The Zunami Protocol, a decentralized finance (DeFi) platform, confirmed Sunday that its liquidity pool on Curve Finance was attacked, leading to a loss of over $2.1 million. The hack was reported by blockchain security firms PeckShield and Ironblocks.
Zunami Protocol is a yield farming aggregator for stablecoin staking, and maintained its primary "zStables" pool on Curve, which enables the decentralized exchange (DEX) of stablecoins within Ethereum.
Zunami, managed as a decentralized autonomous organization (DAO), promised "the highest APY on the market" and touted $5 million total value locked on its website. The cross-chain protocol claimed to allow users to "diversify their stablecoin portfolio and avoid the risk of crashing one of them."
The scheme used in the attack was a familiar one to blockchain watchers.
"The attacker took [a] flash loan from [the] balancer, then he added liquidity so he [would] be able to change the price significantly and started to trade in Zunami's exchange," Ironblocks explained. "Then he removed the liquidity and changed the price, then he traded back and [returned] the flash loan and got 1,152 ETH to himself.
This morning, Curve Finance said that apart from several Ethereum pools, an Arbitrum-based liquidity pool may have also been "potentially affected" over the weekend.
Curve Finance is a popular decentralized exchange (DEX), letting users swap like-assets such as Ethereum for Staked Ethereum, or Tether's USDT for Circle's USDC. It can be a helpful arbitrage tool for many traders should those assets decouple in price from one another.
Per initial reports, the platform was exploited on Sunday for ov...
Fellow blockchain analysis firm PeckShield, which has been tracking attacks on Curve, also detected the Zunami attack and notified the protocol on Twitter.
Hi @zunamiprotocol, we have detected an ongoing attack. Users are strongly suggested to take necessary actions.
Here is the encrypted hash: 2638ae2969ce932d61c3ca66f9b8a4a6c01c4d89bb2b34ddcf2c4145960f41c4. Actual hash will be released once the situation is stable.
"Today's hack leads to more than $2.1 million loss and there are two hack transactions involved," Peckshield explained in a follow up. "It is a price manipulation issue, which can be exploited by donation to incorrectly calculate the price."
"It appears that zStables have encountered an attack. The collateral remain secure, we delve into the ongoing investigation," Zunami posted to Twitter a few moments later. "Please do not buy zETH and UZD at the moment, their emission has been attacked."
The price of both the Zunami USD stablecoin (UZD) and Zunami Ether (zETH) fell precipitously as a result of the hack, with the former collapsing entirely—more than 99%—and the latter plummeting over 88% to $206.
Zunami USD Price Chart (UZD) via CoinGecko.
The funds have already been washed through controversial coin mixer Tornado Cash, the firm reported.
Curve Finance has struggled with multiple attacks in recent weeks, and is still attempting to recover about $19 million stolen by a hacker—and put out a $1.8 million bounty for information leading to the identity of the perpetrator.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
HYPE, the native token of Hyperliquid, was a standout performer among altcoins in May, as traders flocked to the decentralized exchange’s perpetual futures offering, according to a report published by asset manager Grayscale on Monday.
HYPE was recently changing hands around $37.72, a 14% increase over the past day, according to crypto data provider CoinGecko. Over the past 30 days, the token’s price has soared 80%. HYPE reached an all-time high of $39.68 just over a week ago.
“Hyperliquid has s...
Publicly traded real estate tech company DeFi Development Corporation further intensified its rapidly growing commitment to Solana with the creation of a liquid staking token alongside a collaboration with Kamino Finance, a leading DeFI protocol in Solana’s ecosystem.
The liquid staking token or LST, called dfdvSOL—which was created with LST platform Sanctum—allows users staking Solana (SOL) via the DeFi Development Corp. validator group to maintain liquidity while their native Solana tokens ar...
An investor’s $1 billion Bitcoin bet on the decentralized exchange Hyperliquid swung massively on Wednesday, with their account surviving a $32 million drawdown on paper, as the asset’s price ping-ponged on a volatile day of trading.
The user, controlling a wallet starting with “0x507,” saw their position whipsaw between a profit and a loss, hours after topping off the 40x leveraged long position, according to blockchain explorer HypurrScan. Bitcoin rose to a record $109,500 earlier in the day....