• bitcoinBitcoin (BTC) $ 80,506.00
  • ethereumEthereum (ETH) $ 2,268.38
  • tetherTether (USDT) $ 0.999626
  • xrpXRP (XRP) $ 1.43
  • bnbBNB (BNB) $ 653.74
  • usd-coinUSDC (USDC) $ 0.999676
  • solanaSolana (SOL) $ 94.53
  • tronTRON (TRX) $ 0.348119
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.108714
  • whitebitWhiteBIT Coin (WBT) $ 59.02
  • usdsUSDS (USDS) $ 0.999825
  • cardanoCardano (ADA) $ 0.269282
  • hyperliquidHyperliquid (HYPE) $ 40.27
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 10.17
  • zcashZcash (ZEC) $ 550.73
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • bitcoin-cashBitcoin Cash (BCH) $ 439.06
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 10.19
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 399.51
  • the-open-networkToncoin (TON) $ 2.36
  • canton-networkCanton (CC) $ 0.156691
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.162379
  • suiSui (SUI) $ 1.23
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 0.998917
  • litecoinLitecoin (LTC) $ 57.19
  • daiDai (DAI) $ 0.999356
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 3.24
  • avalanche-2Avalanche (AVAX) $ 9.74
  • hedera-hashgraphHedera (HBAR) $ 0.093202
  • wethWETH (WETH) $ 2,268.37
  • ethena-usdeEthena USDe (USDE) $ 0.999484
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007510
  • usdt0USDT0 (USDT0) $ 0.998824
  • global-dollarGlobal Dollar (USDG) $ 0.999652
  • crypto-com-chainCronos (CRO) $ 0.079667
  • paypal-usdPayPal USD (PYUSD) $ 0.999854
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • bittensorBittensor (TAO) $ 307.31
  • tether-goldTether Gold (XAUT) $ 4,671.96
  • uniswapUniswap (UNI) $ 3.73
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • mantleMantle (MNT) $ 0.669060
  • polkadotPolkadot (DOT) $ 1.31
  • pax-goldPAX Gold (PAXG) $ 4,669.47
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.066710
  • nearNEAR Protocol (NEAR) $ 1.54
  • ondo-financeOndo (ONDO) $ 0.395452
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • pi-networkPi Network (PI) $ 0.171369
  • okbOKB (OKB) $ 85.05
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.998523
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • internet-computerInternet Computer (ICP) $ 3.22
  • skySky (SKY) $ 0.074820
  • pepePepe (PEPE) $ 0.000004
  • aster-2Aster (ASTER) $ 0.668259
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 2.11
  • usddUSDD (USDD) $ 0.999801
  • ethereum-classicEthereum Classic (ETC) $ 9.33
  • aaveAave (AAVE) $ 95.47
  • bfusdBFUSD (BFUSD) $ 0.999207
  • morphoMorpho (MORPHO) $ 2.07
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • kucoin-sharesKuCoin (KCS) $ 8.32
  • algorandAlgorand (ALGO) $ 0.122925
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • ethenaEthena (ENA) $ 0.120694
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.100304
  • quant-networkQuant (QNT) $ 71.43
  • kaspaKaspa (KAS) $ 0.037891
  • united-stablesUnited Stables (U) $ 1.00
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • cosmosCosmos Hub (ATOM) $ 1.99
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.08
  • render-tokenRender (RENDER) $ 1.88
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.87
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.909697
  • stable-2​​Stable (STABLE) $ 0.040237
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • worldcoin-wldWorldcoin (WLD) $ 0.264268
  • siren-2Siren (SIREN) $ 1.18
  • wbnbWrapped BNB (WBNB) $ 759.61
  • aptosAptos (APT) $ 1.07
  • filecoinFilecoin (FIL) $ 1.08
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • arbitrumArbitrum (ARB) $ 0.135370
  • gatechain-tokenGate (GT) $ 7.32
  • venice-tokenVenice Token (VVV) $ 16.79
  • justJUST (JST) $ 0.089847
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • jupiter-exchange-solanaJupiter (JUP) $ 0.227425
  • flare-networksFlare (FLR) $ 0.008648
  • pump-funPump.fun (PUMP) $ 0.001949
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • build-onBUILDon (B) $ 0.660132
  • vechainVeChain (VET) $ 0.007435
  • xdce-crowd-saleXDC Network (XDC) $ 0.032236
  • bonkBonk (BONK) $ 0.000007
  • beldexBeldex (BDX) $ 0.079777
  • ousgOUSG (OUSG) $ 115.21
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.009628
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • dexeDeXe (DEXE) $ 12.62
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • ghoGHO (GHO) $ 0.999428
  • midnight-3Midnight (NIGHT) $ 0.034708
  • dashDash (DASH) $ 45.28
  • clbtcclBTC (CLBTC) $ 76,920.00
  • skyaiSkyAI (SKYAI) $ 0.567337
  • usual-usdUsual USD (USD0) $ 0.998144
  • hash-2Provenance Blockchain (HASH) $ 0.010431
  • official-trumpOfficial Trump (TRUMP) $ 2.31
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000097
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.812772
  • usdtbUSDtb (USDTB) $ 0.999467
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • yldsYLDS (YLDS) $ 0.999940
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.224580
  • tbtctBTC (TBTC) $ 70,942.00
  • a7a5A7A5 (A7A5) $ 0.012924
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.53
  • humanityHumanity (H) $ 0.267242
  • true-usdTrueUSD (TUSD) $ 0.999363
  • blockstackStacks (STX) $ 0.260687
  • sei-networkSei (SEI) $ 0.070084
  • injective-protocolInjective (INJ) $ 4.64
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • euro-coinEURC (EURC) $ 1.17
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • edgexedgeX (EDGE) $ 1.28
  • aerodrome-financeAerodrome Finance (AERO) $ 0.472815
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • chilizChiliz (CHZ) $ 0.042268
  • kite-2Kite (KITE) $ 0.189094
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • curve-dao-tokenCurve DAO (CRV) $ 0.280628
  • adi-tokenADI (ADI) $ 4.03
  • usdgoUSDGO (USDGO) $ 0.999858
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • billions-networkBillions Network (BILL) $ 0.172578
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • tezosTezos (XTZ) $ 0.381369
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.18
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998530
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • spx6900SPX6900 (SPX) $ 0.438598
  • unibaseUnibase (UB) $ 0.161525
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • celestiaCelestia (TIA) $ 0.429984
  • sun-tokenSun Token (SUN) $ 0.020437
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.384553
  • apxusdapxUSD (APXUSD) $ 0.999956
  • usxUSX (USX) $ 0.999796
  • ether-fiEther.fi (ETHFI) $ 0.439012
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • layerzeroLayerZero (ZRO) $ 1.46
  • monadMonad (MON) $ 0.030674
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • kinesis-goldKinesis Gold (KAU) $ 151.78
  • doublezeroDoubleZero (2Z) $ 0.102981
  • noonNoon (NOON) $ 0.751949
  • pendlePendle (PENDLE) $ 2.07
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • zebec-networkZebec Network (ZBCN) $ 0.003552
  • labLAB (LAB) $ 4.56
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • gnosisGnosis (GNO) $ 129.03
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • flokiFLOKI (FLOKI) $ 0.000035
  • bitcoin-svBitcoin SV (BSV) $ 16.86
  • jasmycoinJasmyCoin (JASMY) $ 0.006736
  • lido-daoLido DAO (LDO) $ 0.389880
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Abracadabra $1.8m hack repeats earlier fork flaw, Hacken reveals

