Stablecoin Cashio Suffers 'Infinite Glitch' Exploit, TVL Drops by $28M

2 years ago

Solana-based stablecoin protocol Cashio was exploited successful an “infinite glitch” attack, developers said connected Wednesday.

  • Following the exploit, the worth of Cashio's CASH token dropped to astir zero.

  • “Please bash not mint immoderate CASH. There is an infinite mint glitch. We are investigating the contented and we judge we person recovered the basal cause. Please retreat your funds from pools,” the squad wrote successful a tweet.

  • CASH is simply a stablecoin pegged to the U.S .dollar and is backed by USDC and USDT via a liquidity excavation connected Saber, a Solana-based marketplace maker. Users tin mint their CASH by providing liquidity with USDT and USDC.

  • The incidental connected Wednesday allowed the hacker to manipulate Cashio’s astute contracts to mint an infinite proviso of CASH without providing immoderate liquidity successful return. Blockchain data shows implicit 2 cardinal CASH were minted, without immoderate USDC oregon USDT backing.

  • The hacker utilized the recently minted tokens to speech them for stablecoins connected Cashio’s liquidity pools. Data from tracking instrumentality DeFi Llama shows the full worth locked connected Cashio dropped by $28 cardinal aft the attack.

  • Stablecoins based connected different protocols has suffered akin attacks successful the past. Polygon-based Safedollar dropped to $0 aft an exploit successful June 2021, with some USDC and USDT siphoned disconnected by the hacker astatine the time.

DISCLOSURE

The person successful quality and accusation connected cryptocurrency, integer assets and the aboriginal of money, CoinDesk is simply a media outlet that strives for the highest journalistic standards and abides by a strict acceptable of editorial policies. CoinDesk is an autarkic operating subsidiary of Digital Currency Group, which invests successful cryptocurrencies and blockchain startups. As portion of their compensation, definite CoinDesk employees, including editorial employees, whitethorn person vulnerability to DCG equity successful the signifier of stock appreciation rights, which vest implicit a multi-year period. CoinDesk journalists are not allowed to acquisition banal outright successful DCG.

Shaurya is an analyst/editor for CoinDesk's markets squad successful Asia.


Subscribe to Valid Points, our play newsletter astir Ethereum 2.0.

By signing up, you volition person emails astir CoinDesk merchandise updates, events and selling and you hold to our terms of services and privacy policy.

View source