Cointime

Download App
iOS & Android

Ankr: Will Use Reserves to Compensate Liquidity Providers for aBNBc Pools

Validated Project

Cointime staff: Ankr, a decentralized finance (DeFi) protocol on the BNB chain, has been hit with a $5 million exploit. A total of 10 trillion aBNBc was minted and later swapped by the attacker for 4,050,500 USDC and 5,000 BNB tokens.  Ankr announced that they will use reserves to compensate liquidity providers for the aBNBc pools.

The aBNBc Token Report: Security Updates Applied & Compensation for Affected LPs

Ankr identified a hack on Dec. 1st, in which malicious actors accessed the developer private key and altered the smart contract for our BNB liquid staking token (aBNBc). After internal research and assessment, we estimate the damage to be $5m worth of BNB across liquidity pools in various DEXes. Ankr has already restored security and will promptly compensate affected liquidity providers.

“Thanks to the fast actions from the Ankr team and various protocols, we were able to minimize any damage done extremely quickly. Hacks and exploits from bad actors like this are an unfortunate possibility in Web3, even with every attention to detail in security processes – but we were well prepared. Unlike previous events in the space this year, we are doing the right thing by our community and ensuring that this is taken care of immediately with lost funds restored.”

– Chandler Song, Co-Founder & CEO, Ankr

What happened?

The exploiter was able to leverage the smart contract for the aBNBc token to create an infinite amount of this token and then exchange it for USDC. The aBNBc token represents a staked version of Binance's BNB token that earns rewards from validation efforts.

The aBNBb smart contract was safe from third-party minting prior to the attack, however, the attacker was able to obtain access to the deployer key. The attacker then uploaded a new aBNBb contract that included an extra method to mint without authorization checks. The attacker minted an excess of aBNBb out of thin air and rapidly moved to swap it out for other tokens on decentralized exchanges.

The address 0xf3a used the infinite mint bug in Ankr's contract code to mint a total of 60 trillion aBNBc across 6 different transactions. The attacker was able to swap some for the stablecoin USDC and began moving them off of the Binance Smart Chain and onto Ethereum before the transactions were flagged. The Ankr team confirmed that the losses incurred are in the region of $5 million in BNB. No other liquid staking tokens or Ankr products have been affected. Likewise, Ankr’s validators, RPC API, and AppChain services continue to operate without any disruptions.

As this occurred, Ankr simultaneously:

  1. Alerted known off-ramps to implement their emergency plans (minimum: halt trading)
  2. Secured the smart contracts with a new key to prevent any further tampering.
  3. Updated smart contracts and systems to temporarily pause the movement of the underlying collateral (BNB) to be safe.

What are the next steps for Ankr?

The team at Ankr is working hard to resolve this issue completely and efficiently. We have taken the necessary steps to offset the loss of funds and resolve the attack.

  • We are identifying all those who provided liquidity to DEXes and all protocols supporting aBNBc or aBNBb LP, as well as aBNBc collateral pools (Midas, Helio) and we will notify all affected parties.
  • Ankr will purchase $5 million worth of BNB and use this to compensate the liquidity providers that have been affected by the exploit due to the drainage of liquidity pools. We understand diluted aBNBc was speculatively traded after the exploit occurred, but we are only able to compensate LP’s caught off guard by the event.
  • We are discontinuing aBNBc and aBNBb tokens effective immediately, and new ankrBNB tokens will be minted and airdropped to affected aBNBc and aBNBb users.
  • We will use a snapshot and airdrop the newly-released ankrBNB tokens to all valid aBNBc holders before the snapshot. User collateral is safe with all of BNB collateral.

What should you do as a user?

To mitigate risks, Ankr is issuing the following guidelines for liquidity providers:

  1. Do not trade aBNBc or speculatively buy it at a discount.
  2. Remove liquidity from DEXes if you are a liquidity provider (and retain the aBNBc token).
  3. Our snapshot taken on Dec-02-2022 12:43:18 AM +UTC will identify you if you are an affected LP.
  4. Wait for the ankrBNB airdrop, which will be proportional to the amount of aBNBc and aBNBb that you held. ankrBNB will be redeemable against staked BNB.

This action plan allows the team at Ankr to more rapidly restore value to legitimate token holders while also accelerating the planned migration to an upgraded contract.

At this stage, all necessary precautions are being taken to promptly resolve the situation and restore lost capital. As mentioned, Ankr will purchase $5m worth of BNB to compensate previous liquidity providers that have been affected by the exploit due to the drainage of liquidity pools.

Ankr understands the concern this has created within the community and will continue working to mitigate the situation and prevent future similar incidents.

Please note that, at this time, all user funds and underlying staked assets are safe. All aBNB users will retain their positions from before, including staked LP Tokens in Farms and accumulation of rewards during that time for doing so.

