In a recent exploit that has rocked the decentralized finance (DeFi) community, a cyber attacker managed to siphon off nearly $9.6 million from Resupply, a platform known for its ties with heavyweight DeFi entities Convex Finance and Yearn Finance. The heist was orchestrated by exploiting a flaw within Resupply’s exchange rate mechanism, specifically tied to its cvcrvUSD token. By manipulating market conditions in a thinly traded environment, the attacker triggered a zero exchange rate bug, enabling them to borrow vast sums against virtually non-existent collateral.
Resupply promptly acknowledged the breach, temporarily halting transactions in the affected wstUSR market and disclosing that the ill-gotten funds had been dispersed through Tornado Cash, a cryptocurrency mixer, before being divided into multiple wallets. This incident underlines the vulnerabilities present in the fabric of decentralized finance protocols, despite an increasing focus on enhancing security measures.
The sophisticated attack involved the artificial inflation of the cvcrvUSD token’s price through strategic transactions in a market with low liquidity. The manipulated valuation then served as the foundation for the attacker to secure loans in reUSD tokens amounting to nearly ten million dollars with just one wei (the smallest denomination of Ether) of collateral. The revelations from blockchain security outfit Phalcon provide a concerning glimpse into the potential for exploitation within these protocols.
This event adds to a troubling trend of significant security breaches within the cryptocurrency sphere, contributing to losses surpassing $2.1 billion for the year. The attacker’s method, which skirted the platform’s solvency checks due to the aforementioned bug, underscores the complex risks that can arise from the innovative mechanisms at the core of DeFi systems.
After accruing the fraudulent loans, the perpetrator converted the assets into other cryptocurrencies such as USDC and wrapped Ethereum through exchanges Curve and Uniswap, realizing a profit close to the $9.5 million mark. In the wake of the exploit, security analysts have urged users to withdraw their investments from reUSD vaults as a precaution.
Further investigation by PeckShield laid bare the mechanics behind the operation, tracing the initial steps of the attack to a transaction involving 2 ETH on Cow Swap, followed by an attempt to anonymize the proceeds through Tornado Cash. This maneuver resulted in the withdrawal of approximately 1,581 ETH from the system.
In response to the intrusion, Resupply has taken steps to mitigate the damage, including the suspension of the impacted market and assurances that a thorough post-mortem analysis will be shared with the community. The exploit has prompted a reassessment of security protocols on the platform, which remains operational outside of the compromised market.
As the exploit’s ramifications continue to unfold, it serves as a poignant reminder of the ongoing challenges facing the DeFi sector. This incident not only highlights the ingenuity of malicious actors but also the imperative for continual advancement in the security architectures protecting these burgeoning financial ecosystems.