Sturdy Finance DeFi Hacked

Sturdy Finance DeFi Hacked


Good day everyone,

I hope you are all well are having an excellent day, welcome to CryptoGod-1’s blog on all things crypto. Today I will be looking at the recent exploit which saw more than $800,000 taken from the Sturdy Finance DeFi Protocol.

 

 

Sturdy Finance Hack

On the 12th of June the DeFi protocol Sturdy Finance got the dreaded Twitter alert from @peckshield, informing them that they have been exploited and 442.6 ETH had been sent to Tornado Cash. This equates to around $800,000 or so and is a massive taking for the hacker, with the impact felt by the protocol immediately as they paused markets and assured community members that additional funds are safe.

On the 13th of June Sturdy Finance founder Sam Forman noted that his team had informed the exploiter that no further action will be taken against the hackers if the money is returned. They also made it clear that they are offering a $100,000 bounty if all funds are returned to the protocol, giving a nice incentive for the hackers to keep roughly 1/8th of what they managed to take from the protocol.

Whether or not any funds will be returned remains to be seen, but it will be interesting to watch the developments. There have been mixed results in the past with offering bounties for hacked funds, as some exploiters decide to agree a deal while other refrain from it and keep the funds for themselves. Examples of this have included Euler Finance protocol seeing $100 million returned back in March, while Arbitrum based Jimbos Protocol failed is getting $7.5 million returned after a hack in May.

In terms of the exploit itself, it is expected that a Read-only Reentrancy is the cause of the problem. Twitter user @0xCygaar made a detailed explanation of what exactly a Read-only Reentrancy is, and how it works. He explains in detail how the destructive attack works, basically outlining how a function makes an external call to another untrusted contract. The untrusted contract then makes a recursive call back to the original function in an attempt to drain funds. Once the contract fails to update its state before sending funds, the attacker is then able to continuously call the withdraw function to drain the contract’s funds, which in this case led to the 442 ETH being taken from the protocol. The thread with further explanation on the process is available in the tweet below.

 

 

 

More tough times in the DeFi space, with a large amount of ETH taken through an exploit. Users have been reassured that additional funds are in place and that they have no reason to be fearful, although anybody who has watched the space over the past couple of years will be feeling apprehensive over the sheer amount of hacks taking place. How this gets resolved will be very interesting, and certainly something to keep an eye on.

Have a great day.

Peace. CryptoGod-1.

 

Referral Links and Follow Me:

Linktree

How do you rate this article?

26


cryptogod-1
cryptogod-1

Writer, designer, creator, and life enthusiast. I love to read and write and enjoy sharing my passion for crypto, sports, literature and everything and anything I can enjoy in life.


CryptoGod-1 : Crypto & Blockchain
CryptoGod-1 : Crypto & Blockchain

Enthusiast here looking to share my ideas, thoughts, analysis, and experience when it comes to all things crypto

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?