{"id":113212,"date":"2020-11-16T22:33:06","date_gmt":"2020-11-16T19:33:06","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/value-defi-protocol-hacker-flooded-with-sob-stories-after-returning-95k-dai\/"},"modified":"2020-11-16T22:33:06","modified_gmt":"2020-11-16T19:33:06","slug":"value-defi-protocol-hacker-flooded-with-sob-stories-after-returning-95k-dai","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/value-defi-protocol-hacker-flooded-with-sob-stories-after-returning-95k-dai\/","title":{"rendered":"# Value DeFi protocol hacker flooded with sob stories after returning $95K DAI"},"content":{"rendered":"<p>&#8220;<strong># Value DeFi protocol hacker flooded with sob stories after returning $95K DAI  <\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjAtMTEvMDBkODk2OTUtOGFmYy00M2JjLTg1ODItMDZmNjIwMmNiMjcwLmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-5a136f3a>On Nov 14, an unknown party exploited flash loans via the decentralized finance protocol Value DeFi to the tune of $5.4 million. A number of individuals have received a portion of their stolen funds back, however, after pleading with the hacker using input data on the Ethereum blockchain.<\/p>\n<p>According to data from Etherscan, the hacker <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/etherscan.io\/txs?a=0xa773603b139ae1c52d05b35796df3ee76d8a9a2f&amp;f=2\">sent<\/a> $95,000 in Dai (DAI) back to two of the victims who posted messages accessible in the Ethereum block explorer\u2019s input data on Sunday.<\/p>\n<p>\u201cI lost $100,000 in your attack,\u201d <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/etherscan.io\/tx\/0xdf10b20e49135306cfe16fc87da5fc6d859755ecbfd76180b36898052c765fab\">said<\/a> one victim who claimed to be a nurse. \u201cThese are all my savings. I hope you can return it to me.\u201d <\/p>\n<p>\u201cMy grandparents and my parents sent me their life savings for high yield return that I boasted about,\u201d <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/etherscan.io\/tx\/0x88792d24670eaa93af7a5ac6751674a484a9951b5bf01510a14ebb00b2de6444\">said<\/a> another, stating he was a 19-year-old student living in the U.K. who had lost $200,000. \u201cI will be grateful if you can send the funds back and I will return them to my family.\u201d<\/p>\n<p>While the hacker did transfer 50,000 DAI to the nurse and 45,000 DAI to the 19-year-old, they\u00a0<a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/etherscan.io\/tx\/0xd043d48e91bfca3e0709ca741d321eeb27311c9c9cf35a2375b941f809d5d6fd\">had<\/a> a message for both of them. The hacker inferred that their attack was a &#8220;tough love&#8221; lesson for investors:<\/p>\n<blockquote><p>\u201cI don\u2019t expect to get your money, but as we have seen, there are so many people here who lack knowledge and caution, and sooner or later those money will be lost. Some wounds are painful, but very effective.\u201d<\/p><\/blockquote>\n<p>In the time since these messages were posted, many affected users have likewise <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/etherscan.io\/tx\/0x998b9e39262a1c7f279c3ecf76c7c875c4c7cf026410499e11125f7bd4c2fffd\">sent<\/a> small transactions with messages attached,\u00a0<a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/etherscan.io\/tx\/0x529ebb826cd4df67140be026c99edd0898ebdcec4dafe5440bdc3d1c960e249b\">requesting<\/a>\u00a0that the hacker make them whole again. At the time of publication, there have been no outgoing transactions from the address associated with the exploit since yesterday.<\/p>\n<p>According to a post-mortem report from Value DeFi\u00a0<a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/valuedefi.medium.com\/multistables-vault-exploit-post-mortem-d11b0635788f\">published<\/a> on Sunday, the exploit began when a user took out a flashloan of 80,000 ETH \u2014 roughly $37 million at the time of publication \u2014 from lending protocol Aave in addition to buying 116 million DAI and 31 million Tether (USDT). The attacker then sw<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>ed 25 million Dai for the protocol\u2019s dollar stablecoin mvUSD, 91 million DAI for USD Coin (USDC), 31 million USDT for 17 million USDC. Each swap was designed to exploit the pricing used by Value\u2019s vault withdrawal method. <\/p>\n<p>The protocol has stated it will be creating a compensation fund for affected users, and has reached out to the hacker in a transaction of its own in an attempt to \u201caccelerate the process.\u201d Etherscan records <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/etherscan.io\/tx\/0x8bc8a4f4fa0c54702d018eaf7adee5937be566366ea8d4a3adb191a3dc71b855\">show<\/a> that Value DeFi offered a $1 million bounty for the hacker to return $5.4 million in DAI. There has been no response or outgoing transactions from the hacker in the time since, however.<\/p>\n<p>\u201cAll teams within this space are pioneering very risky <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/technology\/\" data-internallinksmanager029f6b8e52c=\"4\" title=\"Technology\" target=\"_blank\" rel=\"noopener\">technology<\/a> that is by nature lacking the benefit of time for rigorous analysis and testing,\u201d <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/valuedefi.medium.com\/multistables-vault-exploit-post-mortem-d11b0635788f\">stated<\/a> Value DeFi. \u201cNo matter if your funds are deployed in Value DeFi Protocol or any other DeFi projects, there is always an element of risk when it comes to smart contracts and increasingly complex deployments.\u201d<\/p>\n<p>The value of the $VALUE token is $2.02 at the time of publication, having fallen more than 26% since its pre-exploit price of $2.74 on Saturday.<\/p>\n<p><template data-name=\"subscription_form\" data-type=\"defi_newsletter\"><\/template><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener noreferrer\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/value-defi-protocol-hacker-flooded-with-sob-stories-after-returning-95k-dai\" target=\"_blank\" rel=\"noopener noreferrer\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Value DeFi protocol hacker flooded with sob stories after returning $95K DAI &#8221; On Nov 14, an unknown party exploited flash loans via the decentralized finance protocol Value DeFi to the tune of $5.4 million. A number of individuals have received a portion of their stolen funds back, however, after pleading with the hacker&#8230;<\/p>\n","protected":false},"author":1,"featured_media":113213,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/s3.cointelegraph.com\/uploads\/2020-11\/00d89695-8afc-43bc-8582-06f6202cb270.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74868,74882,80225,117,70944],"class_list":["post-113212","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-defi","tag-hacks","tag-value","tag-business","tag-hackers"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/113212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=113212"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/113212\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/113213"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=113212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=113212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=113212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}