Skip to main content

Belt Finance suffers exploit: history repeats itself



Another DeFi exploit shakes the BSC community. And once again a flash loan played the central role. The Belt Finance team had to admit yesterday that there was an incident on May 29 that drove investors $ 50 million. The attacker only made a little more than 6 million US dollars. The rest was on fees and is now part of the investor's loss.

With a flash loan, you can borrow extremely large sums provided that you repay them in the same transaction. The attacker used this mechanism to exploit gaps in the pool's strategy and suck liquidity from it. In the case at hand, it hit the beltBUSD pool, which was targeted eight times in a row in a short period of time. 

In response, the developers stopped all deposits and withdrawals to prevent further damage. Now they want to have further audits carried out in order to rule out that such an incident could repeat itself in the future. They are also said to be working on a plan to compensate those affected.

Copied Ethereum and yet learned nothing?

At the start of the Binance Smart Chain and the in-house DeFi ecosystem, the exchange had to take a lot of criticism. One part focused on the question of whether the BSC is also decentralized and another denounced that the many DeFi products were simply copies of what had already been developed on the basis of Ethereum.

In fact, the rise of the Ethereum-based DeFi ecosystem in 2020 was accompanied by very similar exploits. This gives rise to the suspicion that the old mistakes have simply been adopted, but in the end, it is not that simple. Because even in the case of Belt Finance, several smart contracts interlock and form a complex network. And with this as well as all other exploits, the interplay of the various decentralized financial products was the attacker's actual target.

It can therefore be assumed that DeFi will always have a residual risk in this regard, regardless of the respective chain. Even if a log has been audited, there are no guarantees for interested investors.

FaucetPay &  My Top Picks of their linked 
Honeygain - Passive earner that pays in BTC or PayPal
BetFury - Stack BFG for daily dividends - Play smart!
Pipeflare - Faucet that pays in ZCash and Doge, Games pay in DAI
Womplay - Mobile dApp gaming platform that rewards in EOS
Cointiply - The #1 Crypto Earning Site                                       LiteCoinPay - The #1 FaucetPay earner for Litecoin                               Upland - Collect Digital Properties & Test Your Skills                            Publish0X - Earn Money By Writing and Reading Articles!                       LBRY/Odysee - YouTube Alternative that lets you earn Money by viewing videos!

FaucetPay - The #1 Microwallet Platform
FREEBTC - The #1 FaucetPay earner for Satoshi's
FaucetCrypto - An earning/faucet site that pays out instantly
FireFaucet - An earning site that pays better for some than Cointiply
DogeFaucet - Dogecoin Faucet
xFaucet - BTC, ETH, LTC, Doge, Dash, Tron, DGB, BCH, BNB, ZEC, FEY - Claim every 5 minutes
Konstantinova - BTC, ETH, LTC, Doge, Dash, Tron, DGB, BCH, BNB, ZEC, USDT, FEY, 25 Claims Daily

Comments

Popular posts from this blog

From offchain to offchain: Statechains meets Lightning

  Without a doubt, the most significant off-chain Bitcoin solution is the Lightning network. But in its wake, the statechain has emerged as an intriguing replacement. There is currently a proposal to link the two offchain networks. From an ocean, for example, you can see sunbeams glistening in the water, waves rippling, and possibly a jellyfish drifting toward the light. But you only see a small portion of it. The distance from the sea's surface to its bottom is hundreds of meters. It has dozens of different fish species swimming in it, crabs and starfish crawling on the bottom, shells clinging to rocks, and sea plants climbing up. A completely new world starts where your gaze diverges. You can picture a blockchain like Bitcoin, just like the sea. What you see on the outside is only a small portion of what is actually there; the set of UTXOs (coins) and transaction history that full nodes store are just the beginning of a much larger world. It's the plan, at least. With Bitcoin...

Phishing attack on popular crypto sites tries to empty wallets

  Several major crypto sites such as Etherscan, CoinGecko, DeFi Pulse, and others report malicious pop-ups scammers use to try to trick users into connecting their MetaMask wallets. The phishing attack came from a domain displaying the Bored Ape Yacht Club (BAYC) logo. "We are investigating the root cause of this attack to fix the threat as soon as possible," CoinGecko founder Bobby Ong tweeted. The phishing attack appears to have been triggered by a malicious ad script from Coinzilla, a crypto ad network, according to CoinGecko. Etherscan also advises its users not to confirm any transactions that may appear on the website. The attackers attempted to use the hype around the “bored monkeys” non-fungible tokens (NFT) to gain access to the cryptocurrencies of unsuspecting website visitors. Although the websites affected by the scam attempt have reacted in the last few hours and deactivated the advertising pop-up, it is still recommended not to connect your MetaMask wallet to ne...

Bored Ape Yacht Club NFTs stolen through phishing on Instagram

  Bored Ape Yacht Club ( BAYC ) developers announced on Monday that hackers have hijacked the official Instagram page of the popular NFT collection and posted links to a fake airdrop. Crypto enthusiasts who connected their MetaMask wallet to the rogue website subsequently had their Ape NFTs stolen. Apparently, the attack was planned to coincide with the one-year anniversary of the BAYC collection. This increased the "perceived credibility" of the phishing link. About 100 NFTs are said to have been stolen in the phishing attack . According to CoinGecko data , the minimum price for a BAYC NFT is 139 Ether ( ETH ) or $400,726. So if reports are correct, over $40 million worth of NFTs were stolen in the attack. These numbers are only the lowest estimate, however, as they are based on the lowest price.  At the time of writing, it was still unclear how the hackers gained access to BAYC's official Instagram account. Social media users have pointed out the importance of two-fact...