platforms hold. Top DeFi platforms process billions of dollars in transactions each month. As such, the rewards are high for hackers who are able to carry out successful attacks.

The fact that most DeFi protocol codes are open source also makes them even more prone to cybersecurity threats.

This is because open source programs are available for scrutiny by the public and can be audited by anyone with an internet connection. As such, they are easily scoured for exploits. This inherent property allows hackers to analyze DeFi applications for integrity issues and plan heists in advance.

Some DeFi developers have also contributed to the situation by deliberately disregarding platform security audit reports published by certified cybersecurity firms. Some development teams also launch DeFi projects without subjecting them to extensive security analysis. This increases the probability of coding defects.

Another dent in the armor when it comes to DeFi security is the interconnectivity of ecosystems. DeFi platforms are typically interconnected using cross-bridges, which bolster convenience and versatility.

While cross-bridges provide enhanced user experience, these crucial snippets of code connect huge networks of distributed ledgers with varying levels of security. This multiplex configuration allows DeFi hackers to harness the capabilities of multiple platforms to amplify attacks on certain platforms. It also allows them to quickly transfer ill-gotten funds across multiple decentralized networks seamlessly.

Besides the aforementioned risks, DeFi platforms are also prone to insider sabotage.

Security breaches

Hackers are using a wide range of techniques to infiltrate vulnerable DeFi perimeter systems. 

Security breaches are a common occurrence in the DeFi sector. According to the 2022 Chainalysis report, approximately 35% of all stolen crypto in the past two years is attributed to security breaches.

Many of them occur due to faulty code. Hackers usually dedicate significant resources to finding systemic coding errors that allow them to carry out these types of attacks and typically utilize advanced bug tracker tools to aid them in this.

Another common tactic used by threat actors to seek out vulnerable platforms is tracking down networks with unpatched security issues that have already been exposed but yet to be implemented.

Hackers behind the recent Wormhole DeFi hack attack that led to the loss of about $325 million in digital tokens are reported to have used this strategy. An analysis of code commits revealed that a vulnerability patch uploaded to the platform’s GitHub repository was exploited before the patch was deployed.

The mistake enabled the intruders to forge a system signature that allowed the minting of 120,000 Wrapped Ether (wETH) coins valued at $325 million. The hackers then sold the wETH for about $250 million in Ether (ETH). The exchanged Ethereum coins were derived from the platform’s settlement reserves, thereby leading to losses.

The Wormhole service acts as a bridge between chains. It allows users to spend deposited cryptocurrencies in wrapped tokens across chains. This is accomplished by minting Wormhole-wrapped tokens, which alleviate the need to swap or convert the deposited coins directly.

Recent: How blockchain archives can change how we record history in wartime

Flash loan attacks

Flash loans are unsecured DeFi loans that require no credit checks. They enable investors and traders to borrow funds instantly.

Because of their convenience, flash loans are usually used to take advantage of arbitrage opportunities in connected DeFi ecosystems.

In flash loan attacks, lending protocols are targeted and compromised using price manipulation techniques that create artificial price discrepancies. This allows bad actors to buy assets at hugely discounted rates. Most flash loan attacks take minutes and sometimes seconds to execute and involve several interlinked DeFi protocols.

One way through which attackers manipulate asset prices is by targeting assailable price oracles. DeFi price oracles, for example, draw their rates from external sources such as reputable exchanges and trade sites. Hackers can, for example, manipulate the source sites to trick oracles into momentarily dropping the value of targeted asset rates so that they trade at lower prices compared to the wider market.

Attackers then buy the assets at deflated rates and quickly sell them at their floating exchange rate. Using leveraged tokens obtained through flash loans allows them to magnify the profits.

Besides manipulating prices, some attackers have been able to carry out flash loan attacks by hijacking DeFi voting processes. Most recently, Beanstalk DeFi incurred a $182 million loss after an attacker took advantage of a shortcoming in its governance system.

The Beanstalk development team had included a governance mechanism that allowed participants to vote for platform changes as a core functionality. This setup is popular in the DeFi industry because it upholds democracy. Voting rights on the platform were set to be proportional to the value of native tokens held.

An analysis of the breach revealed that the attackers obtained a flash loan from the Aave DeFi protocol to get almost $1 billion in assets. This enabled them to get a 67% majority in the voting governance system and allowed them to unilaterally approve the transfer of assets to their address. The perpetrators made off with about $80 million in digital currencies after repaying the flash loan and related surcharges.

Approximately $360 million worth of crypto coins was stolen from DeFi platforms in 2021 using flash loans, according to Chainalysis.

Where does stolen crypto go?

For a long time now, hackers have used centralized exchanges to launder stolen funds, but cybercriminals are beginning to ditch them for DeFi platforms. In 2021, cybercriminals sent about 17% of all illicit crypto to DeFi networks, which is a significant jump from 2% in 2020.

Market pundits theorize that the shift to DeFi protocols is because of the wider implementation of more stringent Know Your Customer (KYC) and Anti-Money Laundering (AML) processes. The procedures compromise the anonymity sought after by cybercriminals. Most DeFi platforms forego these crucial processes.

