Dough Finance flash loan attack: What we know so far

Dough Finance flash loan attack


Dough Finance lost $1.8M in a flash loan attack due to smart contract vulnerability.
Attacker exploited unvalidated calldata stealing USDC before converting the assets into 608 ETH.
Users urged to withdraw funds to secure wallets.

Dough Finance has fallen victim to a significant flash loan attack, resulting in a staggering loss of digital assets worth approximately $1.8 million.

The attack, which exploited vulnerabilities in the protocol’s smart contract, highlights ongoing security challenges within the cryptocurrency space, and specifically within the DeFi space.

What happed in the Dough Finance attack?

The attack, detected on July 12 by Web3 security firm Cyvers, targeted Dough Finance’s “ConnectorDeleverageParaswap” smart contract.

Binance

This contract, designed to facilitate transactions within the DeFi platform, failed to adequately validate call data during flash loan executions giving the attacker a chance to manipulate transaction details and illegally transfer of 608 Ether (ETH), valued at approximately $1.8 million at the time of the attack.

The funds, originally in the form of USD Coin (USDC), were swiftly converted into ETH using the zero-knowledge protocol Railgun, complicating efforts to trace and recover the stolen assets.

Who were affected by the flash loan attack?

The Dough Finance flash loan attack primarily affected users who had funds deposited in the exploited contract of Dough Finance.

While the lending pools of Aave, another prominent DeFi platform, remained unaffected, the incident underscores the vulnerability of smart contracts and the potential risks associated with decentralized finance protocols.

Security experts, including Olympix, emphasized the importance of users withdrawing their funds to secure wallets and refraining from interacting with Dough Finance until the platform issues clear guidance on safety measures.

Remarkably, the attack on Dough Finance adds to a concerning trend of security breaches plaguing the cryptocurrency industry in 2024.

According to a recent report by CertiK, on-chain attack incidents have already led to losses exceeding $1.19 billion in the first half of the year, with phishing attacks and private key compromises contributing significantly to these figures.





Source link

[wp-stealth-ads rows="2" mobile-rows="3"]

Leave a Reply

Your email address will not be published. Required fields are marked *

Pin It on Pinterest

#GlobalNewsIt
Ledger
#GlobalNewsIt
Dough Finance flash loan attack
Binance
Blockonomics
Tests $2,500 Support Level Amid International Trade Tensions
EigenLayer to begin 'slashing' restakers in April
Tests $2,500 Support Level Amid International Trade Tensions
Ethereum's weekly blob fees hit 2025 lows
Whales Increase Holdings by 12% Despite Market Downturn
Vitalik Buterin meows at a robot, and the crypto world loses it
bitcoin
ethereum
bnb
xrp
cardano
solana
dogecoin
polkadot
shiba-inu
dai
Bitcoin
Dogecoin
Tests $2,500 Support Level Amid International Trade Tensions
Cango to Offload Chinese Assets for $352M, Eyes Bitcoin Mining Growth 
Crypto market bottom likely by June despite tariff fears: Finance Redefined
Bitcoin
Dogecoin
Tests $2,500 Support Level Amid International Trade Tensions
Cango to Offload Chinese Assets for $352M, Eyes Bitcoin Mining Growth 
bitcoin
ethereum
tether
xrp
bnb
solana
usd-coin
dogecoin
cardano
tron
bitcoin
ethereum
tether
xrp
bnb
solana
usd-coin
dogecoin
cardano
tron