Daily Mail PH

Monday, November 13, 2023

[New post] DeFi vulnerability leading to $6.7M exploit ‘not detected’ by auditors

Site logo image Crypto Breaking News posted: "Decentralized U.S. dollar stablecoin protocol Raft claims that despite multiple security audits, the firm still suffered a security exploit leading to the loss of $6.7 million last week.According to the project's Nov. 13 post-mortem report, a few days pri" Crypto Breaking News

DeFi vulnerability leading to $6.7M exploit 'not detected' by auditors

Crypto Breaking News

Nov 13

Decentralized U.S. dollar stablecoin protocol Raft claims that despite multiple security audits, the firm still suffered a security exploit leading to the loss of $6.7 million last week.

According to the project's Nov. 13 post-mortem report, a few days prior, a hacker borrowed 6,000 Coinbase-wrapped staked Ether (cbETH) on decentralized finance protocol Aave, transferred the sum to Raft, and minted 6.7 million Raft stablecoin, dubbed "R," using a smart contract glitch.

The unauthorized minted funds were then swapped off the platform through liquidity pools on decentralized exchanges Balancer and Uniswap, netting $3.6 million in proceeds. The R stablecoin depegged after the attack. 

According to the report:

"The primary root cause was a precision calculation issue when minting share tokens, which enabled the exploiter to obtain extra share tokens. The attacker leveraged the amplified index value to increase the worth of their shares."

The smart contracts exploited during the incident were audited by blockchain security firms Trail of Bits and Hats Finance. "Unfortunately, the vulnerabilities that led to the incident were not detected in these audits," Raft developers wrote.

The project says that since the Nov. 10 incident it has filed a police report and is currently working with centralized exchanges to track down the flow of the stolen funds. All Raft's smart contracts are currently suspended, though users who minted R "retain the ability to repay their positions and retrieve their collateral."

Decentralized stablecoins are minted using users' crypto deposits as collateral. Last December, decentralized stablecoin HAY depegged against the U.S. dollar after a hacker took advantage of a smart contract glitch and minted 16 million HAY without proper collateral. The HAY stablecoin has since re-pegged, in part, due to the protocol requiring a collateralization ratio of 152% at the time of exploit as part of risk management. 

We are aware of a potential security vulnerability.

We are currently investigating and will provide an update as soon as we can.

— Raft (@raft_fi) November 10, 2023

Related: September becomes the biggest month for crypto exploits in 2023

Source: Cointelegraph.com


Manage your email settings or unsubscribe.

Trouble clicking? Copy and paste this URL into your browser:
https://www.cryptobreaking.com/defi-vulnerability-leading-to-6-7m-exploit-not-detected-by-auditors/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at November 13, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Rappler x Linya-Linya campaign launch kasama sina Raco Ruiz, Ansis Sy, Monica Cruz

Tara na sa Rappler x Linya-Linya campaign launch!   06 January 2026 View in Browser       Pagbati!   Isang bagong taon ang sumasalubon...

  • [New post] Achieve Data Sovereignty through Omnisphere
    Crypto Breaking News posted: "Web 3.0 is one of the biggest buzzwords flying around the world of social media this year. An...
  • [New post] Tuesday’s politics thread is trying to stay positive.
    SheleetaHam posted: " Even though I just finished the latest Opening Arguments podcast about how Roe v. Wade is toast, and ...
  • [New post] Is XRP going to take the Crypto market by storm
    admin posted: "Is XRP going to take the Crypto market by storm While the SEC has been going after Ripple in court the XRP b...

Search This Blog

  • Home

About Me

Daily Newsletters PH
View my complete profile

Report Abuse

Labels

  • Last Minute Online News

Blog Archive

  • January 2026 (1)
  • December 2025 (8)
  • November 2025 (4)
  • October 2025 (2)
  • September 2025 (1)
  • August 2025 (2)
  • July 2025 (5)
  • June 2025 (3)
  • May 2025 (2)
  • April 2025 (2)
  • February 2025 (2)
  • December 2024 (1)
  • October 2024 (2)
  • September 2024 (1459)
  • August 2024 (1360)
  • July 2024 (1614)
  • June 2024 (1394)
  • May 2024 (1376)
  • April 2024 (1440)
  • March 2024 (1688)
  • February 2024 (2833)
  • January 2024 (3130)
  • December 2023 (3057)
  • November 2023 (2826)
  • October 2023 (2228)
  • September 2023 (2118)
  • August 2023 (2611)
  • July 2023 (2736)
  • June 2023 (2844)
  • May 2023 (2749)
  • April 2023 (2407)
  • March 2023 (2810)
  • February 2023 (2508)
  • January 2023 (3052)
  • December 2022 (2844)
  • November 2022 (2673)
  • October 2022 (2196)
  • September 2022 (1973)
  • August 2022 (2306)
  • July 2022 (2294)
  • June 2022 (2363)
  • May 2022 (2299)
  • April 2022 (2233)
  • March 2022 (1993)
  • February 2022 (1358)
  • January 2022 (1323)
  • December 2021 (2064)
  • November 2021 (3141)
  • October 2021 (3240)
  • September 2021 (3135)
  • August 2021 (1782)
  • May 2021 (136)
  • April 2021 (294)
Simple theme. Powered by Blogger.