A few hours ago, Penpie @Penpiexyz_io , a farming protocol built on the Pendle Protocol, suffered a reentrancy attack resulting in a loss of ~$27M. Since Penpie has been paused, we are now providing a detailed root cause analysis.
This is a typical issue due to the lack of reentrancy guard. Specifically, the vulnerable contract (0xff51c6, the implementation contract of PendleStaking) fails to consider that the provided argument, i.e., markets, might be untrusted, which can abused to reenter into this contract.
Attack preparation TX: https://t.co/GfqcLFioiO
The attacker initially created a counterfeit SY (standardized yield token, i.e., 0x4476b). Although the SY tokens themselves were worthless, the contract was set up with two high-value PENDLE-LPT market tokens (i.e., 0x6010_PENDLE-LPT, 0x038c_PENDLE-LPT) as the reward tokens. By doing so, the attacker then created a market on Pendle and registered it on Penpie.
Attack TX: https://t.co/tyI6SmL5Ao
During the attack, the attacker executed the batchHarvestMarketRewards() function to harvest rewards, which were calculated based on the difference in balanceOf() before and after the redeemRewards() function was invoked. The redeemRewards() function, in turn, triggered the claimRewards() function of the specific market. As the protocol did not anticipate the possibility of a market being maliciously controlled, the attacker was able to re-enter the victim contract through the depositMarket() function.
After that, the attacker deposited the two high-value LPT market tokens, which were mistakenly treated as rewards. Simultaneously, the attacker received minted shares corresponding to these deposits. Consequently, the attacker could withdraw the same valuable LPT market tokens along with the corresponding shares minted in depositMarket(), and claim the reward to realize a profit.
๐จ Again another victim lost $72,857 (28.89 $stETH) 10 minutes ago, due to a malicious smart contract interaction. ๐คฆ๐ปโโ๏ธ
๐ฉI've reached out to the victim via an on-chain message for more details on the incident and am currently monitoring the movements of the scammer...๐
More details soon...๐๐ป
๐จ Alert: A user lost $809,851 (321 $stETH) just 2 hours ago due to a malicious smart contract interaction.
๐ฉI've reached out to the victim via an on-chain message for more details on the incident and am currently monitoring the movements of the scammer...๐
Stay tuned for further updates...๐๐ป
@_nikolajankovic Google Ads can't auto-detect cloaking. For faster action, report the ad for trademark issues and urge @defisaver to report it too. Human review is needed.
๐จ ATTENTION WEB3 USERS! ๐จ
Beware of fake dApp websites! Scammers are still using Google Ads to trick you.
Example: Searching "defisaver" on Google?
The top ad might lead you to "defissaver .com" - a scam site with Inferno drainer! ๐
Always double-check URLs & never sign transactions hastily. Stay safe out there! ๐
#Web3Security
*BTW @DeFiSaver you should do something about it!
๐จ 1 hour ago (sealgoodman.eth) lost $26,067 (1000 $PIXL) by interacting with a malicious smart contract.
Iโve sent an on-chain message to the victim to understand what happened and am tracking the crypto scammer...๐
More details below...๐๐ป
๐จ Someone just lost 3.69 $ETH ($9,219.56) by interacting with a fake claim function in a malicious smart contract.
Iโve sent an on-chain message to the victim to understand what happened and am tracking the scammers...๐
More details below...๐๐ป
๐จ Just uncovered a smart contract thatโs been siphoning multiple approvals through interactions with wallets. Some of these wallets hold massive fortunes that could be at risk of being drained. ๐ต๏ธโโ๏ธ
โ ๏ธ Users, be extremely cautious and make sure to revoke any unnecessary approvals immediately!
Stay safe out there. More details soon...
๐จ 1 hour ago someone lost $180,198 (67 $stETH) by interacting with a malicious smart contract.
Iโve sent an on-chain message to the victim to understand what happened and am tracking the crypto scammer...๐
More details below...๐๐ป