Cointime

Download App
iOS & Android

Recklessness Comes at a Cost? Zunami Protocol Attacked for Price Manipulation with a Loss of Over $2.1 Million

On August 14, 2023, Beosin EagleEye detected a price manipulation attack on the Zunami Protocol, a protocol on the Ethereum blockchain. The attack resulted in a loss of 1152 ETH($2.1 million).

It is understood that the Zunami Protocol is a platform that distributes stablecoins to users. It can be seen as a decentralized yield aggregator, providing more beneficial solutions for stablecoin holders.

There is an interesting twist to this incident. A security company had previously warned about vulnerabilities, but the project team did not take these warnings seriously, displaying a nonchalant attitude. As a consequence, by the time the incident occurred, it was already too late.

Beosin security team promptly analyzed the security incident and reported the following findings:

Attack-related Information:

● Attack Transactions:

Tx1: 0x2aec4fdb2a09ad4269a410f2c770737626fb62c54e0fa8ac25e8582d4b690cca

Tx2: 0x0788ba222970c7c68a738b0e08fb197e669e61f9b226ceec4cab9b85abe8cceb

● Attacker's Address:

0x5f4c21c9bb73c8b4a296cc256c0cde324db146df

● Attack Contract:

0xa21a2b59d80dc42d332f778cbb9ea127100e5d75

● Targeted Contract:

0xe47f1cd2a37c6fe69e3501ae45eca263c5a87b2b

Vulnerability Analysis:

The cause of this attack was the vulnerability in the contract where LP (Liquidity Provider) price calculation depended on the contract's own CRV balance and the exchange ratio of CRV in the wETH/CRV pool. The attacker manipulated the LP price by injecting CRV into the contract and manipulating the exchange ratio of the wETH/CRV pool.

Attack Process:

Taking transaction 0x2aec4... as an example:

Attack Preparation:

1. The hacker borrowed 6811 ETH using a balancer:Vault flash loan as attack funds.

2.  They exchanged 300 ETH borrowed through a flash loan for 84 zETH, preparing for the subsequent increase in zETH value

Attack Phase:

1. They exchanged 11 ETH for 35293 CRV and transferred it to the sEthFraxEthCurveConvex contract, enabling the attacker to manipulate the CRV balance in the sEthFraxEthCurveConvex contract for later manipulation.

2. They repeatedly exchanged 406 ETH for CRV in the wETH/CRV pool, causing the price of CRV to increase by approximately 10 times.

3. The value calculation of zETH (LP) depended on the price of CRV tokens and the valuation of CRV to ETH calculations in the sEthFraxEthCurveConvex contract.

4. The attacker manipulated the CRV price and the CRV balance in the vulnerable contract, causing the final _assetPriceCached to increase.

5. Due to the increased _assetPriceCached, the value of 84 zETH increased to 221 zETH.

6. They exchanged the CRV obtained in step 4 back to ETH to repay the flash loan.

7. They exchanged the increased 221 zETH (LP) for 389 ETH.

8. They repaid the 6811 ETH flash loan and other fees, resulting in a profit of 26 ETH.

Funds Tracing:

As of the time of writing, the Beosin security analysis team found that the stolen funds had all been transferred to Tornado cash.

Summary:

In response to this incident, the Beosin security team recommends:

1.  Similar projects should consider different token pool dependencies when calculating LP value.

2.  Before the launch of a project, it's advisable to engage a professional security auditing company for comprehensive security audits to mitigate security risks.

Beosin is a leading global blockchain security company co-founded by several professors from world-renowned universities and there are 40+ PhDs in the team, and set up offices in 10+ cities including Hong Kong, Singapore, Tokyo and Miami. With the mission of "Securing Blockchain Ecosystem", Beosin provides "All-in-one" blockchain security solution covering Smart Contract Audit, Risk Monitoring & Alert, KYT/AML, and Crypto Tracing. Beosin has already audited more than 3000 smart contracts including famous Web3 projects PancakeSwap, Uniswap, DAI, OKSwap and all of them are monitored by Beosin EagleEye. The KYT AML are serving 100+ institutions including Binance.

Contact

If you need any blockchain security services, welcome to contact us:

Offiial Website Beosin EagleEye Twitter Telegram Linkedin

Comments

All Comments

Recommended for you

  • OpenTrade announces $4 million seed extension round led by AlbionVC

    OpenTrade has announced the completion of a $4 million seed extension financing round to build RWA-supported loan and stablecoin yield products. This round of financing was led by AlbionVC, with participation from a16z Crypto and CMCC Global. OpenTrade plans to use the funds to expand its operations and enhance its product capabilities.

