Decentralized finance (DeFi) lending protocol Euler Finance grew to become a sufferer of a flash mortgage assault on March 13, ensuing within the largest hack of crypto in 2023 to this point. The lending protocol misplaced practically $197 million within the assault and impacted greater than 11 different DeFi protocols as effectively.

On March 14, Euler got here out with an replace on the scenario and notified its customers that they’d disabled the vulnerable etoken module to dam deposits and the vulnerable donation operate.

The agency mentioned that they work with varied safety teams to carry out audits of its protocol, and the vulnerable code was reviewed and accepted throughout an out of doors audit. The vulnerability was not found as a part of the audit.

One of our auditing companions, @Omniscia_sec, ready a technical autopsy and analysed the assault in nice element. You can learn their report right here:

In brief, the attacker exploited vulnerable code which allowed it to create an unbacked token debt…

— Euler Labs (@eulerfinance) March 14, 2023

The vulnerability remained on-chain for eight months till it was exploited, regardless of a $1 million bug bounty in place.

Sherlock, an audit group that has labored with Euler Finance up to now, verified the basis reason for the exploit and helped Euler submit a declare. The audit protocol later voted on the declare for $4.5 million, which handed, and later executed a $3.3 million payout on March 14.

In its evaluation report, the audit group famous a major issue for the exploit: a lacking well being examine in “donateToReserves,” a brand new operate added in EIP-14. However, the protocol harassed that the assault was nonetheless technically doable even earlier than EIP-14.

Related: More than 280 blockchains vulnerable to ‘zero-day’ exploits, warns safety agency

Sherlock famous that the Euler audit by WatchPug in July 2022 missed the vital vulnerability that finally led to the exploit in March 2023.

Similarly, Sherlock stands behind each auditor who reviewed Euler.

Sherlock initially labored with @cmichelio to audit the primary model of Euler in Dec 2021, then with @shw9453 to audit a really small replace in Jan 2022, and at last with @WatchPug_ to audit EIP-14 in July 2022.

— SHERLOCK (@sherlockdefi) March 13, 2023

Euler has additionally reached out to main on-chain analytic and blockchain safety companies, reminiscent of TRM Labs, Chainalysis and the broader ETH safety group, in a bid to assist them with the investigation and recuperate the funds.

Euler notified that also they are attempting to contact these liable for the assault as a way to study extra concerning the concern and probably negotiate a bounty to recuperate the stolen funds.


Please enter your comment!
Please enter your name here