DeFi platform dForce was attacked, and the lock-up volume plummeted by 99.9%

On April 19, a decentralized finance (DeFi) and currency protocol platform called dForce suffered a security incident. The platform's lending protocol was lendf.me attacked, resulting in a temporary shutdown of the platform. According to security experts, the attack is very similar to the previous day's attack on a certain DEX, and it is likely that the same people did it. Currently, the dForce team is actively investigating the details of the incident.

Blockchain data shows that the attackers have transferred the acquired assets to two major DeFi platforms. According to the information of the industry data statistics platform, the lock-up amount on the dForce platform dropped sharply within 24 hours, falling by as much as 99.9%.

!

The attack was linked to another security incident that occurred the day before. In that incident, hackers exploited a compatibility vulnerability between a DEX and the ERC777 token standard. Specifically, the attacker implemented a re-entrancy attack by repeatedly calling the tokensToSend function in ERC777 when trading ETH and imBTC.

According to an analysis by blockchain security firm PeckShield, a DEX lost about 1,278 ETH, worth about $220,000, in that attack. In addition, about 18.37 imBTC were acquired by two addresses at a price below the market price, and these two addresses are considered arbitrageurs.

!

These two back-to-back attacks have once again highlighted the security challenges facing the DeFi space. It reminds us that despite the many innovations and opportunities that decentralized finance brings, its security remains an urgent issue. Developers and users alike need to be vigilant and constantly improve their security measures to deal with increasingly sophisticated attack vectors.

DEFI-0.77%
DF-4.33%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Repost
  • Share
Comment
0/400
NotFinancialAdviservip
· 06-26 12:22
Another play people for suckers and run away
View OriginalReply0
OptionWhisperervip
· 06-24 19:37
Another Rug Pull happened.
View OriginalReply0
MechanicalMartelvip
· 06-24 16:25
Another victim has fallen.
View OriginalReply0
Layer2Arbitrageurvip
· 06-24 15:25
Classic reentrant exploit ngmi
Reply0
LayoffMinervip
· 06-24 15:25
Suckers have been played for suckers again.
View OriginalReply0
ForeverBuyingDipsvip
· 06-24 15:23
I have already lost a lot.
View OriginalReply0
DefiPlaybookvip
· 06-24 15:20
Has the contract code been audited?
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)