Cointime

Download App
iOS & Android

An Account of the Recent White Hat Attack on DeFi Protocol Tender.fi

Validated Project

In the latest development in the world of Decentralized Finance (DeFi), Tender.fi, a DeFi lending protocol, fell victim to a white hat attack. The alleged ethical hacker behind the attack had managed to drain a whopping $1.6 million from the platform, forcing the service to halt borrowing while it attempts to recover its assets.

The attack, which took place on Mar-07-2023 at 08:21:38 AM +UTC, has caused significant concern among the DeFi community. According to Numen Cyber’s on-chain monitoring, the attacker siphoned 198 ETH, 541700 USDC, 16 WBTC, 8798 UNI, 50011 DAI, 36700 USDT, 24975 FRAX, and 16,203 LINK, causing the native token of the Tender.fi (TND) project to fall by over 30% before recovering slightly after the recovery of funds.

Timeline of Events

Tender.fi confirmed an incident on March 7th that led to the depletion of funds after various community users raised concerns. Tender.fi took to Twitter to acknowledge the issue and announced that they were investigating an unusually high amount of borrows, which led to the depletion of funds. As a result, the platform temporarily halted all borrowing activities until the investigation was complete.

The native token of Tender.fi (TND) plummeted over 30% in response to news of a suspected black hat hacking incident. The market reacted swiftly, with investors reacting to the news of the platform’s loss of funds.

Vulnerability Details

The attack on Tender.fi has exposed a critical flaw in the platform’s smart contract code, specifically its price oracle, which allowed the attacker to exploit the system and make off with $1.6 million worth of cryptocurrencies. The attacker was able to obtain tGMX tokens by purchasing them with initial funds and then proceeded to borrow using the tETH.borrow method. However, the borrowing process had an error in the price calculation, specifically in the GMXPriceOracle.getUnderlyingPrice method.

The initial price was multiplied by both 1e20 and 1e10, resulting in a significant increase in the price of tGMX tokens. This allowed the attacker to borrow large sums of money, which eventually led to the loss of millions of dollars in funds for Tender.fi.

Attacker’s address:

https://arbiscan.io/address/0x896DF3759205C141c97640B2B7345FA479FEB1aB

Transaction:

https://arbiscan.io/address/0x896DF3759205C141c97640B2B7345FA479FEB1aB

Transaction Details

Post-Mortem

Tenderfi has rewarded a bounty of 62 ETH, which is approximately 6% of the exploited funds, to the White Hat. This amount is consistent with the industry standard for rewarding white hats who find and report security vulnerabilities. The White Hat who discovered the exploit promptly notified the Tenderfi team, who then worked quickly to repay the exploited funds.

Following the transaction’s completion, Tender.fi took to Twitter to confirm that their funds were officially secure. The platform also announced that it would conduct a post-mortem analysis of the attack to identify areas of improvement and prevent similar incidents in the future. Their native token, TND has since bounced back slightly since the recovery of funds.

Conclusion

The swift and cooperative response from both the White Hat and the Tenderfi team is highly commendable. This type of collaboration between security researchers and blockchain companies is critical to creating a safer and more secure ecosystem.

Comments

All Comments

Recommended for you

  • ETH Surpasses $2400

    Market data shows that ETH has surpassed $2400, currently priced at $2400.69, with a 24-hour increase of 3.61%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Iranian Media Confirms Receipt of 'Some Signals' from the U.S. to Lift Blockade

    On April 22, according to Iran's Tasnim News Agency, an Iranian envoy stated that Iran is prepared to negotiate once the U.S. lifts its maritime blockade. The Iranian state media released a video featuring Amir Saeed Iravani, Iran's permanent representative to the United Nations, who indicated that Tehran is ready to engage in talks immediately after the U.S. ends its maritime blockade, emphasizing that Washington must first cease its 'violations of the ceasefire agreement.' Following the report, the market reacted swiftly, with gold and silver prices rising briefly, while the dollar and crude oil prices fell. Previously, media outlets such as the Associated Press and RIA Novosti had reported the ambassador's statements, but this is the first report from Iranian state media linked to the Islamic Revolutionary Guard Corps.

  • Dollar Index DXY Drops 10 Points, Currently at 98.28

    Market data shows that the Dollar Index DXY has dropped 10 points in the short term, currently reported at 98.28.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,008, with a 24-hour increase of 2.79%. The market is highly volatile, so please ensure proper risk management.

  • Iran Receives 'Certain Signs' Indicating US Prepared to Lift Sanctions

    On April 22, according to Iran's Tasnim News Agency: Iran has received 'certain signs' indicating that the United States is prepared to lift sanctions. (Jinshi)

  • Iran Implements Maritime Enforcement on Container Ship Ignoring Warnings

    According to Iran's Tasnim News Agency: Iran has stated that it has implemented maritime enforcement on a container ship that ignored warnings. (Jinshi)

  • Expert: Trump's Hostility Towards Iran Has Deep Roots; US-Israel Leadership Lacks Historical Foundation and Acumen

    On April 22, according to Al Jazeera, Brian Clark, Director of Defense Concepts at the Hudson Institute in Washington, stated: "Trump has expressed disdain for the Iranian leadership for many years, and he seems to have been seeking a legacy initiative that could permanently change Iran, making it at least a 'neutral or even friendlier country towards the US.' Therefore, from this perspective, it is indeed not a new goal he suddenly started pursuing. The leadership of the US and Israel believes that now might be the time to finally subdue the Iranian regime, as it is in a passive position. However, this may reflect a lack of historical foundation and acumen in the US-Israel leadership, as Iran is not a country that can easily have its existing leadership structure overthrown." (Jinshi)

  • US Spot Ethereum ETF Sees Net Inflow of $43.36 Million Yesterday

    On April 22, according to monitoring by Trader T, the US spot Ethereum ETF recorded a net inflow of $43.36 million yesterday.

  • US Spot Bitcoin ETF Sees Net Inflow of $11.83 Million Yesterday

    On April 22, according to monitoring by Trader T, the US spot Bitcoin ETF experienced a net inflow of $11.83 million yesterday.

  • BTC Surpasses $77,000

    Market data shows that BTC has surpassed $77,000, currently reported at $77,067.57, with a 24-hour increase of 1.78%. The market is experiencing significant volatility, so please ensure proper risk management.