{"id":50036,"date":"2023-05-02T04:11:51","date_gmt":"2023-05-02T04:11:51","guid":{"rendered":"https:\/\/egrowonline.com\/?p=50036"},"modified":"2023-05-02T04:11:51","modified_gmt":"2023-05-02T04:11:51","slug":"level-finance-confirms-1m-exploit-due-to-buggy-smart-contract","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=50036","title":{"rendered":"Level Finance confirms $1M exploit due to buggy smart contract"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div data-v-2ab31f4e=\"\">\n<p>Decentralized exchange Level Finance has experienced a security breach allowing an attacker to steal more than $1 million of the exchange\u2019s native Level Finance (LVL) token.\u00a0<\/p>\n<p>Level Finance informed its 20,000 Twitter followers that more than 214,000 of the exchange\u2019s LVL tokens had been drained and swapped into 3,345 Binance Coin (<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/binance-coin-price-index\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/binance-coin-price-index\" rel=\"noopener\">BNB<\/a>), with an approximate value of $1.01 million.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">An exploit targeted our Referral Controller Contract.<\/p>\n<p>&#8211; 214k LVL tokens drained to exploiters address.<br \/>&#8211; Attacker swapped LVL to 3,345 BNB<br \/>&#8211; Exploit was isolated from other contracts.<br \/>&#8211; Fix to be deployed in 12 Hrs.<br \/>&#8211; LP&#8217;s and DAO treasury UNAFFECTED. <\/p>\n<p>More details to follow.<\/p>\n<p>\u2014 LEVEL Finance #RealYield (@Level__Finance) <a target=\"_blank\" href=\"https:\/\/twitter.com\/Level__Finance\/status\/1653140756540825638?ref_src=twsrc%5Etfw\" rel=\"noopener\">May 1, 2023<\/a><\/p><\/blockquote>\n<p>According to blockchain security firm Peckshield, Level Finance\u2019s \u201cLevelReferralControllerV2\u201d smart contract contained a bug that allowed for \u201crepeated referral claims\u201d from the same epoch. This was confirmed by Level Finance in a later statement made on Discord. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">It seems the <a target=\"_blank\" href=\"https:\/\/twitter.com\/Level__Finance?ref_src=twsrc%5Etfw\" rel=\"noopener\">@Level__Finance<\/a>&#8216;s LevelReferralControllerV2 contract has a bug that allows for repeated referral claims from the same epoch. So far 214k LVLs have been drained and swapped  into  3,345 BNB (~1M)<\/p>\n<p>Here is an example hack tx: <a target=\"_blank\" href=\"https:\/\/t.co\/isqHhzFk1Z\" rel=\"noopener\">https:\/\/t.co\/isqHhzFk1Z<\/a> <a target=\"_blank\" href=\"https:\/\/t.co\/ikOWx2ezf6\" rel=\"noopener\">https:\/\/t.co\/ikOWx2ezf6<\/a> <a target=\"_blank\" href=\"https:\/\/t.co\/wlr5bFFf0R\" rel=\"noopener\">pic.twitter.com\/wlr5bFFf0R<\/a><\/p>\n<p>\u2014 PeckShield Inc. (@peckshield) <a target=\"_blank\" href=\"https:\/\/twitter.com\/peckshield\/status\/1653149493133729794?ref_src=twsrc%5Etfw\" rel=\"noopener\">May 1, 2023<\/a><\/p><\/blockquote>\n<p>Meanwhile, \u00a0<a target=\"_blank\" href=\"https:\/\/bscscan.com\/address\/0x977087422C008233615b572fBC3F209Ed300063a\" rel=\"noopener nofollow\">data<\/a> from Binance chain explorer BSC Scan, the V2 controller contract shows multiple calls of the \u201cclaim multiple\u201d function over the past 48 hours.<\/p>\n<p>At the time of writing, the <a target=\"_blank\" href=\"https:\/\/bscscan.com\/address\/0x9f00fbd6c095d2c542687ed5afb68d9c3fb2f464#code\" rel=\"noopener nofollow\">implementation<\/a> of the contract does not appear to have been altered since the advent of the attack, however Level Finance says that it will deploy a new implementation of the referral contract within the next 12 hours.<\/p>\n<p>The exchange also noted that its liquidity pools and related DAOs remain unaffected by the attack. <\/p>\n<p><strong>Related: <\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/april-s-crypto-scams-exploits-and-hacks-lead-to-103m-lost-certik\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/april-s-crypto-scams-exploits-and-hacks-lead-to-103m-lost-certik\/amp\" rel=\"noopener\"><strong>April\u2019s crypto scams, exploits and hacks lead to $103M lost \u2014 CertiK<\/strong><\/a><\/p>\n<p>According to @DeDotFiSecurity on Twitter, the team <a target=\"_blank\" href=\"https:\/\/twitter.com\/DeDotFiSecurity\/status\/1653125030874587143\" rel=\"noopener nofollow\">says<\/a> that it has \u201ctemporarily shut down the referral program,\u201d which has stopped the exploit. <\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2023-05\/c090689c-c0f9-4e90-8097-b538713fe088.png\" \/><\/figure>\n<p>On Discord, Level Finance said that the exploit had been isolated from other exploits and that users of the exchange should \u201cstand by for a full post mortem.\u201d <\/p>\n<p><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/ethereums-layer-2-zk-rollups-can-become-interoperable\/\" rel=\"noopener\"><strong><em>Magazine: Here\u2019s how Ethereum\u2019s ZK-rollups can become interoperable<\/em><\/strong><\/a><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/level-finance-confirms-1m-exploit-due-to-buggy-smart-contract\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Decentralized exchange Level Finance has experienced a security breach allowing an attacker to steal more than $1 million of the exchange\u2019s native Level Finance (LVL) token.\u00a0 Level Finance informed its 20,000 Twitter followers that more than 214,000 of the exchange\u2019s LVL tokens had been drained and swapped into 3,345 Binance Coin (BNB), with an approximate [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":50037,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[38],"tags":[13207,1721,185,132,1802,28,664,1242],"class_list":["post-50036","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-buggy","tag-confirms","tag-contract","tag-due","tag-exploit","tag-finance","tag-level","tag-smart"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/05\/cbf3a87b-8db5-47d9-bf0b-8722e57c6253.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/50036","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=50036"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/50036\/revisions"}],"predecessor-version":[{"id":50038,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/50036\/revisions\/50038"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/50037"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=50036"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=50036"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=50036"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}