Cointime

Download App
iOS & Android

Logic flaw: Analysis of the DEUS attack incident

On May 6, 2023, Beijing time, a burn logic flaw was discovered in DEUS’s stablecoin DEI contract, resulting in an attacker gaining approximately $6.3 million in profits.

SharkTeam conducted a technical analysis of the incident and has summarized security measures as a precautionary lesson for future projects, aiming to strengthen the security defenses of the blockchain industry.

Analysis of the Incident

Attacker address:

0x08e80ecb146dc0b835cf3d6c48da97556998f599

Attack contract: 0x2b1a7a457a2c55ba1e03c087cc3e4e5b05b6360f

Vulnerable contract:

0xDE1E704dae0B4051e80DAbB26ab6ad6c12262DA0

Attack transactions:

0xde2c8718a9efd8db0eaf9d8141089a22a89bca7d1415d04c05ba107dc1a190c3

The execution flow of the attack transaction:

1. First, the attacker (0x08e80ecb) calls the attack function of the attack contract (0x2b1a7a45).

2. In the attack function, call the approve->burnFrom->transferFrom function of the vulnerable contract (0xDE1E704d)

3. In the transferFrom function, transfer 1.1 million DEI to your own account, and finally call the swap of the trading pair to exchange DEI for USD and transfer it to the attacker (0x08e80ecb).

Vulnerability analysis:

In the burnFrom function, the allowance of the sender to the account and the allowance of the account to the sender are copied directly.

The attacker first approves the maximum value of the vulnerable contract (0xDE1E704d), and then calls the burnFrom function to input amount=0, that is, directly makes the vulnerable contract (0xDE1E704d) approve the maximum value of the attack contract.

Then directly call the tranferFrom function to transfer 1.1 million DEI to your own address, and finally exchange it into USD through the pair transaction to complete the attack

Vulnerability Summary:

The root cause of this incident lies in a contract vulnerability (RouteProcessor2) related to the invocation permissions of the burnFrom function or a potential error in the _allowance parameter. It is necessary to make modifications based on the actual business requirements of the project. This can be addressed by setting appropriate administrative permissions for burnFrom or by adjusting the _allowance[_msgSender()][account] to _allowance[account][_msgSender()] or similar approaches for fixing the issue.

Security Recommendations:

In light of the recent attack incident, it is important to adhere to the following considerations during the development process:

1. Exercise caution and ensure the rigor of business logic when developing functions related to assets.

2. The vulnerable burnFrom function was introduced during a contract upgrade conducted by the project team on April 16. Therefore, before deploying or upgrading contracts, it is crucial for projects to undergo contract audits by professional third-party auditing teams.

About us

SharkTeam’s vision is to comprehensively protect the security of the Web3 world. The team is composed of experienced security professionals and senior researchers from all over the world. They are proficient in the underlying theory of blockchain and smart contracts, and provide services including smart contract auditing, on-chain analysis, and emergency response. It has established long-term cooperative relationships with key players in various fields of the blockchain ecosystem, such as Polkadot, Moonbeam, polygon, OKC, Huobi Global, imToken, ChainIDE, etc.Official
 website: https://www.sharkteam.org/
Twitter: https://twitter.com/sharkteamorg
Discord: https://discord.gg/jGH9xXCjDZ
Telegram: https://t.me/sharkteamorg

Comments

All Comments

Recommended for you

  • Morgan Stanley: The U.S. dollar will peak before the end of the year and enter a "bear market pattern" in 2025

    Morgan Stanley predicts that the strong US dollar will peak before the end of the year and then enter a "bearish market trend", slowly declining until 2025. The bank believes that due to the Bank of Japan's rate hikes and gradual easing actions by the Reserve Bank of Australia, the potential for the yen and Australian dollar to rise next year is the greatest.

  • Equation News calls out Binance for "insider trading": You are destroying the sentiment of the trading market

    On November 25th, Formula News reported that to those insider traders who participated in the listing of Binance perpetual contracts, please slow down when selling your chips next time. The WHY and CHEEMS crashes you caused resulted in a 100% negative return for everyone involved in the trade, and you are destroying the emotions of the trade. Earlier today, Binance announced the listing of 1000WHYUSDT and 1000CHEEMSUSDT perpetual contracts, which caused a short-term crash in WHY and CHEEMS and sparked intense discussion within the community.

  • U.S. Congressman Mike Flood: Looking forward to working with the next SEC Chairman to revoke the anti-crypto banking policy SAB 121

     US House of Representatives will investigate Representative Mike Flood's recent statement: "Despite widespread opposition, SAB 121 is still operating as a regulation, even though it has never gone through the normal Administrative Procedure Act process." Flood said, "I look forward to working with the next SEC chairman to revoke SAB 121. Whether Chairman Gary Gensler resigns on his own or President Trump fulfills his promise to dismiss Gensler, the new government has an excellent opportunity to usher in a new era after Gensler's departure." He added, "It's not surprising that Gensler opposed the digital asset regulatory framework passed by the House on a bipartisan basis earlier this year. 71 Democrats and House Republicans passed this common-sense framework together. Although the Democratic-led Senate rejected it, it represented a breakthrough moment for cryptocurrency and may provide information for the work of the unified Republican government when the next Congress begins in January next year."

  • Indian billionaire Adani summoned by US SEC to explain position on bribery case

    Indian billionaire Gautam Adani and his nephew, Sahil Adani, have been subpoenaed by the US Securities and Exchange Commission (SEC) to explain allegations of paying over $250 million in bribes to win solar power contracts. According to the Press Trust of India (PTI), the subpoena has been delivered to the Adani family's residence in Ahmedabad, a city in western India, and they have been given 21 days to respond. The notice, issued on November 21 by the Eastern District Court of New York, states that if the Adani family fails to respond on time, a default judgment will be made against them.

  • U.S. Congressman: SEC Commissioner Hester Peirce may become the new acting chairman of the SEC

    US Congressman French Hill revealed at the North American Blockchain Summit (NABS) that Republican SEC Commissioner Hester Peirce is "likely" to become the new acting chair of the US Securities and Exchange Commission (SEC). He noted that current chair Gary Gensler will step down on January 20, 2025, and the Republican Party will take over the SEC, with Peirce expected to succeed him.

  • Tether spokesperson: The relationship with Cantor is purely business, and the claim that Lutnick influenced regulatory actions is pure nonsense

     a spokesperson for Tether stated: "The relationship between Tether and Cantor Fitzgerald is purely a business relationship based on managing reserves. Claims that Howard Lutnick's joining the transition team in some way implies an influence on regulatory actions are baseless."

  • Bitwise CEO warns that ETHW is not suitable for all investors and has high risks and high volatility

    Hunter Horsley, CEO of Bitwise, posted on X platform that he was happy to see capital inflows into Bitwise's Ethereum exchange-traded fund ETHW, iShares, and Fidelity this Friday. He reminded that ETHW is not a registered investment company under the U.S. Investment Company Act of 1940 and therefore is not protected by the law. ETHW is not suitable for all investors due to its high risk and volatility.

  • Musk said he liked the "WOULD" meme, and the related tokens rose 400 times in a short period of time

    Musk posted a picture on his social media platform saying he likes the "WOULD" meme. As a result, the meme coin with the same name briefly surged. According to GMGN data, the meme coin with the same name created 123 days ago surged over 400 times in a short period of time, with a current market value of 4.5 million US dollars. Reminder to users: Meme coins have no practical use cases, prices are highly volatile, and investment should be cautious.

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.

  • Meta’s prototype ‘full holographic’ glasses could be a game changer for Web3

    The new holographic display could give NFTs the Pokemon Go treatment.