Hackers attacked decentralized exchange (DEX) QuickSwap today, making away with $220,000 in a flash loan exploit.
The DEX said Monday that it had closed QuickSwap Lend, its lending protocol, following the exploit. It added that the only platform hit by an exploit was its Market XYZ lending market.
Users also didn’t lose any funds, according to the DEX. Flash loans, popular in the world of DeFiDeFi (decentralized finance), allow crypto users to take out instant loans without collateral.
⚠️QuickSwap Lend is closing⚠️
🔗$220k was exploited in a flash loans attack due to a vulnerability with the Curve Oracle, which @marketxyz was using
☣ Only the Market XYZ lending market was compromised. QuickSwap's contracts are unaffected
But they are prone to exploits—like QuickSwap’s today. Flash loan exploits—which happen a lot in DeFi—are when a highly capitalized bad actor manipulates the price of an asset by taking out lots of loans, and then quickly sells back the borrowed capital to earn a profit.
Blockchain security firm PeckShield posted details of the exploit. A few hours later, the hackers were using sanctioned coin mixer Tornado Cash to hide the origin of the funds, according to Etherscan data.
People use QuickSwap to swap tokens. As a DEX, it requires no sign-up (unlike a centralized exchange like Coinbase) and has no middle-man—so anyone can use it.
QuickSwap is a fork of the Uniswap DEX, one of the biggest DeFi apps in the crypto space. But unlike Uniswap, it doesn’t run on Ethereum but Polygon, the blockchain which hosts the 12th biggest cryptocurrency, MATIC.
Even if you’re relatively new to crypto, you may have bought or traded Bitcoin, Ethereum and other assets on a cryptocurrency exchange. Exchanges like Binance and Coinbase are some of the most successful businesses in the crypto space; Coinbase, one of the leading exchanges, went public in a direct listing earlier this year. Binance, Coinbase, Gemini, Kraken, and others are called "centralized exchanges," since one company operates them and reaps profit from operating them.
The Ultimate Beginner...
DEXs are vulnerable to flash loans and other hacks, though, and as users are completely in control of their funds, there is no insurance—as there would be on a centralized exchange.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
Raydium's native token, Ray, rose sharply on Monday, driven by the decentralized exchange's "deep liquidity," even as it faces stiff competition from the recently launched rival PumpSwap, according to one core contributor.
As the 133rd largest crypto by market capitalization, Ray is trading at about $1.95, according to crypto data provider CoinGecko.
It is up 25% over the past 14 days, recovering ground lost earlier this year as Pump.fun grew more popular.
Ray had dropped 7.6% over a five-minut...
Real-world asset have notched a combined $10.216 billion in total-value locked on decentralized platforms as digitizing traditional financial instruments becomes increasingly popular in Web3.
The total is spread across 79 DeFi platforms, with the top three RWA protocols accounting for 36% of that total-value locked, according to DeFiLlama. The top three RWA protocols—Maker RWA, BlackRock BUIDL and Ethena USDtb—hold $1.298 billion, $1.232 billion and $1.182 billion in TVL, respectively.
Analyst...
Ethereum real-world asset platform Zoth has suffered an attack that resulted in the loss of $8.85 million. Security experts believe the hack, the second suffered by the company in a month, came about as the result of a private key leak.
On Friday morning, a Zoth proxy contract was upgraded by what security firm Cyvers called a "suspicious address.” Soon thereafter, $8.85 million worth of stablecoin USD0++ was transferred out of the proxy contract into the attackers wallet before all funds were s...