Cointime

Download App
iOS & Android

Platypus DeFi Recovered 2.4 Million USDC From Yesterday’s 9 Million Exploit

Cointime Official

Decentralized finance protocol Platypus recovered 2.4 million USDC from yesterday's 9 million exploit with the help of smart contract audit firm BlockSec, the team announced on Twitter.

According to MetaSleuth, a crypto funds visualization and analysis tool powered by BlockSec, the attacker could only cash out $270,000 of the almost $9.1 million in stolen funds from Platypus. The first attack, which resulted in a loss of approximately $8.5 million, have been frozen in the attacked contract, while the second attack, which resulted in additional $380,000, was mistakenly transferred to Aave, on-chain data show.

Daniel Von Fange @danielvf revealed how Playtpus hack stolen funds have been recovered:

In a dazzling reverse hack, a substantial chunk of the Playtpus hack stolen funds have been recovered.

Here's how it worked: (1/4)

The attacker forgot to code any way collect the funds after stealing them, so the funds were locked in the attack contract.

They also neglected Flash Loan 101 and allowed anyone to call the flash loan callback code. No check that they had started the flash loan. 2/4

This allowed @BlockSecTeam and the project to retrigger the hack, but with one major twist - the project contracts had been upgraded to steal back from the attacker during the hack. 3/4

The attack sequence involved taking flash loaned USDC, approving it, and depositing into the project.

But during the retrigger, the attack code used its own stolen USDC to approve and deposit instead.

The new project code simply took the attacker's USDC and ran with it. 4/5

This was some magnificent recovery work by @BlockSecTeam. Definitely people to have on your side when things go bad. 5/5

Comments

All Comments

Recommended for you

  • BTC breaks through $67,000

    The market shows that BTC has broken through $67,000 and is now trading at $67,018.39, with a daily increase of 0.85%. The market is volatile, so please be prepared for risk control.

  • Decentralized AI platform Prime Intellect completes $5.5 million seed round of financing

    Decentralized AI platform Prime Intellect has announced the completion of a $5.5 million seed round of financing, led by Distributed Global and CoinFund, with Compound also participating. The funds will be used to build a computing platform that enables decentralized training across instances, and to achieve shared ownership of artificial intelligence models through contributions of computing power, code, data, capital, or expertise.

  • Crypto wallet Turnkey raises $15 million in funding, led by Galaxy Ventures

    Turnkey, a cryptocurrency wallet infrastructure company, has raised $15 million in Series A funding led by Lightspeed Faction and Galaxy Ventures, with participation from Sequoia Capital, Coinbase Ventures, Alchemy, Figment Capital, and Mirana Ventures. The project concluded in October of last year and raised $7.5 million in seed funding starting from 2022. Turnkey was co-founded by two former Coinbase employees who helped build the company's cryptocurrency exchange custody service, with the aim of helping application developers build user-friendly blockchain wallets.

  • Magpie: A vulnerability was found in the contract, and users are advised to cancel authorization as soon as possible

    Cross-chain infrastructure Magpie Protocol published an article stating that there is a vulnerability in the contract and urging users who have authorized its contract and still hold funds in their wallets to cancel the relevant contract authorization on each chain as soon as possible.

  • Messari ·

    State of Sia Q1 2024

    Sia (SC) is a decentralized cloud storage network that combines a Proof-of-Work blockchain with a contract-based storage model.

  • Messari ·

    0x Q1 2024 Brief

    0x is an integrated suite of decentralized finance (DeFi) infrastructure APIs that enables developers and teams to build financial products on crypto rails.

  • SlowMist reveals a new scam: maliciously modifying RPC node links to defraud assets

    SlowMist security team has exposed a new type of cryptocurrency scam. This scam uses the remote procedure call (RPC) function of modified Ethereum nodes to commit fraud. The specific process of the scam is as follows: the scammer induces the user to download the imToken wallet and gain the user's trust by using 1 USDT and a small amount of ETH as bait. Then, the scammer guides the user to change their ETH's RPC URL to the node controlled by the scammer. The node uses Tenderly's fork function to falsify the user's USDT balance. When the user sees the incorrect balance, they may attempt a transfer, but the scammer has already disappeared. According to SlowMist Technology's report, this type of scam exploits users' trust and negligence, resulting in asset losses. The SlowMist security team reminds users to remain vigilant when trading and avoid using untrusted RPC nodes.

  • The Future of Ethereum: Use Cases (Part 1)

    In our 4-part series named “The Value of Ether”, we have discussed in detail the framework in which we think it is most appropriate to link value accrual to ETH token holders with the underlying mechanics that operate the Ethereum blockchain. More specifically, we have laid out a case on how increased usage of the network has an impact on supply dynamics and can therefore have a knock-on effect on the value of the Ether token.

  • Philippines SEC: Remove Binance App from Google and Apple App Stores

    Philippine Securities and Exchange Commission stated that we have taken action to remove the Binance app from the Google and Apple app stores.

  • BTC falls below $66,000

    The market shows that BTC has fallen below $66,000, currently trading at $65,997.14, with a daily decline of 0.02%. The market is volatile, please be prepared for risk control.