• bitcoinBitcoin (BTC) $ 78,203.00
  • ethereumEthereum (ETH) $ 2,178.93
  • tetherTether (USDT) $ 0.999526
  • bnbBNB (BNB) $ 654.95
  • xrpXRP (XRP) $ 1.41
  • usd-coinUSDC (USDC) $ 0.999841
  • solanaSolana (SOL) $ 86.45
  • tronTRON (TRX) $ 0.352670
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.109620
  • whitebitWhiteBIT Coin (WBT) $ 57.63
  • usdsUSDS (USDS) $ 0.999734
  • hyperliquidHyperliquid (HYPE) $ 40.91
  • cardanoCardano (ADA) $ 0.255625
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 9.93
  • bitcoin-cashBitcoin Cash (BCH) $ 417.00
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • zcashZcash (ZEC) $ 500.49
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 384.95
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • chainlinkChainlink (LINK) $ 9.70
  • canton-networkCanton (CC) $ 0.149887
  • the-open-networkToncoin (TON) $ 1.94
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.152199
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999640
  • litecoinLitecoin (LTC) $ 56.22
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • suiSui (SUI) $ 1.07
  • memecoreMemeCore (M) $ 3.12
  • avalanche-2Avalanche (AVAX) $ 9.31
  • wethWETH (WETH) $ 2,268.37
  • hedera-hashgraphHedera (HBAR) $ 0.091973
  • rainRain (RAIN) $ 0.007330
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 0.999786
  • crypto-com-chainCronos (CRO) $ 0.071546
  • global-dollarGlobal Dollar (USDG) $ 0.999747
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,533.56
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bittensorBittensor (TAO) $ 273.29
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • uniswapUniswap (UNI) $ 3.50
  • polkadotPolkadot (DOT) $ 1.27
  • pax-goldPAX Gold (PAXG) $ 4,533.11
  • mantleMantle (MNT) $ 0.644022
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.061338
  • nearNEAR Protocol (NEAR) $ 1.49
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • falcon-financeFalcon USD (USDF) $ 0.997961
  • htx-daoHTX DAO (HTX) $ 0.000002
  • okbOKB (OKB) $ 83.27
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.668890
  • pi-networkPi Network (PI) $ 0.160665
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • ondo-financeOndo (ONDO) $ 0.347038
  • skySky (SKY) $ 0.069701
  • pepePepe (PEPE) $ 0.000004
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • usddUSDD (USDD) $ 0.999687
  • internet-computerInternet Computer (ICP) $ 2.64
  • ethereum-classicEthereum Classic (ETC) $ 9.00
  • bitget-tokenBitget Token (BGB) $ 2.01
  • aaveAave (AAVE) $ 90.44
  • bfusdBFUSD (BFUSD) $ 0.999103
  • quant-networkQuant (QNT) $ 83.92
  • morphoMorpho (MORPHO) $ 1.78
  • kucoin-sharesKuCoin (KCS) $ 8.03
  • usdtbUSDtb (USDTB) $ 0.999403
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • united-stablesUnited Stables (U) $ 0.999599
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • cosmosCosmos Hub (ATOM) $ 1.99
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.08
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • algorandAlgorand (ALGO) $ 0.111398
  • ethenaEthena (ENA) $ 0.107057
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.090735
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.87
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • render-tokenRender (RENDER) $ 1.84
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • kaspaKaspa (KAS) $ 0.034365
  • nexoNEXO (NEXO) $ 0.858927
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • stable-2​​Stable (STABLE) $ 0.036997
  • worldcoin-wldWorldcoin (WLD) $ 0.242013
  • wbnbWrapped BNB (WBNB) $ 759.61
  • flare-networksFlare (FLR) $ 0.009151
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.958925
  • justJUST (JST) $ 0.090771
  • filecoinFilecoin (FIL) $ 0.976786
  • gatechain-tokenGate (GT) $ 7.13
  • arbitrumArbitrum (ARB) $ 0.120442
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • jupiter-exchange-solanaJupiter (JUP) $ 0.200969
  • xdce-crowd-saleXDC Network (XDC) $ 0.032423
  • pump-funPump.fun (PUMP) $ 0.001751
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • beldexBeldex (BDX) $ 0.079097
  • dexeDeXe (DEXE) $ 12.99
  • venice-tokenVenice Token (VVV) $ 13.02
  • vechainVeChain (VET) $ 0.006869
  • ghoGHO (GHO) $ 0.999350
  • usual-usdUsual USD (USD0) $ 0.998287
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • ousgOUSG (OUSG) $ 115.25
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • bonkBonk (BONK) $ 0.000006
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • hash-2Provenance Blockchain (HASH) $ 0.010366
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008486
  • midnight-3Midnight (NIGHT) $ 0.032006
  • clbtcclBTC (CLBTC) $ 76,920.00
  • yldsYLDS (YLDS) $ 0.999842
  • dashDash (DASH) $ 41.46
  • official-trumpOfficial Trump (TRUMP) $ 2.18
  • a7a5A7A5 (A7A5) $ 0.012732
  • true-usdTrueUSD (TUSD) $ 0.999387
  • kite-2Kite (KITE) $ 0.215226
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • chilizChiliz (CHZ) $ 0.046386
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.47
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.726901
  • tbtctBTC (TBTC) $ 70,942.00
  • apxusdapxUSD (APXUSD) $ 0.999879
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • injective-protocolInjective (INJ) $ 4.64
  • euro-coinEURC (EURC) $ 1.16
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.197016
  • blockstackStacks (STX) $ 0.241315
  • edgexedgeX (EDGE) $ 1.25
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000078
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • sei-networkSei (SEI) $ 0.062486
  • humanityHumanity (H) $ 0.232757
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.17
  • adi-tokenADI (ADI) $ 4.01
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • unibaseUnibase (UB) $ 0.163821
  • usdgoUSDGO (USDGO) $ 0.999723
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.395781
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • aerodrome-financeAerodrome Finance (AERO) $ 0.421405
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997663
  • build-onBUILDon (B) $ 0.392670
  • tezosTezos (XTZ) $ 0.357414
  • usxUSX (USX) $ 0.999629
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • siren-2Siren (SIREN) $ 0.520443
  • sun-tokenSun Token (SUN) $ 0.019461
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • celestiaCelestia (TIA) $ 0.402276
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • curve-dao-tokenCurve DAO (CRV) $ 0.241229
  • labLAB (LAB) $ 4.70
  • spx6900SPX6900 (SPX) $ 0.372497
  • billions-networkBillions Network (BILL) $ 0.142257
  • kinesis-goldKinesis Gold (KAU) $ 144.19
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • conflux-tokenConflux (CFX) $ 0.065023
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • monadMonad (MON) $ 0.027905
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • ethgas-2ETHGas (GWEI) $ 0.155598
  • ether-fiEther.fi (ETHFI) $ 0.391447
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • layerzeroLayerZero (ZRO) $ 1.29
  • gnosisGnosis (GNO) $ 122.40
  • zebec-networkZebec Network (ZBCN) $ 0.003278
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • skyaiSkyAI (SKYAI) $ 0.318927
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • bitcoin-svBitcoin SV (BSV) $ 15.77
  • doublezeroDoubleZero (2Z) $ 0.090545
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • hastra-primePRIME (PRIME) $ 1.04
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Moonwell is battling a governance attack where attempts control of around $1.08M in assets

