Mango Market hacker’s attempt to exploit Aave fails

1 year ago

Mango Market’s exploiter Avraham Eisenberg’s effort to replicate his “highly profitable trading strategy” connected Aave (AAVE) has failed, resulting successful the nonaccomplishment of millions.

CRV warfare was played retired connected #Aave yesterday and ended with the longer defeating the shorter.

1.🧵

ponzishorter.eth shorted $CRV by borrowing and dumping $CRV;$CRV guardians bought $CRV, soaring the terms to $0.72, and liquidating each collateral of ponzishorter.eth.

— Lookonchain (@lookonchain) November 23, 2022

Lookonchain reported that ponzishorter.eth — an code associated with Eisenberg — transferred $40 cardinal USD Coin (USDC) into Aave to get Curve (CRV) token with the volition of shorting. This resulted successful CRV terms tanking 26% to $0.464 from $0.625 implicit the past week.

However, the determination didn’t spell wholly arsenic planned arsenic the assemblage rallied down CRV, buying the DeFi token and causing its worth to spike 46% successful the past 24 hours to arsenic precocious arsenic $0.71

First, helium came for Mango, and I did not talk out, for I americium not an investor

Then helium came for USDT, and I did not talk out, for helium did not airs a risk

Now, helium tries to hunt the indebtedness of 1 of the godfather's of DeFi and that's erstwhile the ft is enactment down to support pic.twitter.com/feV78YPtq0

— Andrew Kang (@Rewkang) November 22, 2022

Arkham says CRV shorting mightiness beryllium a bait

Blockchain analytics steadfast Arkham Intelligence tweeted Eisenberg mightiness beryllium baiting radical to judge that helium was shorting CRV to origin the liquidation of Michael Egorov, laminitis of the DeFi network.

According to Arkham Intelligence, Eisenberg’s existent people was AAVE’s susceptible looping strategy and his borrowings could permission the DeFi web with terrible atrocious debt. The blockchain analytics steadfast added:

“To liquidate Avi’s position, AAVE liquidators volition person nary mode to bargain backmost each the CRV helium borrowed. On-chain, determination is nary liquidity to wage backmost much than ~20% of the position. AAVE volition person to merchantability important amounts of tokens from the information module to screen this loss.”

In October, Eisenberg explained that it was imaginable to manipulate Aave lending policies to get massively, dump it, and permission Aave with atrocious debt.

Aave issues statement

Following the nonaccomplishment of the abbreviated strategy, Aave said the liquidation process of its CRV excavation was palmy and went arsenic planned. But it noted that the presumption was not afloat covered arsenic 2.6 cardinal CRV ($1.6 million) remained, representing little than 0.1% of the positions connected the protocol.

1/6 We privation to code the rhythm of liquidations that occurred successful the CRV excavation connected the Aave Protocol today. The liquidations were palmy (and worked arsenic designed), but unfortunately, the size of the presumption near immoderate excess indebtedness wrong the protocol.

— Aave (@AaveAave) November 22, 2022

Gauntlet Network, the fiscal modeling institution managing Aave, said it volition screen the nonaccomplishment done its insolvency refund program. The steadfast added that it has made respective proposals successful the past fewer weeks to mitigate these types of attacks.

Just to clarify:
1) Our insolvency refund *will* assistance screen this (in lawsuit that wasn't clear)
2) We made aggregate proposals implicit the past fewer weeks to bounds these benignant of attacks

We'll station a afloat investigation and post-mortem successful the AAVE forums soon https://t.co/LKeeCUx2yd

— Gauntlet (@gauntletnetwork) November 23, 2022

A caller governance proposal is present unrecorded connected Aave that volition forestall different terms manipulation connected the platform.

Meanwhile, the Aave assemblage pointed retired that the developers could person done thing to forestall this script arsenic they had received respective warnings astir the anticipation previously.

The station Mango Market hacker’s effort to exploit Aave fails appeared archetypal connected CryptoSlate.

View source