{"id":58546,"date":"2023-08-19T20:24:15","date_gmt":"2023-08-19T20:24:15","guid":{"rendered":"https:\/\/egrowonline.com\/?p=58546"},"modified":"2023-08-19T20:24:15","modified_gmt":"2023-08-19T20:24:15","slug":"defi-protocols-exactly-harbor-hacked-in-separate-attacks","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=58546","title":{"rendered":"DeFi protocols Exactly, Harbor hacked in separate attacks"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=840\/https:\/\/s3.cointelegraph.com\/uploads\/2023-08\/a22c2880-31ad-467e-8a59-54602f3bb4ae.jpg\" \/><\/p>\n<div data-v-2649fa34=\"\">\n<p>Decentralized finance (DeFi) protocols Exactly and Harbor were exploited on Aug. 18 in two separate \u2014 and apparently unrelated \u2014 attacks, according to blockchain security firms DeDotFi and PeckShield.<\/p>\n<p>On-chain data reveals 4323.6 Ether (<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/ethereum-price\" rel=\"noopener\">ETH<\/a>), worth nearly $7.3 million at the time of writing, had been stolen from Exactly Protocol. The hackers then bridged 1490 ETH using the Across Protocol, and 2,832.92 ETH to the Ethereum network via Optimism Bridge. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Update: After a thorough review of the Exactly Protocol Hack, we have concluded that the total of stolen amount up to date is ~$7.2M (4323.6 <a target=\"_blank\" href=\"https:\/\/twitter.com\/search?q=%24ETH&amp;src=ctag&amp;ref_src=twsrc%5Etfw\" rel=\"noopener\">$ETH<\/a>)<\/p>\n<p>Eventually, they bridged ~1490 <a target=\"_blank\" href=\"https:\/\/twitter.com\/search?q=%24ETH&amp;src=ctag&amp;ref_src=twsrc%5Etfw\" rel=\"noopener\">$ETH<\/a>, using Across Protocol, and 2,832.92 <a target=\"_blank\" href=\"https:\/\/twitter.com\/search?q=%24ETH&amp;src=ctag&amp;ref_src=twsrc%5Etfw\" rel=\"noopener\">$ETH<\/a> to Ethereum via Optimism Bridge:\u2026 <a target=\"_blank\" href=\"https:\/\/t.co\/s61ai1OEMd\" rel=\"noopener\">https:\/\/t.co\/s61ai1OEMd<\/a><\/p>\n<p>\u2014 De.Fi &#xfe0f; Web3 Antivirus (@DeDotFiSecurity) <a target=\"_blank\" href=\"https:\/\/twitter.com\/DeDotFiSecurity\/status\/1692549866713407912?ref_src=twsrc%5Etfw\" rel=\"noopener\">August 18, 2023<\/a><\/p><\/blockquote>\n<p>Exactly is one of the crypto lenders on the Optimism network. Initial reports mentioned over 7160 ETH stolen, worth nearly $12 million, but were later revised to reflect a smaller amount missing. The attacker targeted the DebtManager periphery contract, according to Exactly: <\/p>\n<blockquote><p>&#8220;The attacker passed in a malicious market contract address, bypassing the permit check, and executed a malicious deposit function to steal assets deposited by users. Approximately $7.3M were stolen.&#8221;<\/p><\/blockquote>\n<p>The protocol filed a police report and is trying to communicate with the attackers to return the stolen assets, its team noted on X (formerly Twitter).\u00a0<\/p>\n<p>In another security incident, the interchain stablecoin protocol Harbor <a target=\"_blank\" href=\"https:\/\/twitter.com\/Harbor_Protocol\/status\/1692836252498723154\" rel=\"noopener nofollow\">disclosed<\/a> being the victim of an attack that led to the loss of funds sitting on its stable-mint, as well as stOSMO, LUNA and WMATIC vaults. At the time of writing, the amount of crypto assets stolen remains unclear. Harbor is said to be working on tracing funds and estimating the total losses.<\/p>\n<p>The attacks follow a number of security incidents across the DeFi ecosystem over the past few weeks. On July 30, a vulnerability on three versions of the Vyper programming language <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/curve-vyper-exploit-whole-story-so-far\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/curve-vyper-exploit-whole-story-so-far\/amp\" rel=\"noopener\">resulted in over $61 million stolen<\/a> from stable pools on Curve Finance. Other protocols compromised in the past days include <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/aave-earning-farm-protocol-targeted-by-reentrancy-attack-peckshield\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/aave-earning-farm-protocol-targeted-by-reentrancy-attack-peckshield\/amp\" rel=\"noopener\">Earn.Finance, with at least $287,000<\/a> worth of ETH stolen, in addition to <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/zunami-protocol-confirms-stablecoin-pools-attacked-in-exploit\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/zunami-protocol-confirms-stablecoin-pools-attacked-in-exploit\/amp\" rel=\"noopener\">$2.1 million in losses incurred<\/a> by Zunami Protocol due to another exploit.<\/p>\n<p><em><strong>Magazine:<\/strong> <\/em><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/ethereum-is-woefully-undervalued-but-growing-more-powerful-defi-dad-hall-of-flame\/\" rel=\"noopener\"><strong><em>DeFi Dad, Hall of Flame: Ethereum is \u2018woefully undervalued\u2019 but growing more powerful<\/em><\/strong><\/a><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/defi-protocols-exactly-harbor-hacked-separate-attacks\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Decentralized finance (DeFi) protocols Exactly and Harbor were exploited on Aug. 18 in two separate \u2014 and apparently unrelated \u2014 attacks, according to blockchain security firms DeDotFi and PeckShield. On-chain data reveals 4323.6 Ether (ETH), worth nearly $7.3 million at the time of writing, had been stolen from Exactly Protocol. The hackers then bridged 1490 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":58547,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[38],"tags":[1296,172,846,3358,477,13191],"class_list":["post-58546","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-attacks","tag-defi","tag-hacked","tag-harbor","tag-protocols","tag-separate"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/08\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjMtMDgvYTIyYzI4ODAtMzFhZC00NjdlLThhNTktNTQ2MDJmM2JiNGFlLmpwZw.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/58546","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=58546"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/58546\/revisions"}],"predecessor-version":[{"id":58548,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/58546\/revisions\/58548"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/58547"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=58546"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=58546"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=58546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}