0 0


Moonwell, the decentralized lending protocol operating on Moonriver, is fighting an active attempt by an unknown attacker to seize administrative control of its smart contracts through a manipulated governance vote.

The proposal, if executed, would hand control of seven lending markets, holding around $1.08 million in user assets, to a wallet that is reportedly designed to drain them.

How did an $1,808 bet threaten a $1 million protocol?

On March 24, the attacker funded a deployer wallet and used it to purchase 40.17 million MFAM tokens, Moonwell’s native governance token, from the SolarBeam decentralized exchange on Moonriver for 1,600 MOVR, worth $1,808.

The attacker then deployed a contract containing purpose-built exploit logic and submitted Proposal #74, titled “MIP-R39: Protocol Recovery – Admin Migration.”

This proposal calls for the transfer of the administrative control of all seven lending markets, the Comptroller, and the Oracle to the attacker’s contract.

Blockful, a governance security platform for decentralized autonomous organizations (DAOs), wrote that the proposal is clearly an attack, adding that the attacker’s contract already contained the transactions needed to drain all markets upon execution.

At the snapshot block, the attacker’s 40.17 million MFAM exceeded the protocol’s 40 million quorum threshold. The implied return, if successful, would have been approximately 597 times the cost of the attack.

The funds exposed across Moonwell’s Moonriver markets total about $1.08 million. This attack is coming roughly a month after Moonwell suffered a loss of about $1.8 million in bad debt, which is attributed to a misconfigured oracle for its Coinbase-wrapped ETH (cbETH) market.

Can Moonwell stop the vote, and what happens next?

Community voting data as of 26 March shows 66.7% of cast votes opposing the proposal. The vote closes on 27 March at 10:28 UTC, leaving a narrow window for action.

Snapshot of the Moonwell vote. Source: Moonwell governance forum

Moonwell’s governance lead has asked whoever is behind the proposal to come forward and provide more clarity by sharing details on the intent of the proposal and a technical explanation of the changes. The lead also asked the proposer to engage with the community in the forum.

Until the required context is provided, Moonwell advises community members to exercise caution when reviewing or voting on this proposal, avoid supporting proposals that lack sufficient transparency, and wait for further clarification before taking action.

So far, the number of votes against the proposal indicates that Moonwell is gaining the upper hand.

Blockful outlined two viable defense strategies to mitigate the proposal from being passed. The first is mobilizing sufficient “Against” votes before the deadline. However, this move is also complicated due to the fact that voting power is snapshotted at the proposal’s start block, meaning MFAM purchased after the attack carries no weight on this vote.

Blockful noted that the proposer of the prior legitimate proposal holds at least 48.8 million voting power in staked MFAM, enough to defeat the proposal outright with a single transaction.

The second and, according to Blockful, safer option is the Break Glass Guardian, a 2-of-3 Gnosis Safe multisig that can bypass the protocol’s timelock entirely and transfer admin back to the legitimate governance address, rendering the attacker’s proposal a no-op even if it passes.

If the proposal passes without intervention, the attacker could queue execution as early as 27 March, with a 24-hour timelock expiring on 28 March, the earliest date all funds could be drained.

There have been a series of governance attacks in the past that left some DeFi platforms with major losses. A notable incident occurred in April 2022 with the Beanstalk stablecoin protocol, which lost $181 million to a flash loan-based governance attack that exploited the same fundamental vulnerability with temporary voting power with immediate execution.

In 2024, a faction of Compound Finance investors submitted an unsolicited proposal to redirect 5% of the COMP treasury to a multisig they controlled, prompting a community backlash.



Source link

Leave A Reply

Your email address will not be published.