ParaSwap evades hack targeting Augustus v6 contract vulnerability

cyptouser8 months agoCryptocurrencies News134
25cc9d4a>

Decentralized finance (DeFi) aggregator ParaSwap discovered a vulnerability in its newly launched Augustus V6 contract and prevented a colossal loss of funds through timely white hat intervention.

On March 18, the ParaSwap Augustus v6 went live, promising greater efficiency in swapping gas fees than all its preceding contracts. The contract contained a critical vulnerability that would allow hackers to drain funds when approved.

Soon after discovering the vulnerability, on March 20, ParaSwap paused the v6 application prog interface (API) and secured the potential victims’ funds through a white hack.

Source: ParaSwap

ParaSwap advised all users to revoke permissions to the Augustus v6 contract to avoid further loss of funds until the vulnerability is neutralized.

Despite ParaSwap’s proactive effort to roll back the vulnerable v6 contract and inform users to take necessary steps as well, the hacker managed to cash out funds worth roughly $24,000 from four different addresses.

In total, ParaSwap revealed that 386 addresses were affected by the vulnerability. The protocol also asked users to report any loss of funds that may have gone unidentified during the preliminary investigation.

ParaSwap identified 386 wallet addresses being affected by the Augustus Vv contract vulnerability. Source: paraswap.notion.site

In addition, ParaSwap also deactivated the support for the vulnerable v6 contract on its recently updated user interface (UI) and reverted to using v5. “We have successfully recovered funds for all addresses, and more details about the refund process will be shared soon,” the company added.

ParaSwap did not immediately respond to Cointelegraph’s request for comment.

Affected users remain at risk as long as they haven’t revoked their approvals, so ParaSwap recommends individuals use exploit checker services like Revoke to confirm their safety. Check out Cointelegraph’s guide on how to identify and mitigate smart contract vulnerabilities.

Related: Old Trust Wallet iOS vulnerability from 2018 may still affect some accounts

Generative artificial intelligence (AI) tools like the ChatGPT-4 are good at generating and parsing codes. However, the tools fail to perform as a fully reliable security auditor.

According to a recently published research paper from a pair of researchers from Salus Security, a blockchain security company with offices in North America, Europe and Asia:

“GPT-4 can be a useful tool in assisting with smart contract auditing, especially in code parsing and providing vulnerability hints. However, given its limitations in vulnerability detection, it cannot fully replace professional auditing tools and experienced auditors at this time.”

According to their findings, ChatGPT is good at detecting true positives — actual vulnerabilities that, outside of a testing environment, would be worth investigating. It reached greater than 80% precision in testing.

Magazine: South Africa’s digital-nomad crypto hub: Cape Town, Crypto City Guide

The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Senators pressure SEC’s Gensler not to approve any more crypto ETFs

Senators pressure SEC’s Gensler not to approve any more crypto ETFs

25cc9d4a˃Two United States senators want Gary Gensler to pull the pin on any further crypto exchange...

Riot Platforms bounces after damning report claiming collapse

Riot Platforms bounces after damning report claiming collapse

55966e89˃Shares in Riot Platforms Inc (RIOT) recovered from a hefty dip on June 5 after a strongly-w...

Montenegrin authorities to release Do Kwon as he awaits extradition: Report

Montenegrin authorities to release Do Kwon as he awaits extradition: Report

25cc9d4a˃Authorities in Montenegro will reportedly release Terraform Labs co-founder Do Kwon as loca...

Bitcoin has '3 bullish reasons' to head higher after $68K dip — analysis

Bitcoin has '3 bullish reasons' to head higher after $68K dip — analysis

55966e89˃Bitcoin (BTC) dropping to multi-day lows is nothing against the broader BTC price uptrend,...

Historic Bitcoin mining revenue fails to offset Canaan Q2 financial loss

Bitcoin (BTC) miner Canaan‘s second-quarter financial report showed that the firm ope...

Genesis forfeits BitLicense, pays $8 million to settle NYDFS lawsuit

The New York State Department of Financial Services (NYDFS) announced a settlement with Genesis Glob...