{"id":3767,"date":"2022-06-27T16:13:23","date_gmt":"2022-06-27T16:13:23","guid":{"rendered":"https:\/\/coingrafter.com\/index.php\/2022\/06\/27\/how-this-ethereum-platform-was-attacked-and-made-a-deal-with-the-hacker\/"},"modified":"2022-06-27T16:13:24","modified_gmt":"2022-06-27T16:13:24","slug":"how-this-ethereum-platform-was-attacked-and-made-a-deal-with-the-hacker","status":"publish","type":"post","link":"https:\/\/coingrafter.com\/index.php\/2022\/06\/27\/how-this-ethereum-platform-was-attacked-and-made-a-deal-with-the-hacker\/","title":{"rendered":"How This Ethereum Platform Was Attacked And Made A Deal With The Hacker"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p>Ethereum lending platform XCarnival <a href=\"https:\/\/xcarnival-lab.medium.com\/xcarnival-has-got-1-467-eth-back-the-security-agencies-have-tentatively-determined-the-hackers-3ea05ad134ae\" target=\"_blank\" rel=\"noopener\">confirmed<\/a> a foul actor stole $3.8 million or 3,087 ETH. According to a report from on-chain safety agency Peck Shield, a hacker exploited a vulnerability on the protocol\u2019s sensible contract by borrowing ETH and creating \u201cmultiple pledge orders to pledge BAYC (Bored Ape Yacht Club NFTs) many times\u201d.<\/p>\n<p style=\"text-align: center;\"><strong>Related Reading |\u00a0<a href=\"https:\/\/bitcoinist.com\/morgan-creek-trying-to-bailout-blockfi\/\" target=\"_blank\" rel=\"noopener\">Morgan Creek Said To Be In Bid To Secure $250-M To Counter FTX BlockFi Bailout<\/a><\/strong><\/p>\n<p>XCarnival operates as a non-fungible token (NFT) lending pool. The platform allows NFT holders to deposit their property in change for liquidity. This course of includes three sensible contracts: an NFT supervisor, a P2Controller to handle lending restrictions, and fund storage, as <a href=\"https:\/\/goplussecurity.medium.com\/nft-liquidity-solver-xcarnival-was-exploited-with-a-total-loss-of-3087-eth-b2e1c57720ed\" target=\"_blank\" rel=\"noopener\">stated<\/a> by one other safety agency Go+ Security.<\/p>\n<p>The hacker purchased merchandise 5110 from the favored Bored Ape Yacht Club NFT assortment on OpenSea. Later, he deposited this asset on XCarnival and carried out an assault to \u201cuse the same NFT for borrowing\u201d.<\/p>\n<p>In different phrases, the attacker was in a position to pledge the NFT, borrowed ETH, after which take away the NFT with out paying again the mortgage. The unhealthy actor accomplished this course of a number of instances till the pool was drained.<\/p>\n<p>Go+ Security defined that the hacker created a Master sensible contract and a number of other \u201cslaves\u201d sensible contracts to conduct the assault:<\/p>\n<blockquote>\n<p>Then Slave 5338 withdrew the NFT and despatched it again to Master, who then repeated this course of with different Slaves. In this manner they created many orderIDs, which might later be used as lending credentials. But bugged xNFT contract didn\u2019t revoke the credential after withdrawing.<\/p>\n<\/blockquote>\n<p>XCarnival\u2019s <a href=\"https:\/\/twitter.com\/BenWAGMI\/status\/1541156106122461185\" target=\"_blank\" rel=\"noopener\">operated<\/a> with a vulnerability on its sensible contracts, talked about above, which allow the assault if the consumer stays inside a sure. Go+ Security added on the assault and the sensible contract vulnerability: \u201cCollateral is still valid after withdrawing. This is a very simple &amp; naive bug in contract implementation.\u201d<\/p>\n<p>In gentle of the profitable assault, the Ethereum-based NFT lending protocol determined to supply the hacker a deal.<\/p>\n<h2>Ethereum Platform Makes Deals With Its Attacker<\/h2>\n<p>According to its official Twitter account, the XCarnival supplied the hacker a 1,500 ETH or $1.8 million bounty. Half the stolen funds. The attacker solely wanted to return the opposite half and so they acquired to maintain the cash and undergo no authorized penalties.<\/p>\n<p>The group behind the platform confirmed that the hacker agreed to the phrases. Half the stolen funds have been returned to the pool. The Ethereum lending platform claims \u201csecurity agencies have tentatively determined the hacker\u2019s geographic location\u201d.<\/p>\n<p>This assertion appears to trace at potential authorized penalties for the attacker, however the group behind this mission is but to supply extra data.