Cooperation with the authorities

Centralized exchanges are also, now more than ever before, working with authorities to counter cybercrime. In April, the Binance exchange played an instrumental role in the recovery of $5.8 million in stolen cryptocurrencies that was part of a $625 million stash stolen from Axie Infinity. The money had initially been sent to Tornado Cash.

Tornado Cash is a token anonymization service that obfuscates the origin of funds by fragmenting on-chain links that are used to trace transacting addresses.

A portion of the stolen funds was, however, tracked by blockchain analytic firms to Binance. The loot was held in 86 addresses on the exchange.

In the aftermath of the incident, a spokesperson for the United States Treasury Department underlined that crypto exchanges that handle money from blacklisted crypto address risk sanctions.

Tornado Cash also seems to be cooperating with the authorities to stop the transfer of stolen funds to its network. The company has said that it will be implementing a monitoring tool to help identify and block embargoed wallets.

There seems to be some progress in the seizure of nicked assets by the authorities. Earlier this year, the U.S. Department of Justice announced the seizure of $3.6 billion in crypto and arrested two people who were involved in laundering the funds. The money was part of the $4.5 billion purloined from the Bitfinex crypto exchange in 2016.

The crypto seizure was among the biggest ever recorded.

DeFi CEOs speak about the current situation

Speaking exclusively to Cointelegraph earlier this week, Eric Chen, CEO and co-founder of Injective Labs — an interoperable smart contracts platform optimized for decentralized finance applications — said that there is hope that the problems will subside.

“We are seeing the tide continuing to subside, as more robust security standards are put into place. With proper testing and further security infrastructures put into place, DeFi projects will be able to prevent common exploit risks in the future,” he said.

On the measures that his network was taking to avert hack attacks, Chen provided an outline:

“Injective ensures a more tightly defined application-centric security model compared to traditional Ethereum Virtual Machine-based DeFi applications. The design of the blockchain and the logic of core modules protect Injective from common exploits such as re-entrancy, maximum extractable value and flash loans. Applications built on top of Injective are able to benefit from the security measures that are implemented in the blockchain on the consensus level.”

Recent: Rising global adoption positions crypto perfectly for use in retail

Cointelegraph also had the chance to speak with Konstantin Boyko-Romanovsky, CEO and founder of Allnodes — a non-custodial hosting and staking platform — about the increase in hack incidences. Regarding the main catalysts behind the trend, he said:

“No doubt it will take some time to lower the risk of DeFi hacks. It is unlikely, however, that it will happen overnight. There is a lingering sense of a race in DeFi. Everyone seems to be in a hurry, including the project founders. The market is evolving faster than the speed at which programmers write code. Good players who take every precaution are in the minority.”

He also provided some insight on procedures that would help counteract the problem:

“The code must get better and smart contracts must be thoroughly audited, that’s for sure. In addition, users should be constantly reminded of cautious etiquette online. Identifying any flaws can be attractively incentivized. This, in turn, might promote healthier conduct across a particular protocol.”

The DeFi industry is having a hard time thwarting hack attacks. There is, however, hope that increased monitoring from the authorities and greater cooperation among exchanges will help curb the scourge.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cointelegraph Store: Introducing Bitcoin Pizza Day merch for crypto OGs

May 22, 2022

6 Questions for Sonali Giovino of Defiyield – Cointelegraph Magazine

May 22, 2022

NFTs: Empowering artists and charities to embrace the digital movement

May 22, 2022

Bitcoin targets record 8th weekly red candle while BTC price limits weekend losses

May 22, 2022

Bitcoin Pizza Day rewind: A homage to weird and wonderful BTC purchases

May 22, 2022

Bitcoin stands apart from other crypto, and what that means for US public policy

May 22, 2022
Add A Comment

Leave A Reply Cancel Reply

Top Posts

Cointelegraph Store: Introducing Bitcoin Pizza Day merch for crypto OGs

May 22, 2022

6 Questions for Sonali Giovino of Defiyield – Cointelegraph Magazine

May 22, 2022

NFTs: Empowering artists and charities to embrace the digital movement

May 22, 2022

Subscribe to Updates

Get the latest sports news and analysis about crypto coins and the latest news about domains from Techie Memo.

Advertisement

Your number 1 source for all Cryptocurrency news and analysis. here you can follow all updates and latest rates for all currencies. Visit our about page for more information.

We're social. Connect with us:

Facebook Twitter Instagram YouTube LinkedIn
Top Insights

Cointelegraph Store: Introducing Bitcoin Pizza Day merch for crypto OGs

May 22, 2022

6 Questions for Sonali Giovino of Defiyield – Cointelegraph Magazine

May 22, 2022

NFTs: Empowering artists and charities to embrace the digital movement

May 22, 2022
Get Informed

Subscribe to Updates

Get the latest sports news and analysis about crypto coins.

Facebook Twitter Instagram LinkedIn
  • Guest Post
  • Privacy Policy
  • Terms & Conditions
  • Contact
© 2022 Cryptocurrency Report. Designed by Sawah Dev.

Type above and press Enter to search. Press Esc to cancel.