0 1


DeFi protocol Abracadabra lost $1.8 million after an attacker exploited a simple logic mistake in its batch function. Analysts at Hacken say the attacker already laundered funds via Tornado Cash.

Summary
  • Abracadabra lost almost $2 million after an attacker exploited a simple logic mistake in its batch function, similar to an attack on a forked project days earlier.
  • The attacker bypassed a safety flag meant to check if borrowers had enough collateral and drained six Cauldrons in one go before swapping the stolen MIM for ETH and routing it through Tornado Cash.
  • This isn’t the first time Abracadabra’s code has been targeted, but the incident highlights how a small unimplemented function can let hackers take advantage, even when the same flaw was visible in a fork.

In early October, Abracadabra, a DeFi lending protocol that lets people borrow its stablecoin MIM using deposited tokens as collateral and suffered multiple hacker attacks before, this time once again lost about $1.8 million after an attacker used a simple logic mistake in the protocol’s batch function to borrow without putting up any collateral, in the same way a forked project had been hit just days before, analysts at blockchain security firm Hacken said in a research note shared with crypto.news.

Abracadabra launched as a way for people to use interest-bearing tokens as collateral and borrow a U.S. dollar-pegged token called Magic Internet Money, or MIM. The system is built around two pieces: Cauldrons, which handle the borrowing rules, and DegenBox, the shared vault that actually holds tokens. In short: you put up collateral in a Cauldron, and the DegenBox keeps track of the money behind the scenes.

You might also like: PancakeSwap’s Chinese X account hacked to promote meme coin

The short version of what went wrong is this: a safety flag that’s supposed to force a final check on whether a borrower actually has collateral got turned off inside a single transaction. As Hacken’s report lays out, the attacker “exploited a logic flaw in Abracadabra’s cook() function where they could borrow MIM tokens and then immediately reset the validation flag that was supposed to check if they had enough collateral.” That allowed a one-shot, uncollateralized borrow across multiple Cauldrons.

Under the microscope

Here’s how the flow worked, in plain terms. Abracadabra uses a batched function called cook() so users can do several actions in one transaction. Say, deposit collateral and borrow in the same click. One of those actions, like the “borrow” step, sets a flag named needsSolvencyCheck to true, meaning “at the end of this transaction, check that the borrower is safe.”

Abracadabra $1.8m hack repeats earlier fork flaw, Hacken reveals - 1

One of the vulnerable Cauldrons | Source: Hacken

But another action that can be run inside the same batch calls “_additionalCookAction(…).” As Hacken points out, that function was declared as “virtual” and never was implemented, so by default it returned an empty object where everything was set to false, including that needsSolvencyCheck flag.

As a result, the attacker called the borrow action, then called the default action that reset the flag, and at the end, the protocol never checked solvency.

The analysts say the attacker hit six Cauldrons in one go, taking roughly 1.79 million MIM and swapping it for ETH. Attackers exploited vulnerability, and systematically went through six different Cauldrons and drained each one “using the same technique with a dedicated cook function call,” the analysts explained.

Laundered funds from the Abracadabra hack | Source: Hacken

After swapping, the attacker routed funds through Tornado Cash, a crypto mixing protocol, mostly 10 ETH each, sending gradually over the following day.

And this isn’t the first time Abracadabra’s CauldronV4 code has been involved in trouble. Other incidents earlier this year used different edge cases in the same family of contracts. What’s interesting now is how fast the forked deployment reacted.

According to the report, a fork called Synnax paused or un-whitelisted its CauldronV4 master on its own DegenBox days before the Abracadabra drain, so basically the fork team pulled the emergency brake after spotting the same weak pattern, suggesting that the risk was visible to teams watching the code, if not fixed.

Read more: Bitcoin can be hacked, quantum’s biggest breakthrough proves it’s not if but when



Source link

Leave A Reply

Your email address will not be published.