DeFi protocol Arcadia Finance hacked on Ethereum and Optimism for $455k

DeFi protocol Arcadia Finance hacked on Ethereum and Optimism for $455k

A hacker drained approximately $455,000 from non-custodial decentralized finance (DeFi) protocol Arcadia Finance by exploiting a code vulnerability.

Blockchain investigator PeckShield alerted about the hack on Arcadia Finance, pointing out the cause as “the lack of untrusted input validation.” The code supposedly lacked a validation mechanism to cross-check unverified inputs. This loophole allowed the hacker to drain funds worth roughly $455,000 from Ethereum (darcWETH) and Optimism (darcUSDC) vaults collectively.

779a665c-0e9a-4e27-9204-1ac5f57d3b71.pngArcadia Finance code required no validation of untrusted input. Source: PeckShield

Arcadia Finance has not yet responded to Cointelegraph’s request for comment.

Arcadia Finance confirmed the hack two hours after PeckShield’s intimation and subsequently paused the contracts to prevent further bleeding of funds.

We are aware of a potential exploit in our protocol.
We have paused the contracts and are investigating the root-cause with security experts as we speak. More info will follow as it comes available.

— Arcadia Finance (@ArcadiaFi) July 10, 2023

While the investigations are underway, Arcadia’s code houses another vulnerability, which could prove catastrophic for the protocol if exploited. According to PeckShield:

“In addition, there is a lack of reentrancy protection, which allows for the instant liquidation to bypass the internal vault health check.”

The majority of the stolen funds — approximately 180 Ether (ETH) — were from Optimism, and have been washed via Tornado Cash. However, the stolen tokens — worth over $103,000 at the time of writing — on Ethereum remain parked at the suspected wallet address.

Related: Multichain MPC bridge sees $100M+ outflows, sparking fears of exploit

In Q2 of 2023, hacks and exploits in the crypto space resulted in a cumulative loss of over $300 million.

A report by blockchain security company CertiK showed that a total of 212 security incidents were recorded in the quarter, resulting in a loss of $313,566,528 from Web3 protocols.

When compared to the previous year’s Q2 data, CertiK found that the crypto hacks declined by 58%. Out of the lot, BNB Chain recorded the most incidents, with 119 incidents leading to $70,711,385 in losses.

Collect this article as an NFT to preserve this moment in history and show your support for independent journalism in the crypto space.

Magazine: Should you ‘orange pill’ children? The case for Bitcoin kids books

Source Link