CrypLogger.com
  • Home
  • Exclusive
  • Learn About Coins
  • Artificial Intelligence
  • Forecasts
  • News
  • Opinions
  • Current Prices
No Result
View All Result
  • Home
  • Exclusive
  • Learn About Coins
  • Artificial Intelligence
  • Forecasts
  • News
  • Opinions
  • Current Prices
No Result
View All Result
CrypLogger
No Result
View All Result
Home News

A bug in the Solana library allowed to steal up to $ 27 million in an hour

by Vaibhav
December 6, 2021
in News
0
A bug in the Solana library allowed to steal up to $ 27 million in an hour
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

A bug in the Solana Protocol Program Library (SPL) could potentially allow stealing from several large DeFi-Projects funds at a rate of approximately $ 27 million per hour. This was found out by experts from the Neodyme team.

We recently discovered a critical bug in the token-lending contract of the solana-program-library (SPL). This blog post details our journey from discovery, through exploitation and coordinated disclosure, and finally the fix.

– Neodyme (@Neodyme) December 3, 2021

The Tulip Protocol yield aggregator and the Solend and Larix lending protocols were under threat. At its peak, cumulative TVL of these projects reached $ 2.6 billion.

Related articles

QuickNode raises $60M investment at $800M valuation

Plai Labs Raises $32M in Seed Round

March 26, 2023
US mulls ‘expansion’ of emergency lending facility for banks: report

US mulls ‘expansion’ of emergency lending facility for banks: report

March 26, 2023

The experts noted that the bug was publicly disclosed by one of the group’s auditors, nicknamed Simon, back in June. On December 1, he discovered that the vulnerability had not been fixed. As suggested by Neodyme, it may have been considered harmless.

See also  Dogecoin Foundation and Vitalik Buterin to develop DOGE staking mechanism

However, experts have found that the bug allows you to quickly steal “hundreds of millions of dollars” through tiny amounts.

For assets on Solana, you must indicate the number of zeros after the decimal point, and the program from the SPL for withdrawing funds rounds the minimum asset value to the nearest whole number, experts explained.

Theoretically, nothing prevents you from setting up the output so as to get rounding in your favor and display this amount. However, for example, for the Solana token, it is 1 Lamport, equal to 0.000000001 SOL, or approximately $ 0.00000022 (at the time of research). The transaction fee exceeds this value by almost 5,000 times, emphasized in Neodym.

See also  Finopolis participant pointed to the shortcomings of cryptocurrency regulation in the Russian Federation
Some coins from Solend listing. The number of zeros after the decimal point, the approximate value of the cryptocurrency at the time of the study, the ratio of the minimum unit to the transaction fee in it. Data: blog.

At the same time, for cryptocurrencies with a larger denomination, this gap does not look so catastrophic. By testing their theory on a copy of the blockchain, experts were able to steal $ 0.05 in Bitcoin and $ 0.005 in Ethereum.

Since a transaction on the Solana network can contain many instructions, Neodyme experts used an exploit to carry out about 300 transfers per second. In the case of Bitcoin, this meant approximately $ 7,500 stolen funds over the period, or ~ $ 27 million per hour. The attack has also become economically feasible against FTT and even RAY tokens.

See also  Circle has regained access to its SVB deposit

Experts contacted the Solana Foundation and eight projects that they believe are affected by the vulnerability. In some cases, the assumptions turned out to be wrong, and Port Finance resolved the problem on its own several months ago. Tulip, Solend and Larix did this after the call, and the Solana team made some changes to the documentation.

Recall that in early December, a hacker withdrew assets worth over $ 120 million from the Badger DAO DeFi project.

Subscribe to Cryplogger news in Twitter…

Found a mistake in the text? Select it and press CTRL + ENTER

Share76Tweet47

Related Posts

QuickNode raises $60M investment at $800M valuation

Plai Labs Raises $32M in Seed Round

by Vaibhav
March 26, 2023
0

The proceeds will be used to hire staff and create social services. sitesThe company wants to combine Web3 and artificial...

US mulls ‘expansion’ of emergency lending facility for banks: report

US mulls ‘expansion’ of emergency lending facility for banks: report

by Vaibhav
March 26, 2023
0

United States authorities are reportedly considering extending an emergency line of credit to banks "in ways" that could give the...

Gemini releases details of phishing scams

Gemini prepares lawsuit after Genesis bankruptcy

by Vaibhav
March 26, 2023
0

Winklevoss again criticizes the head of the DCG Barry SilbertIt requires a clear plan for refunds to Gemini customersOtherwise, the...

WSJ: “Binance has been cheating US regulators for years”

Binance Will Remove Some NFT Collections

by Vaibhav
March 26, 2023
0

The exchange will update the rulesUsers can also report support if they find suspicious collectionsClients of the largest crypto exchange...

Huobi Officially Recognizes Justin Sun’s Leadership And Announces…

Huobi Officially Recognizes Justin Sun’s Leadership And Announces…

by Vaibhav
March 26, 2023
0

Huobi published a massive press release In it, the company acknowledged the leadership of Justin Sun for the first time.The...

Load More

Recent News

  • Plai Labs Raises $32M in Seed Round
  • US mulls ‘expansion’ of emergency lending facility for banks: report
  • Gemini prepares lawsuit after Genesis bankruptcy
  • Binance Will Remove Some NFT Collections
  • Huobi Officially Recognizes Justin Sun’s Leadership And Announces…
  • Genesis owes over $3.5 billion to top 50 creditors
  • The world’s first decentralized exchange will appear in Busan…
  • Revolut delays issuance of its own cryptocurrency RevCoin due to the collapse of FTX
  • Peter Thiel closed all positions in BTC ahead of the crypto winter. Gold…
  • Trump’s NFT collection breaks all records. Daily sales…
  • Binance Pay Adds DT One Mobile Funding Option
  • Alphabet Inc to lay off 12,000 employees
  • China has implemented smart contracts in the electronic yuan
  • Ukraine shared the results of blocking Russian…
  • CoinDesk may pass into the hands of the holding in which Binance invests
  • Bitcoin breaks $22,000 for first time since mid…
  • Bitcoin rises to $23,000 and exits the bearish trend
  • Weekly: Bitzlato is a scam, Genesis files for bankruptcy, Coindesk is for sale, and…
  • US seizes $700 million in funds from SBF
  • A single BTC miner mines a block with a hashrate of 10 TH/s

Follow Us On Twitter

  • Home
  • About Us
  • CCPA
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms of Use
Email: contact@cryplogger.com

© 2021-23 Cryplogger.com
CrypLogger is a cult magazine about bitcoin, blockchain technology and the digital economy. Every day we supply news and analytics on the cryptocurrency market since 2021.

No Result
View All Result
  • Home
  • Artificial Intelligence
  • Forecasts
  • News
  • Opinions

© 2021-23 Cryplogger.com
CrypLogger is a cult magazine about bitcoin, blockchain technology and the digital economy. Every day we supply news and analytics on the cryptocurrency market since 2021.

Go to mobile version