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">7\/8 Funds returned<a href=\"https:\/\/t.co\/oRwSsGgT6U\">https:\/\/t.co\/oRwSsGgT6U<\/a> <a href=\"https:\/\/t.co\/YgXZ9DTj03\">pic.twitter.com\/YgXZ9DTj03<\/a><\/p>\n<p>\u2014 Tal Be&#8217;ery (@TalBeerySec) <a href=\"https:\/\/twitter.com\/TalBeerySec\/status\/1541329974208200704?ref_src=twsrc%5Etfw\" rel=\"noopener\">June 27, 2022<\/a><\/p>\n<\/blockquote>\n<p>This shouldn&#8217;t be the primary time a hacker agrees to return a portion or the complete quantity of the stolen funds. Some hackers assault decentralized finance (DeFi) platforms and infrequently held the cash hostage till they obtain fee for what they thought-about to be a \u201cservice\u201d. Other tasks are much less fortunate and pay the last word value.<\/p>\n<p style=\"text-align: center;\"><strong>Related Reading |\u00a0<a href=\"https:\/\/bitcoinist.com\/harmony-dangles-1m-reward\/\" target=\"_blank\" rel=\"noopener\">Harmony Dangles $1M Reward For Return Of $100M Stolen Funds \u2013 Is It Enough?<\/a><\/strong><\/p>\n<p>At the time of writing, Ethereum (ETH) trades at $1,180 with a 3% loss within the final 24 hours.<\/p>\n<figure id=\"attachment_186270\" aria-describedby=\"caption-attachment-186270\" style=\"width: 980px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"wp-image-186270 size-large\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/06\/Ethereum-ETH-ETHUSD-6-980x429.png\" alt=\"Ethereum ETH ETHUSD\" width=\"980\" height=\"429\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/06\/Ethereum-ETH-ETHUSD-6-980x429.png 980w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/06\/Ethereum-ETH-ETHUSD-6-640x280.png 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/06\/Ethereum-ETH-ETHUSD-6-768x336.png 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/06\/Ethereum-ETH-ETHUSD-6-1536x672.png 1536w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/06\/Ethereum-ETH-ETHUSD-6-750x328.png 750w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/06\/Ethereum-ETH-ETHUSD-6-1140x499.png 1140w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2022\/06\/Ethereum-ETH-ETHUSD-6.png 1813w\" sizes=\"auto, (max-width: 980px) 100vw, 980px\"\/><figcaption id=\"caption-attachment-186270\" class=\"wp-caption-text\">ETH transferring sideways on the 4-hour chart. Source:<strong> <a href=\"https:\/\/www.tradingview.com\/chart\/UJ6TlxFV\/?symbol=COINBASE%3AETHUSD\" target=\"_blank\" rel=\"noopener\">ETHUSD Tradingview<\/a><\/strong><\/figcaption><\/figure>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/bitcoinist.com\/ethereum-platform-attacked-made-deal-the-hacker\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Ethereum lending platform XCarnival confirmed a foul actor stole $3.8 million or 3,087 ETH. According to a report from on-chain safety agency Peck Shield, a hacker exploited a vulnerability on the protocol\u2019s sensible contract by borrowing ETH and creating \u201cmultiple pledge orders to pledge BAYC (Bored Ape Yacht Club NFTs) many times\u201d. Related Reading [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":496,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"","ocean_second_sidebar":"","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"","ocean_custom_header_template":"","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"","ocean_menu_typo_font_family":"","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"","ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":""},"categories":[6],"tags":[2481,709,108,143,368],"class_list":["post-3767","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ethereum","tag-attacked","tag-deal","tag-ethereum","tag-hacker","tag-platform","entry","has-media","owp-thumbs-layout-horizontal","owp-btn-normal","owp-tabs-layout-horizontal","has-no-thumbnails","has-product-nav"],"_links":{"self":[{"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/posts\/3767","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/comments?post=3767"}],"version-history":[{"count":1,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/posts\/3767\/revisions"}],"predecessor-version":[{"id":3768,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/posts\/3767\/revisions\/3768"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/media\/496"}],"wp:attachment":[{"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/media?parent=3767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/categories?post=3767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coingrafter.com\/index.php\/wp-json\/wp\/v2\/tags?post=3767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}