{"id":55502,"date":"2023-07-11T07:24:37","date_gmt":"2023-07-11T07:24:37","guid":{"rendered":"https:\/\/egrowonline.com\/?p=55502"},"modified":"2023-07-11T07:24:37","modified_gmt":"2023-07-11T07:24:37","slug":"arcadia-finance-hacker-used-reentrancy-exploit-team-demands-return-of-funds","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=55502","title":{"rendered":"Arcadia Finance hacker used reentrancy exploit, team demands return of funds"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=840\/https:\/\/s3.cointelegraph.com\/uploads\/2023-07\/53d30175-f0f6-4924-adb5-bb2fb76338c1.jpg\" \/><\/p>\n<div data-v-7c7881ea=\"\">\n<p>The Arcadia Finance attacker used a reentrancy exploit to drain $455,000 from the decentralized finance (DeFi) protocol, according to a July 10 post-mortem report <a target=\"_blank\" href=\"https:\/\/arcadiafinance.medium.com\/post-mortem-72e9d24a79b0\" rel=\"noopener nofollow\">issued<\/a> by the app\u2019s development team. A \u201creentrancy exploit\u201d is a bug that allows an attacker to \u201creenter\u201d a contract or interrupt it during a multi-step process, preventing the process from being completed correctly.<\/p>\n<p>The team has sent a message to the attacker demanding the return of funds within 24 hours and threatening police action if the hacker fails to comply.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Post Mortem of ongoing situation, providing a technical overview and sharing more information on next steps.<a target=\"_blank\" href=\"https:\/\/t.co\/NPNbbSzKBQ\" rel=\"noopener\">https:\/\/t.co\/NPNbbSzKBQ<\/a><\/p>\n<p>\u2014 Arcadia Finance (@ArcadiaFi) <a target=\"_blank\" href=\"https:\/\/twitter.com\/ArcadiaFi\/status\/1678446942446034946?ref_src=twsrc%5Etfw\" rel=\"noopener\">July 10, 2023<\/a><\/p><\/blockquote>\n<p>Arcadia Finance was <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/arcadia-finance-hacked-on-ethereum-and-optimism-for-455k\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/arcadia-finance-hacked-on-ethereum-and-optimism-for-455k\/amp\" rel=\"noopener\">exploited on the morning of July 10<\/a> and drained of $455,000 worth of crypto. A preliminary report from blockchain security firm PeckShield stated that the attacker had used a \u201clack of untrusted input validation\u201d in the app\u2019s contracts to drain the funds. The Arcadia team had denied this, stating that PeckShield\u2019s analysis was mistaken. However, the team did not explain what it thought the cause was at the time.<\/p>\n<p>The new Arcadia report stated that the app\u2019s \u201cliquidateVault()\u201d function did not contain a reentrancy check. This allowed the attacker to call the function before a health check had been completed but after the attacker had withdrawn funds. As a result, the attacker could borrow funds and not pay them back, draining them from the protocol.<\/p>\n<p>The team has now paused the contracts and is working on a patch to close the loophole.<\/p>\n<p>The attacker first took a flash loan from Aave for $20,672 worth of USD Coin (<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/usdc-price-index\" rel=\"noopener\">USDC<\/a>) and deposited it into an Arcadia vault. Next, the hacker used this vault collateral to borrow $103,210 USDC from an Arcadia liquidity pool. This was accomplished through a \u201cdoActionWithLeverage()\u201d function that allows users to borrow funds only if their account can remain healthy by the end of the block. <\/p>\n<p>The attacker deposited the $103,210 into the vault, bringing the total funds to $123,882. The hacker then withdrew all funds, leaving the vault with no assets and $103,210 in debt.<\/p>\n<p>Theoretically, this should have caused all actions to revert, as withdrawing the funds should have caused the account to fail a health check. However, the attacker used a malicious contract to call liquidateVault() before the health check could commence. The vault was liquidated, eliminating all of its debts. As a result, it was left with zero assets and zero liabilities, allowing it to pass the health check.<\/p>\n<p>Since the account passed the health check after all transactions were concluded, none of the transactions reverted, and the pool was drained of $103,210. The attacker paid back the loan from Aave within the same block. The hacker repeated this exploit multiple times, draining a total of $455,000 from pools on Optimism and Ethereum.<\/p>\n<p>In its report, Arcadia\u2019s team pushed back against claims that the exploit was caused by untrusted input, stating that this alleged vulnerability was not \u201cthe core issue\u201d in the attack.