Scan to download
BTC $70,771.24 +0.20%
ETH $2,070.28 +1.11%
BNB $649.64 +0.63%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $456.48 +1.92%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9138 -6.63%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%
BTC $70,771.24 +0.20%
ETH $2,070.28 +1.11%
BNB $649.64 +0.63%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $456.48 +1.92%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9138 -6.63%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%

BlockSec: Sharwa.Finance has been attacked multiple times, resulting in losses exceeding $140,000

2025-10-20 18:42:56
Collection

ChainCatcher news, according to market reports, Sharwa.Finance has disclosed that it was attacked and subsequently paused operations. However, several hours later, multiple suspicious transactions occurred, suggesting that the attacker may have exploited the same underlying vulnerability through a slightly different attack path.

Overall, the attacker first created a margin account, then used the provided collateral to borrow more assets through leveraged lending, and finally initiated a "sandwich attack" targeting the exchange operations involving the borrowed assets.

The root cause seems to be the lack of bankruptcy checks in the swap() function of the MarginTrading contract, which is used to exchange the borrowed assets from one token (like WBTC) to another token (like USDC). This function only verifies solvency based on the account status at the start of the exchange, leaving room for manipulation during the operation process.

Attacker 1 (starting with 0xd356) executed multiple attacks, profiting approximately $61,000. Attacker 2 (starting with 0xaa24) executed one attack, profiting approximately $85,000.

app_icon
ChainCatcher Building the Web3 world with innovations.