  • BNB Chain Ecosystem Re-staking Infrastructure Kernel Receives Investment from Binance Labs

    BNB Chain's ecological re-staking infrastructure Kernel has announced that it has received investment from Binance Labs. As of now, its total financing amount has reached 10 million US dollars, with main investors including: SCB Limited, Laser Digital, Bankless Ventures, Hypersphere, Draper Dragon, DACM, CYPHER, ArkStream Capital, HTX Ventures, Avid VC, GSR, Cluster Capital, Longhash Ventures, Via BTC, Side Door Ventures, NOIA, and DWF Labs. It is reported that Kernel's mainnet is about to be launched. Kelp provides users with support for Ethereum liquidity re-staking services based on rsETH, while Gain provides DeFi, CeDeFi, and RWA income products. KERNEL tokens are designed to unify the governance and incentive mechanisms of Kelp, Kernel, and Gain, while providing rewards for early supporters of ecosystem development.

  • Morgan Stanley: The U.S. dollar will peak before the end of the year and enter a "bear market pattern" in 2025

    Morgan Stanley predicts that the strong US dollar will peak before the end of the year and then enter a "bearish market trend", slowly declining until 2025. The bank believes that due to the Bank of Japan's rate hikes and gradual easing actions by the Reserve Bank of Australia, the potential for the yen and Australian dollar to rise next year is the greatest.

  • Equation News calls out Binance for "insider trading": You are destroying the sentiment of the trading market

    On November 25th, Formula News reported that to those insider traders who participated in the listing of Binance perpetual contracts, please slow down when selling your chips next time. The WHY and CHEEMS crashes you caused resulted in a 100% negative return for everyone involved in the trade, and you are destroying the emotions of the trade. Earlier today, Binance announced the listing of 1000WHYUSDT and 1000CHEEMSUSDT perpetual contracts, which caused a short-term crash in WHY and CHEEMS and sparked intense discussion within the community.

  • U.S. Congressman Mike Flood: Looking forward to working with the next SEC Chairman to revoke the anti-crypto banking policy SAB 121

     US House of Representatives will investigate Representative Mike Flood's recent statement: "Despite widespread opposition, SAB 121 is still operating as a regulation, even though it has never gone through the normal Administrative Procedure Act process." Flood said, "I look forward to working with the next SEC chairman to revoke SAB 121. Whether Chairman Gary Gensler resigns on his own or President Trump fulfills his promise to dismiss Gensler, the new government has an excellent opportunity to usher in a new era after Gensler's departure." He added, "It's not surprising that Gensler opposed the digital asset regulatory framework passed by the House on a bipartisan basis earlier this year. 71 Democrats and House Republicans passed this common-sense framework together. Although the Democratic-led Senate rejected it, it represented a breakthrough moment for cryptocurrency and may provide information for the work of the unified Republican government when the next Congress begins in January next year."

  • Indian billionaire Adani summoned by US SEC to explain position on bribery case

    Indian billionaire Gautam Adani and his nephew, Sahil Adani, have been subpoenaed by the US Securities and Exchange Commission (SEC) to explain allegations of paying over $250 million in bribes to win solar power contracts. According to the Press Trust of India (PTI), the subpoena has been delivered to the Adani family's residence in Ahmedabad, a city in western India, and they have been given 21 days to respond. The notice, issued on November 21 by the Eastern District Court of New York, states that if the Adani family fails to respond on time, a default judgment will be made against them.

  • U.S. Congressman: SEC Commissioner Hester Peirce may become the new acting chairman of the SEC

    US Congressman French Hill revealed at the North American Blockchain Summit (NABS) that Republican SEC Commissioner Hester Peirce is "likely" to become the new acting chair of the US Securities and Exchange Commission (SEC). He noted that current chair Gary Gensler will step down on January 20, 2025, and the Republican Party will take over the SEC, with Peirce expected to succeed him.

  • Tether spokesperson: The relationship with Cantor is purely business, and the claim that Lutnick influenced regulatory actions is pure nonsense

     a spokesperson for Tether stated: "The relationship between Tether and Cantor Fitzgerald is purely a business relationship based on managing reserves. Claims that Howard Lutnick's joining the transition team in some way implies an influence on regulatory actions are baseless."

  • Bitwise CEO warns that ETHW is not suitable for all investors and has high risks and high volatility

    Hunter Horsley, CEO of Bitwise, posted on X platform that he was happy to see capital inflows into Bitwise's Ethereum exchange-traded fund ETHW, iShares, and Fidelity this Friday. He reminded that ETHW is not a registered investment company under the U.S. Investment Company Act of 1940 and therefore is not protected by the law. ETHW is not suitable for all investors due to its high risk and volatility.

  • Musk said he liked the "WOULD" meme, and the related tokens rose 400 times in a short period of time

    Musk posted a picture on his social media platform saying he likes the "WOULD" meme. As a result, the meme coin with the same name briefly surged. According to GMGN data, the meme coin with the same name created 123 days ago surged over 400 times in a short period of time, with a current market value of 4.5 million US dollars. Reminder to users: Meme coins have no practical use cases, prices are highly volatile, and investment should be cautious.