Hacker Stole $2.8 Million Of Cryptocurrency From The Supposedly 'Unhackable' Blockchain

Data inside a blockchain is transparent, and secure.

In a growing list of records that are called blocks, which are linked with cryptography, each block contains a cryptographic hash of the previous block, the timestamp, and transaction data. By design, a blockchain is resistant to modification of its data.

Blockchain also makes data secured. This is because once something is recorded in a block, the data cannot be altered retroactively without alteration of all subsequent blocks.

But that doesn't mean that the technology is flawless.

An unknown entity has managed to steal $2.8 million worth of cryptocurrency from a shared digital "vault" on the investment website Yearn.finance.

The hacker managed to accomplish such feat using Aave, an open-source cryptocurrency platform that allows people to make "flash loans," which allows a rapid borrowing and repaying of money without the need for collateral.

The hack happened like this:

Yearn.finance allows users to deposite funds in collective pools called "vaults."

It's through these vaults that Yearn.finance handles the mutual funds, with the funds used in other "decentralized finance" or "DeFi" offerings with the goal of generating additional earnings for the vaults' depositors.

Based in Ethereum, Yearn.finance then use 'smart contracts' for functions, to then track all of its users through the blockchain technology.

In this case, the hacker exploited Yearn.finance's vault by issuing an Aave flash loan Repeating the steps multiple times for increasingly smaller amounts, this caused the vault to deposit funds into the imbalanced pool, at a unfavorable exchange rate..

This allowed the culprits to quickly drain the vaults before they could be stopped.

News about this breach was first reported on Discord, a community-centered instant messaging and digital distribution platform on February 4, 2021.

A while later, Yearn.finance's website reported that its vaults were sustaining a loss of 1059%.

In the evening that day, a member of Yearn.finance's team wrote on Discord, that the "attacker got away with 2.8m."

[block:block=87]

The theft may show that the blockchain, the very technology that powers cryptocurrency transactions that was once thought to be "unhackable," actually have vulnerabilities.

According to Yearn’s vulnerability disclosure posted on GitHub, Yearn.finance creator Andre Cronje noticed odd patterns in a contract interacting with the platform’s vaults, which was then recognized as an active exploit of the v1 yDAI vault.

Yearn said that the attackers caused the compromised vault to deposit and withdraw funds from the automated market maker (AMM) Curve’s 3pool at unfavorable rates.

The exploiter were able to debalance the exchange between stablecoins in Curve’s 3CRV pool, make the yDAI vault deposit into the pool at an unfavorable exchange rate, and reverse the imbalance.

“[First], the hacked vault’s slippage protection was set too loose at 1%. [Second], the normal 0.5% withdrawal fee was set to 0%, to encourage migrations to v2 vaults without incurring costs. [And third], this being a v1 vault, the exploiter was able to call earn() and push deposits into the vault’s strategy at will.”

Yearn.finance.

Yearn's security team mitigated the exploit in 11 minutes, but it was still not fast enough to save 24 million of the vault’s 35 million DAI.

The attackers managed to drain $11 million from Yearn, but only made $2.7 million in profits.

This is because the attackers had to pay large amounts in fees for them to carry out the exploit.

From $3.5 million per staker to $1.4 million for Aave v2.