Latest Blockchain news from around the world

Euler Finance blocks weak module, engaged on recovering funds

0



Decentralized finance (DeFi) lending protocol Euler Finance grew to become a sufferer of a flash mortgage assault on March 13, ensuing within the largest hack of crypto in 2023 up to now. The lending protocol misplaced practically $197 million within the assault and impacted greater than 11 different DeFi protocols as effectively.

On March 14, Euler got here out with an replace on the state of affairs and notified its customers that that they had disabled the weak Etoken module to dam deposits and the weak donation perform.

The agency mentioned that they work with varied safety teams to carry out audits of its protocol, and the weak code was reviewed and authorized throughout an outdoor audit. The vulnerability was not found as a part of the audit.

The vulnerability remained on-chain for eight months till it was exploited, regardless of a $1 million bug bounty being in place throughout that point.

Sherlock, an audit group that has labored with Euler Finance previously, verified the foundation explanation for the exploit and helped Euler submit a declare. The audit protocol later held a vote on the declare for $4.5 million, which was handed and later executed a $3.3 million payout on March 14.

The audit group, in its evaluation report, famous that a significant component for the exploit was a lacking well being test in donateToReserves(), a brand new perform added in EIP-14. Nonetheless, the protocol harassed that the assault was nonetheless technically doable even earlier than the existence of EIP-14.

Associated: Greater than 280 blockchains prone to ‘zero-day’ exploits, warns safety agency

Sherlock famous that the Euler audit by WatchPug in July 2022 missed the crucial vulnerability that ultimately led to the exploit in March 2023.

Euler has additionally reached out to main on-chain analytic and blockchain safety corporations, akin to TRM Labs, Chainalysis and the broader ETH safety group, in a bid to assist them with the investigation and get well the funds.

Euler notified that also they are making an attempt to contact these liable for the assault with a purpose to be taught extra in regards to the difficulty and presumably negotiate a bounty to get well the stolen funds.