Hacker drains $19.5 million from UwU Lend in price oracle exploit

cyptouser5 months agoCryptocurrencies News84
Blockchain security firm Cyvers Alert reported a significant exploit on the DeFi lending protocol UwU Lend, which resulted in an approximately $19.5 million loss.

The attacker funded their wallet via the sanctioned crypto mixer Tornado Cash.

Cyvers co-founder and CTO Meir Dolev told CryptoSlate in a June 10 statement:

“The UWU lending contract was exploited by an attacker that executed three transactions in six minutes and drained approximately $20 million.”

On-chain data reveals that the attacker’s wallet moved several digital assets, including wrapped Ethereum (WETH), wrapped Bitcoin (WBTC), and stablecoins like USDC. The attacker’s address has been tagged as the UwU Lend Exploiter on Etherscan.

Web3 security firm PeckShield further corroborated the incident, adding that the root cause of the attack was a price oracle issue. It said:

“In particular, the sUSDe asset is priced as median from multiple sources. Five of them, i.e., FRAXUSDe, USDeUSDC, USDeDAI, USDecrvUSD, and GHOUSDe, were manipulated during the hack.”

Meanwhile, UwU Lend confirmed the incident and immediately paused its platform. The protocol said:

“[We are] taking all necessary steps [and] doing our best here. Stay tuned for further updates.”

TVL surge?

Despite the exploit, the total value of assets locked on the DeFi protocol UwU Lend surged by 135% in the last 24 hours.

Data from DeFiLlama shows that UwU Lend currently holds over 82,000 ETH, valued at $305 million. However, approximately $247 million of these funds are borrowed.

UwU Lend was developed by Michael Patryn — also known as Sifu or 0xSifu — the controversial founder of the defunct Quadriga CX exchange. The platform enables depositors to provide liquidity to earn passive income, while borrowers can obtain liquidity in an over-collateralized manner. Additionally, liquidity providers supply liquidity and earn revenue by staking their LP tokens.

The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Crypto scams hit historic low in April, plummeting 141%

Crypto-related exploits and scams plummeted 141% in April compared to the previous month, reaching a...

Roger Ver arrested in Spain after DOJ files tax fraud charges in the US

The US Department of Justice (DOJ) announced criminal charges against Roger Ver alongside his arrest...

Not just the halving: Why analysts are bullish on Bitcoin in 2024

Not just the halving: Why analysts are bullish on Bitcoin in 2024

25cc9d4a˃The Bitcoin (BTC) halving in April will only be one small part of why the cryptocurrency co...

Terraform, Do Kwon to reach fraud settlement with SEC

55966e89˃Terraform Labs and its CEO Do Kwon have agreed in principle to settle a fraud case with the...

UK's Financial Conduct Authority says crypto firms are failing to satisfy new promotional rules

The U.K.’s Financial Conduct Authority (FCA) said on Oct. 25 that many crypto firms are failin...

Ether ETF approved, but Gary Gensler didn’t vote for it — Here’s why

Ether ETF approved, but Gary Gensler didn’t vote for it — Here’s why

55966e89˃The United States Securities and Exchange Commission (SEC) approved the spot Ether exchange...