<\/p>\n<p><em><strong>Related: <\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/circle-tether-freezes-over-65m-in-assets-transferred-from-multichain\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/circle-tether-freezes-over-65m-in-assets-transferred-from-multichain\/amp\" rel=\"noopener\"><strong>Circle, Tether freezes over $65M in assets transferred from Multichain<\/strong><\/a><\/em><\/p>\n<p>The Arcadia team <a target=\"_blank\" href=\"https:\/\/optimistic.etherscan.io\/tx\/0xc598bf554a738ebeec234930e4bffe1c7a4266a1bbbdfae63b6951e448a17fc5\" rel=\"noopener nofollow\">posted<\/a> a message to the attacker using the input data field of an Optimism transaction, stating:<\/p>\n<blockquote><p>\u201cWe understand you are involved with Arcadia Finance\u2019s exploit. We\u2019re actively working with security experts and law enforcement. Your TC deposits and withdrawals on BNB were a bit too fast, it\u2019s hard to hide your identity online these days. We will escalate this with law enforcement in absence of any funds being returned within the next 24 hours.\u201d<\/p><\/blockquote>\n<p>In its report, Arcadia claimed it had found some promising leads for tracking down the attacker. \u201cBesides obtaining addresses linked to centralized exchanges, we also uncovered links to previous exploits of other protocols,\u201d the report said. \u201cThe team is investigating both on-chain and off-chain data to the fullest extent and has multiple leads.\u201d<\/p>\n<p>Exploits and scams have been a continuing problem in the DeFi space in 2023. A July 5 report from CertiK stated that over $300 million was\u00a0<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/crypto-hacks-and-exploits-snatch-over-300m-in-q2-2023-report\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/crypto-hacks-and-exploits-snatch-over-300m-in-q2-2023-report\/amp\" rel=\"noopener\">lost due to exploits<\/a> in the second quarter of the year.<\/p>\n<p><em><strong><em><a target=\"_blank\" href=\"https:\/\/mint.cointelegraph.com\/?url=https:\/\/cointelegraph.com\/news\/arcadia-finance-hacker-used-reentrancy-exploit-team-demands-return-of-funds&amp;utm_source=cointelegraph_com&amp;utm_medium=appendix&amp;utm_campaign=articles\" data-amp=\"https:\/\/mint-cointelegraph-com.cdn.ampproject.org\/c\/s\/mint.cointelegraph.com\/?url=https:\/\/cointelegraph.com\/news\/arcadia-finance-hacker-used-reentrancy-exploit-team-demands-return-of-funds&amp;utm_source=cointelegraph_com&amp;utm_medium=appendix&amp;utm_campaign=articles\/amp\" rel=\"noopener\">Collect this article as an NFT<\/a><\/em><\/strong><em> to preserve this moment in history and show your support for independent journalism in the crypto space.<\/em><\/em><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/arcadia-finance-hacker-used-reentrancy-exploit-team-demands-return-of-funds\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Arcadia Finance attacker used a reentrancy exploit to drain $455,000 from the decentralized finance (DeFi) protocol, according to a July 10 post-mortem report issued by the app\u2019s development team. A \u201creentrancy exploit\u201d is a bug that allows an attacker to \u201creenter\u201d a contract or interrupt it during a multi-step process, preventing the process from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":55503,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[41],"tags":[16413,3102,1802,28,1351,3288,16414,401,4329],"class_list":["post-55502","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ethereum","tag-arcadia","tag-demands","tag-exploit","tag-finance","tag-funds","tag-hacker","tag-reentrancy","tag-return","tag-team"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/07\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjMtMDcvNTNkMzAxNzUtZjBmNi00OTI0LWFkYjUtYmIyZmI3NjMzOGMxLmpwZw.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/55502","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=55502"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/55502\/revisions"}],"predecessor-version":[{"id":55504,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/55502\/revisions\/55504"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/55503"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=55502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=55502"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=55502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}