Hundred Finance $HND Suffers $7 Million Loss in Optimism Hack $OP

Hundred Finance $HND Suffers $7 Million Loss in Optimism Hack $OP

3 Minuten
1 year ago

The Ethereum layer-2 blockchain Optimism witnessed a significant security breach involving multichain lending protocol Hundred Finance. According to the protocol, the losses amount to $7.4 million. Hundred Finance disclosed details of the exploit on April 15. According to the dis...

Hundred Finance $HND Suffers $7 Million Loss in Optimism Hack $OP

The Ethereum layer-2 blockchain Optimism witnessed a significant security breach involving multichain lending protocol Hundred Finance. According to the protocol, the losses amount to $7.4 million.

Hundred Finance disclosed details of the exploit on April 15. According to the disclosure, their team has already contacted the hacker and was collaborating with various security teams to address the incident. Although the protocol did not divulge the attack's exact methodology, blockchain security firm CertiK identified it as a flash loan attack:

#CertiKSkynetAlert 🚨@HundredFinance’s attacker manipulated the exchange rate between ERC-20 tokens and htokens which allowed them to withdraw more tokens than they had originally deposited. The estimated losses of this attack is around $7.4 million. Stay vigilant! https://t.co/1hxAnFoNjj

— CertiK Alert (@CertiKAlert) April 15, 2023

Flash loan attacks involve hackers borrowing large sums through uncollateralized loans from lending protocols, which they then use to manipulate an asset's price on a decentralized finance (DeFi) platform. A flash loan operates as necessary feature in DeFi platforms, allowing users to borrow significant amounts of assets without collateral for short user-specified duration, typically within a single blockchain transaction.

For these cases, the feature enables arbitrage, refinancing and other operations for user profit during the loan period. However, the fees are to be repaid within the same transaction. If not, the transaction is reversed and no funds are disbursed. Flash loans can be useful for legitimate purposes, malicious actors have exploited them to execute flash loan attacks, such as in the case of Hundred Finance.Other examples include the exploits on Avalanche, Belt Finance, BurgerSwap, Euler Finance, and Platypus, among a slew of other DeFi protocols falling victim to the same method. This attack occurs nearly 12 months after Hundred Finance suffered another exploit on the Gnosis Chain, which saw a hacker drain all of the protocol's liquidity through a reentrancy attack and abscond with over $6 million. The same threat actor also extracted funds from the Aave protocol.

CertiK explained that in Hundred's case, the attacker manipulated the exchange rate between ERC-20 tokens and hTOKENS, enabling them to withdraw more tokens than initially deposited. CertiK further elaborated:

"The exchange rate formula was manipulated through Cash value. Cash is the amount of WBTC that the hBTC contract has. The attacker manipulated it by donating large amounts of WBTC to the hToken contract so that the exchange rate goes up."

CertiK disclosed that massive loans were taken under the manipulated exchange rate, and Hundred Finance was working on a postmortem report for the incident.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

 

0 people liked this article

Related Articles

Trading
XRP’s Price Could Climb to $1 if It Breaks Key Resistance Level
XRP has seen an inflow of more than $8 billion in market cap over the last month as the altcoin garnered investor interest. Read more on CE.
1 year ago
1 Minuten
How Much ETH Do You Need To Be a Millionaire By 2030?
Cryptocurrency is here to stay – or at least that’s what this recent rally has been telling us. With Bitcoin hitting a recent Year-To-Date High of $31,000, and Ethereum following in it&...
1 year ago
12 Minuten
Tech-enabled healthcare platform, CloudClinic, unveiled in Lagos
CloudClinic Limited (CCL), a digital healthcare service company, has launched its cloud-based healthcare solution called CloudClinic. This new…
1 year ago
4 Minuten
BRICS currency could diminish the power of US sanctions—here’s what you need to know
Historically, when the United States imposed sanctions on other countries, their economies often crumbled as allies halted business dealings, leading to financial paralysis and a sharp decline in G...
1 year ago
2 Minuten
Coinbase Says UK is “Web3 Innovation Hub” After Doubting DeFi Future In US
After commenting positively on the recent developments in the UK several weeks ago, Coinbase published a rough outline for the future of DeFi in the country. The post Coinbase Says UK is “Web3 Inno...
1 year ago
5 Minuten
ChainLink price analysis: LINK retracing resistance after a breakout at $8
ChainLink price analysis for April 17, 2023, reveals the market following a bullish movement, showing positive momentum, signifying an increment for the LINK market. On April 16, 2023, the value of...
1 year ago
5 Minuten