Hacker drains $19.5 million from UwU Lend in price oracle exploit

cyptouser4 months agoCryptocurrencies News63
Blockchain security firm Cyvers Alert reported a significant exploit on the DeFi lending protocol UwU Lend, which resulted in an approximately $19.5 million loss.

The attacker funded their wallet via the sanctioned crypto mixer Tornado Cash.

Cyvers co-founder and CTO Meir Dolev told CryptoSlate in a June 10 statement:

“The UWU lending contract was exploited by an attacker that executed three transactions in six minutes and drained approximately $20 million.”

On-chain data reveals that the attacker’s wallet moved several digital assets, including wrapped Ethereum (WETH), wrapped Bitcoin (WBTC), and stablecoins like USDC. The attacker’s address has been tagged as the UwU Lend Exploiter on Etherscan.

Web3 security firm PeckShield further corroborated the incident, adding that the root cause of the attack was a price oracle issue. It said:

“In particular, the sUSDe asset is priced as median from multiple sources. Five of them, i.e., FRAXUSDe, USDeUSDC, USDeDAI, USDecrvUSD, and GHOUSDe, were manipulated during the hack.”

Meanwhile, UwU Lend confirmed the incident and immediately paused its platform. The protocol said:

“[We are] taking all necessary steps [and] doing our best here. Stay tuned for further updates.”

TVL surge?

Despite the exploit, the total value of assets locked on the DeFi protocol UwU Lend surged by 135% in the last 24 hours.

Data from DeFiLlama shows that UwU Lend currently holds over 82,000 ETH, valued at $305 million. However, approximately $247 million of these funds are borrowed.

UwU Lend was developed by Michael Patryn — also known as Sifu or 0xSifu — the controversial founder of the defunct Quadriga CX exchange. The platform enables depositors to provide liquidity to earn passive income, while borrowers can obtain liquidity in an over-collateralized manner. Additionally, liquidity providers supply liquidity and earn revenue by staking their LP tokens.

The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Terraform proposes $1M penalty for SEC case, no relief or disgorgement

Terraform proposes $1M penalty for SEC case, no relief or disgorgement

55966e89˃Lawyers representing Terraform Labs have filed a motion in opposition to a request from the...

Toncoin gains regulatory approval to trade in Kazakhstan

Toncoin gains regulatory approval to trade in Kazakhstan

55966e89˃Kazakhstan's Financial Services and Regulatory Committee (AFSA) has approved Toncoin (TON)...

India's securities watchdog calls for crypto regulation; Turkey moves toward licensing model

Turkey and India advanced crypto policies on May 16 that could create a framework for businesses and...

Is Kelp the key to a more stable future for crypto: AMA recap

Is Kelp the key to a more stable future for crypto: AMA recap

55966e89˃With traditional fiat currencies facing inflation concerns and the volatility of cryptocurr...

Coinbase to file motion to dismiss SEC lawsuit in its ‘entirety’

Leading cryptocurrency exchange, Coinbase, is set to file a motion to dismiss the ongoing lawsuit fr...

Silvergate settles SEC lawsuit for $50 million; Fed, California regulator demand $63 million fine

Silvergate Capital settled with the SEC for $50 million as Federal Reserve governors and California...