Comments

All Comments

Recommended for you

  • The Bitcoin-native stablecoin bitSmiley Alphanet V1 Surpasses $24M TVL in 24 Hours!

    In a remarkable achievement, bitSmiley's Alphanet V1 skyrocketed to over $24 million in TVL within just 24 hours of its launch with over 6 million bitUSD stablecoins minted through over-collateralization. bitSmiley stands as a pioneering initiative, introducing stablecoins by over-collateralizing Bitcoin.

  • Securitize raises $47M in funding led by BlackRock to enhance innovation and expansion in digital asset securities ecosystem

    Miami-based company Securitize, which specializes in tokenizing real-world assets, has raised $47 million in funding. The round was led by BlackRock, with participation from Hamilton Lane, ParaFi Capital, Tradeweb Markets, Aptos Labs, Circle, and Paxos. The funds will be used to enhance the company's innovation and expansion as it consolidates its position in the digital asset securities ecosystem. BlackRock's first tokenized fund, the BlackRock USD Institutional Digital Liquidity Fund, has also been launched on Ethereum and is available to investors by subscribing to the fund with Securitize.

  • Web3 game Shadow War completes $5 million financing, led by Momentum 6

    Game studio Patriots Division has raised $5 million in seed and Series A financing for its Web3 game Shadow War. The Series A funding was led by Momentum 6, with participation from iAngels, Cointelligence Fund, Xborg, Andromeda VC, Cogitent Ventures, and Cluster Capital.

  • BTC falls below $57,000

    According to market data, BTC has fallen below $57,000 and is currently trading at $56,999.99, with a daily decline of 5.48%. The market is volatile, so please be prepared for risk control.

  • CoreWeave, an AI cloud service provider, completes $1.1 billion Series C financing led by Coatue

    CoreWeave, a cloud service provider focusing on artificial intelligence, announced the completion of a $110 million Series C financing round. Coatue led this round of financing, with Magnetar (the main investor in the previous round), Altimeter Capital, Fidelity Management & Research Company, and Lykos Global Management participating.

  • Cointime MAY 1 News Express

    1.Celsius Network destroys 94% of total supply of CEL, worth over $89 million2.USDC Treasury destroyed more than 200 million USDC3.Pike was suspected of being hacked and lost 479 ETH4.Fantom launches $6.5 million development fund, betting on safer memecoins5.Yesterday, the U.S. spot Bitcoin ETF had a net outflow of $162 million6.The balance of Binance Bitcoin wallet increased by 6249.36 in the past 24 hours, and 15565.89 inflows in the past 7 days7.In April, NFT sales on the Bitcoin chain exceeded US$685 million, setting the third highest monthly record in history8.On-chain content distribution agreement Metale Protocol completes additional $2 million in seed round financing9.A whale deposited 1,140 MKR into Coinbase, losing about $1.1 million10.The Bitcoin stablecoin project, bitSmiley, goes live with its Alphanet V1, marking its debut deployment on the Bitcoin Layer 2 network, Bitlayer.

  • Barcelona-based Web3 Video Games Startup GFAL Raises $3.2M in Seed Funding to Expand Team and Accelerate Production Plans

    Barcelona-based startup GFAL has secured $3.2 million in seed funding from investors including Supercell Ltd and Mitch Lasky. The company plans to use the funds to expand its team and accelerate its game production plans, which leverage AI and Web3 technology for immersive gameplay. GFAL's Elemental Raiders mobile game soft-launched in March 2023, with plans to build on this for a 2024 launch. CEO Manel Sort expressed gratitude for the investment and excitement to work with former colleagues from Digital Chocolate.

  • BTC falls below $58,000

    Golden Finance reported that according to OKX market data, BTC briefly touched $57,700 and is now trading at $58,581.53, with a daily decline of 7.15%. The market is volatile, so please be prepared for risk management.

  • On-chain content distribution agreement Metale Protocol completes additional $2 million in seed round financing

    Metale Protocol, a content distribution protocol on the blockchain, announced the completion of an additional $2 million seed round of financing. Waterdrip Capital led the investment, with participation from Aipollo Investment and Ultiverse. As of now, the total size of its seed round financing has reached $4 million. Metale Protocol was formerly known as Read2N, a Web3 decentralized reading application. The new funds will be allocated to its content creation fund to stimulate more content creation activities and promote the construction of its protocol as a platform for issuing and distributing content assets on the blockchain.

  • DWF Ventures announces investment in blockchain game developer Overworld

    DWF Ventures announced an investment in Overworld, a chain game developer. Overworld recently announced plans to launch another NFT series, and in addition, Overworld will soon launch the main world arena.