Uwu lend is hacked by analysis

background

On June 10, 2024, according to the monitoring of the Slow Misteye Safety Monitoring System, UWU Lend, a platform for digital asset lending services, was attacked by the EVM chain, losing about $ 19.3 million.The slow fog security team analyzed the incident and shared the results as follows:

>

(https://x.com/slowmist_team/status/1800181916857155761)

Related information

Attack address:

0x841ddf093F5188989FA1524E7B893DE6421F47

There is a contract address with vulnerabilities:

0x9bc63333081266e55d88942e277fc809b485698B9
Attack transaction:
0xca1bbf3B320662C89232006F1EC6624B56242850F0F1DADBE4F69ba0d6ac3

0xb3f067618ce54BC26A960B660CFC28F9EA0315E2E9A1A855EDE1508EB4017376

0x242A0FB4FDE0DC2FD42E8DB743CBC197FFA2BF6A036BBA303DF296408B

Attack core

The core point of this attack is that the attacker can directly manipulate the price prophecy machine by conducting a large exchange price of the SUSDE tokens through the price of the SUSDE tokens by using it in the Curvefinance pool, and use the manipulated price to put other assets in the pool.

Attack process

1. The price of Lightning Loan borrowing assets and smashing low USDE:The attacker first borrowed a large amount of assets through Lightning Loan, and exchanged some USDE tokens borrowed from the CURVE pool that could affect the price of Susde to other tokens.

>

2. Create a large number of borrowing loans:Under the current SUSDE price plummeting, a large number of SUSDE tokens are borrowed by excess of other underlying tokens.

>

3. Manipulate the price of the prediction machine again to raise the price of the Susde:By performing reverse exchange operations in the previous Curve pool, the price of Susde quickly increased.

>

4. A large amount of liability for liability:As the price of Susde is quickly pulled up, the attacker can get a large number of borrowed positions to get UWETH.

>

5. Stay in the remaining SUSDE and borrow other underlying tokens in the contract:The attacker has once again deposited SUSDE, which is currently at high prices to borrow more underlying asset tokens.

>

It is not difficult to see that the attacker mainly manipulates the price of Susde to make a large amount of loans at low prices, and liquidates and re -mortgage profit at high prices.We follow up to the prediction machine contract of the SUSDE price.

>

It can be seen that the price of the Susde is to obtain the different prices of 11 USDE tokens from the USDE pool and the UNI V3 pool on the Curvefinance, and then sort and calculate the medium digits based on these prices.

In the calculation logic here, the price of 5 USDE is to directly use the get_p function to obtain the instant spot price of the Curve pool, which leads to an attacker that can directly affect the median price in a large exchange method in a transaction.Calculation results.

>

Misttrack analysis

According to MISTTRACK analysis on the chain, the attacker 0x841ddf093F5188989FA1524E7B893DE64B421F47 made a profit of about $ 19.3 million in this attack, including currency ETH, CRVUSD, BLUSD, USDC. It was replaced with ETH.

>

Through the source of the attack fee of the attacker, the initial funds on the address are from 0.98 ETH transferred to the TORNADO CASH, and then the address also received 5 funds from Tornado Cash.

>

Expansion of the transaction map found that the attacker transferred 1,292.98 ETH to the address 0x48D7C1DD4214B41EDA3301BCA434348F8D1C5EB6. The current balance of the address is 1,282.98 ETH; the attacker transfers the remaining 4,000 ETH to the address to the address BF991841827F37745DDADB563FEB70, currently the balance of this address is 4,010 ETH.

>

Misttrack has grueded related addresses and will continue to pay attention to the dynamic dynamics of the stolen funds.

Summarize

The core of this attack is that the attacker uses the price prophet directly obtaining the directly -spot price and the compatible defect of the compatibility of the median calculation price to manipulate the price of the SUSDE, so as to obtain non -expected profits under the influence of severe spreads to obtain non -expected profits.EssenceThe slow fog security team recommends that the project party enhances the anti -operation capability of the price prophecy, and the design is a safer price proportion machine feeding mechanism to prevent similar incidents from happening again.

  • Related Posts

    A pre-provocative death: The money and human nature behind Jeffy’s fake death

    Jessy, bitchain vision Meme in the currency circle has released a new narrative: the death track. On May 6, an obituary of the death of Zerebro Jeffy Yu was released.…

    Binance removed from the shelves but soared. Alpaca dealer’s extreme trading

    Jessy, bitchain vision According to common sense, a token is removed from the exchange, which is a major negative news. However, this rule has not been perfectly reproduced on May…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    9 important investment experiences of Buffett

    • By jakiro
    • May 15, 2025
    • 3 views
    9 important investment experiences of Buffett

    Wall Street Journal: Why did Buffett retire?Who is the next successor?

    • By jakiro
    • May 15, 2025
    • 5 views
    Wall Street Journal: Why did Buffett retire?Who is the next successor?

    Fartcoin’s farts resounded through Wall Street

    • By jakiro
    • May 14, 2025
    • 7 views
    Fartcoin’s farts resounded through Wall Street

    Eight narrative directions and related projects worth paying attention to

    • By jakiro
    • May 14, 2025
    • 9 views
    Eight narrative directions and related projects worth paying attention to

    Bitcoin and cryptocurrencies are occupying Wall Street

    • By jakiro
    • May 14, 2025
    • 11 views
    Bitcoin and cryptocurrencies are occupying Wall Street

    What is the real driving force behind Ethereum’s rise in this round?

    • By jakiro
    • May 14, 2025
    • 11 views
    What is the real driving force behind Ethereum’s rise in this round?
    Home
    News
    School
    Search