A software flaw enabled hackers to steal $31 million from a cryptocurrency service
A software flaw enabled hackers to steal $31 million from a cryptocurrency service

A software flaw enabled hackers to steal $31 million from a cryptocurrency service

Zara

5 min
Business & Finance
Play

Description

<p>MonoX Finance, a blockchain startup, announced on Wednesday that a hacker stole $31 million by exploiting a flaw in the software it uses to create smart contracts.</p> <p>The company utilises the MonoX decentralised finance protocol, which enables users to trade digital currency tokens without complying with certain requirements associated with traditional exchanges. "Without the burden of capital requirements, project owners can list their tokens and focus on developing the project rather than providing liquidity," MonoX company representatives wrote in November. "It operates by grouping deposited tokens into a virtual pair with vCASH, allowing for the creation of a single token pool."</p> <p>An accounting error in the company's software enabled an attacker to inflate the MONO token's price and then use it to withdraw all other deposited tokens, MonoX Finance revealed in a post. The haul totalled $31 million in Ethereum or Polygon tokens, which are both supported by the MonoX protocol.</p> <p>The hack specifically utilised the same token for both tokenIn and tokenOut, which are methods for exchanging the value of one token for another. MonoX calculates new prices for both tokens following each swap. When the swap is complete, the price of tokenIn—the token sent by the user—decreases, while the price of tokenOut—the token received by the user—increases.</p> <p>By using the same token for both tokenIn and tokenOut, the hacker significantly inflated the MONO token's price, as updating the tokenOut overwrote the tokenIn's price update. The hacker then traded the token for $31 million in Ethereum and Polygon tokens.</p> <p>There is no practical reason to exchange a token for another token, and thus the trading software should never have permitted such transactions. Unfortunately, it did, despite the fact that MonoX underwent three security audits this year.</p> <p>The Smart Contracts Pitfalls</p> <p>"These types of attacks are common in smart contracts because many developers fail to define security propert

Uploader

omar.Shore

omar.Shore

A software flaw enabled hackers to steal $31 million from a cryptocurrency service - Listen Free | WowFM