👀 家人们,每天看行情、刷大佬观点,却从来不开口说两句?你的观点可能比你想的更有价值!
广场新人 & 回归福利正式上线!不管你是第一次发帖还是久违回归,我们都直接送你奖励!🎁
每月 $20,000 奖金等你来领!
📅 活动时间: 长期有效(月底结算)
💎 参与方式:
用户需为首次发帖的新用户或一个月未发帖的回归用户。
发帖时必须带上话题标签: #我在广场发首帖 。
内容不限:币圈新闻、行情分析、晒单吐槽、币种推荐皆可。
💰 奖励机制:
必得奖:发帖体验券
每位有效发帖用户都可获得 $50 仓位体验券。(注:每月奖池上限 $20,000,先到先得!如果大家太热情,我们会继续加码!)
进阶奖:发帖双王争霸
月度发帖王: 当月发帖数量最多的用户,额外奖励 50U。
月度互动王: 当月帖子互动量(点赞+评论+转发+分享)最高的用户,额外奖励 50U。
📝 发帖要求:
帖子字数需 大于30字,拒绝纯表情或无意义字符。
内容需积极健康,符合社区规范,严禁广告引流及违规内容。
💡 你的观点可能会启发无数人,你的第一次分享也许就是成为“广场大V”的起点,现在就开始广场创作之旅吧!
DeFi Protocol Sturdy Finance Exploited for 442 ETH Worth Almost $800K
Sturdy Finance – a DeFi project promising up to 10x leverage on staked assets – has been exploited by a hit-and-run attack on its pricing oracle.
Although the amount stolen (worth about $800k at the time this article was written) pales in comparison to other, more high-profile attacks like the one on Atomic Wallet users just last week, it also ensures that laundering the profits will not be nearly as hard as it is for cybercriminals who have made off with much bigger takings.
Price Manipulation
The attack on Sturdy Finance was carried out via reentrancy exploit, a common method of attacking DeFi projects that entails repeatedly calling a function in a smart contract before the original call is completed.
In order to attack Sturdy Finance, the hacker first established the vulnerability of the protocol’s price oracle – the part of Sturdy’s eco that determines the current value of assets to be used in trading and loans – to reentrancy exploits. Once the vulnerability was established, a flashloan from AAVE provided the liquidity necessary for the attack.
This allows the bad actor to withdraw more funds than the smart contract should allow them to. In this case, the price of staked Ether (stETH) was manipulated three times in a row in order to enable the bad actor to withdraw more than the loan should allow them to, pay off the original loan, and cash out the extra funds. This process was then repeated on five occasions, each time using a different smart contract.
The exploit resulted in a loss of 442 ETH for Sturdy, a takeaway already on its way to Tornado Cash.
Post-Mortem in Progress
The security team at Sturdy confirmed that the exploit has been noted, and their operations have been paused for the moment to conduct a proper post-mortem. The team also asserted that no other funds are currently at risk of being stolen.
Sturdy’s community is understandably upset at the news, with some users proclaiming disbelief that attacks typical of the 2017 shitcoin boom era are still happening today.