pwshub.com

Decentralized Web3 Project Onyx Hacked for $3,800,000 Worth of Crypto: PeckShield

Decentralized liquidity protocol Onyx has suffered a security breach that siphoned millions worth of crypto assets from the platform.

Blockchain security firm PeckShield says the perpetrators made off with over $3.8 million in crypto assets, which include  7.35 million of the protocol’s utility token Onyxcoin (XCN), 50,000 Tether (USDT), 4.1 million Virtual USD (VUSD), 5,000 DAI and 0.23 Wrapped Bitcoin (WBTC).

The attackers also swapped the tokens for Ethereum (ETH).

“Here are the latest whereabouts of the stolen $3.8 million funds from OnyxDAO.”

Image
Source: PeckShield

PeckShield identifies an issue that enabled the hackers to compromise the platform.

“It seems today’s victim OnyxDAO (w/ >$3.8m loss) falls prey to a known precision issue in forked CompoundV2 code base… The bug is exploited to leverage a nearly empty market to manipulate the exchange rate.”

Aside from the bug in the forked Compound V2 code base, the attackers also took advantage of another vulnerability.

“Another issue that facilitates the hack is related to the NFTLiquidation contract, which does not properly validate (untrusted) user input and was exploited to inflate the self-liquidation reward amount.”

Image
Source: PeckShield

Onyx, which conducted an investigation following the incident, says the primary issue is the NFTLiquidation contract.

“Onyx Protocol was subject to a security incident where a nefarious actor exploited the protocol to drain VUSD from the protocol. This exploit can be identified and understood from a vulnerability in the NFT Liquidation contract.”

Generated Image: Midjourney

Source: dailyhodl.com

Related stories
1 month ago - The decentralized oracle network Chainlink (LINK) continues to lead all ERC-20 projects in terms of recent development activity, according to the crypto analytics firm Santiment. Santiment notes that Chainlink registered 401.53 notable...
1 month ago - Opinion: Web3 holds the key to climate action, so why isn’t the rest of the world listening?
1 week ago - The involvement of high-profile advisors in WLFI could significantly influence the DeFi landscape and bolster US financial dominance. The post Trump-backed DeFi project taps Scroll co-founder as advisor appeared first on Crypto Briefing.
2 weeks ago - While Bluesky seems like Twitter on the surface, the AT protocol architecture it runs on has the potential to be revolutionary.
2 weeks ago - In the ever-volatile cryptocurrency market, few things are certain, except perhaps the unpredictability of it all. This truth has never been more evident than in the current showdown between Artificial Superintelligence Alliance (FET), a...
Other stories
30 minutes ago - There are steps that former Alameda Research CEO Caroline Ellison can take to make prison a better experience, consultants told Decrypt.
45 minutes ago - As the market continues its bullish climb, Avalanche (AVAX) keeps on garnering investor interest as new developments drive growth on the platform. These developments have since placed AVAX on the crosshairs of the bulls leading to a 25%...
57 minutes ago - The US government’s case against Tornado Cash founder Roman Storm will proceed to a jury trial, a federal judge ruled yesterday. 
57 minutes ago - Latest stats from the US Bureau of Economic Analysis reinforce expectations of a continued dovish policy stance, analysts say
1 hour ago - A slew of metrics indicate the top meme asset Dogecoin (DOGE) could be primed for a price boost, according to a popular crypto trader. The analyst Ali Martinez tells his 72,500 followers on the social media platform X that DOGE recently...