{"id":383546,"date":"2021-12-20T11:58:00","date_gmt":"2021-12-20T08:58:00","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/defi-protocol-grim-finance-lost-30m-in-5x-reentrancy-hack\/"},"modified":"2021-12-20T11:58:00","modified_gmt":"2021-12-20T08:58:00","slug":"defi-protocol-grim-finance-lost-30m-in-5x-reentrancy-hack","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/defi-protocol-grim-finance-lost-30m-in-5x-reentrancy-hack\/","title":{"rendered":"# DeFi protocol Grim Finance lost $30M in 5x reentrancy hack"},"content":{"rendered":"<p>&#8220;<strong># DeFi protocol Grim Finance lost $30M in 5x reentrancy hack <\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMTIvMDZjZTA0ZjMtNDczMi00OTNhLTliOTEtZGU0MzQ0ZjZlY2YzLmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-128018ef>The decentralized finance (DeFi) protocol Grim Finance reported $30 million in losses due to a reentrancy exploit of the platform\u2019s deposits.<\/p>\n<p>Grim Finance officially <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/financegrim\/status\/1472357770846519312?s=20\">announced<\/a>\u00a0on Dec. 18 that an \u201cexternal attacker\u201d had exploited the DeFi platform, stealing \u201cover $30 million\u201d worth of cryptocurrencies.<\/p>\n<p>According to Grim Finance, the hack was an \u201cadvanced attack,\u201d with the attacker exploiting the protocol\u2019s vault contract through five reentrancy loops, which allowed them to fake five additional deposits into a vault while the platform is processing the first deposit.<\/p>\n<p>Grim paused all vaults after the attack to minimize the risk for future funds: \u201cWe have paused all of the vaults to prevent any future funds from being placed at risk, please withdraw all of your funds im<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a>tely.\u201d<\/p>\n<p>Grim noted that they also notified entities involved in operating major cryptocurrencies like Circle (USDC), DAI, and the cross-chain protocol AnySwap regarding the attacker address to freeze further fund transfers.<\/p>\n<p>Grim Finance positions itself as a \u201ccompounding yield optimizer\u201d built on DeFi-focused blockchain protocol, Fantom, allowing users to stake liquidity provider tokens by employing complex vault strategies.<\/p>\n<p>According to the Fantom (FTM) Blockchain Explorer data, Grim Finance Exploiter <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/ftmscan.com\/address\/0xdefc385d7038f391eb0063c2f7c238cfb55b206c\">continued<\/a> transacting on Dec. 19. One of the addresses associated with the exploit holds $1.2 million in Bitcoin (BTC), $1.7 million in SpookyToken (BOO) alongside $13,700 in FTM tokens.<\/p>\n<p>Some in the crypto community suggested that Grim Finance should hold responsibility for the exploit due to failing to adopt proper reentrancy protection tools. DeFi security platform Rugdoc.io also argued that the protocol gave the user \u201cmore privilege than is necessary.\u201d <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">5) So what was the big mistake of grim finance?<br \/>1. No reentrancy guard on a pattern that absolutely needs it (<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/0xPaladinSec?ref_src=twsrc%5Etfw\">@0xPaladinSec<\/a> always points this out)<br \/>2. Giving the user more privilege than is necessary: There is absolutely no need for the user to be able to choose the deposit token<\/p>\n<p>\u2014 Rugdoc.io (@RugDocIO) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/RugDocIO\/status\/1472293727368630273?ref_src=twsrc%5Etfw\">December 18, 2021<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<strong><em>Related: <\/em><\/strong><strong><em>Finance Redefined: Two DeFi hacks top $120M, and $500M Algo Fund launches, Nov. 26\u2013Dec. 3<\/em><\/strong><\/p>\n<p>The rising popularity of DeFi has triggered a number of new challenges for the cryptocurrency industry as hackers were rushing to exploit the flaws of the emerging industry. In early December, DeFi protocol BadgerDAO was reportedly exploited to the tune of $120 million.<\/p>\n<p><template data-name=\"subscription_form\" data-type=\"defi_newsletter\"><\/template><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/defi-protocol-grim-finance-lost-30m-in-5x-reentrancy-hack\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# DeFi protocol Grim Finance lost $30M in 5x reentrancy hack &#8221; The decentralized finance (DeFi) protocol Grim Finance reported $30 million in losses due to a reentrancy exploit of the platform\u2019s deposits. Grim Finance officially announced\u00a0on Dec. 18 that an \u201cexternal attacker\u201d had exploited the DeFi platform, stealing \u201cover $30 million\u201d worth of cryptocurrencies&#8230;.<\/p>\n","protected":false},"author":1,"featured_media":383547,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/images\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMTIvMDZjZTA0ZjMtNDczMi00OTNhLTliOTEtZGU0MzQ0ZjZlY2YzLmpwZw==.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74983,74868,74882,70944],"class_list":["post-383546","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-decentralization","tag-defi","tag-hacks","tag-hackers"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/383546","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=383546"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/383546\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/383547"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=383546"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=383546"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=383546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}