Euler attack causes locked tokens, losses in 11 DeFi protocols, including Balancer

1 year ago

Contagion from the Dec. 12 flash indebtedness onslaught against Euler has dispersed acold and wide, resulting successful frozen oregon mislaid funds for 11 antithetic decentralized concern (DeFi) protocols, according to Dec. 13 reports from each of them connected Twitter. Balancer, an Ethereum protocol with implicit $1 cardinal full worth locked (TVL), is among the affected protocols. Below is simply a rundown of the large exploits and what we cognize truthful far.

Balancer

Balancer reported connected March 13 that the Euler Boosted USD (bb-e-USD) excavation had been affected by the exploit. Approximately $11.9 cardinal worthy of tokens from this excavation were sent to Euler during the exploit. The balancer exigency subDAO reacted by pausing the excavation and putting it into betterment mode. However, implicit 65% of the pool’s TVL had already been mislaid by the clip it was paused.

At 10:00 UTC Balancer contributors became alert of an exploit connected Euler. It was determined the champion people of enactment was to intermission and enactment into betterment mode bbeUSD (Euler Boosted USD) and each pools containing bbeUSD. This was executed by the exigency subDAO astatine 11:00 UTC.

— Balancer (@Balancer) March 13, 2023

As a effect of a bug successful the app’s idiosyncratic interface (UI), liquidity providers cannot retrieve the remaining funds near successful the pool. However, a caller UI volition beryllium offered “in the adjacent future” that volition let the remaining funds to beryllium withdrawn, Balancer said. No different pools person been affected, Balancer clarified.

Angle Protocol

Angle Protocol released a preliminary study connected its vulnerability to the attack. It whitethorn person mislaid implicit $17 cardinal worthy of USD Coin (USDC). This whitethorn person caused the agEUR stablecoin, which is pegged to the euro, to go undercollateralized. The squad is inactive investigating and attempting to hole a elaborate equilibrium sheet. All minting and redemption of agEUR is presently paused, but borrowers tin inactive repay their debts to the protocol arsenic normal, the squad said.

Idle Finance

Idle Finance has provided a elaborate database of its losses owed to the Euler exploit. It seems to person mislaid astir $5.9 cardinal worthy of tokens successful total, based connected March 13 Ether (ETH) and euro prices. The squad has paused each Best Yield vaults and Yield Tranches related to Euler to forestall further losses.

Yearn Finance

Yearn Finance has implicit $423 cardinal successful TVL, according to DeFi Llama. It reported indirect vulnerability to Euler, done Angle Protocol and Idle Finance. It has lost astir $1.38 million. However, the squad said that immoderate atrocious indebtedness not covered by Idle and Angle would beryllium covered by the Yearn Treasury.

Yield Protocol

Yield Protocol is different protocol affected by the exploit. Its "mainnet liquidity pools are built connected Euler," according to the team's announcement regarding the attack. The institution has disabled the mainnet app, paused borrowing, and is investigating the attack. Its mainnet liquidity pools look to person been affected, with a imaginable nonaccomplishment of “less than $1.5 million.”

The Euler hack has affected our mainnet liquidity pools. Yield liquidity pools clasp 2 assets: Euler eTokens and Yield fyTokens. We bash not yet person close figures for the worth of the eTokens held earlier the onslaught but judge the full worth to beryllium little than $1.5 cardinal USD.

— Yield Protocol (@yield) March 13, 2023

InverseFinance

InverseFinance reported that it was deed arsenic well. It's DOLA Fed for the DOLA-bb-e-USD connected Balancer lost implicit $860,000. The squad said it is communicating with Balancer successful an effort to get these funds returned to depositors.

Related: Euler Finance hacked for implicit $195M successful a flash indebtedness attack

SwissBorg

SwissBorg reported that “a tiny information of [its] Smart Yield Program was impacted” by the exploit. However, “the grade of the harm is minimal acknowledgment to our Risk Management Procedure.” The squad said that it would compensate each losses from its funds, and its users “will not endure immoderate nonaccomplishment from this event.”

In a Telegram speech with Cointelegraph, SwissBorg laminitis Cyrus Fazel clarified that the protocol ranks output strategies based connected risk, time, and APY. Since Euler was rated Risk 2- Adventurous, SwissBorg users “had a constricted amount” invested successful Euler. This mitigated against losses to the protocol, helium explained.

Other affected protocols

Opyn, Mean, Sense and Harvest besides reported they mightiness person been affected by the exploit, though nary person provided details connected however overmuch has been lost. This brings the full fig of affected protocols to 11, with $37.6 cardinal successful cumulative losses. 

Euler Finance is simply a crypto borrowing and lending protocol that runs connected Ethereum. It became fashionable acknowledgment successful portion to its enactment for utilizing liquid staking derivatives (LSDs) specified arsenic Coinbase Staked ETH (cbETH) oregon Lido Staked ETH (stETH) arsenic collateral for loans. On March 8, Euler had implicit $311 cardinal successful crypto locked wrong its astute contracts. Since the exploit, its TVL has fallen to $10.37 million.

View source