Scan to download
BTC $77,155.36 +3.16%
ETH $2,416.61 +3.70%
BNB $641.89 +1.93%
XRP $1.47 +2.32%
SOL $88.80 +1.24%
TRX $0.3272 +0.23%
DOGE $0.0988 +0.85%
ADA $0.2575 +0.93%
BCH $455.28 +1.00%
LINK $9.60 +1.74%
HYPE $45.40 +4.42%
AAVE $115.30 +1.45%
SUI $0.9969 +0.89%
XLM $0.1737 +4.51%
ZEC $336.66 +0.35%
BTC $77,155.36 +3.16%
ETH $2,416.61 +3.70%
BNB $641.89 +1.93%
XRP $1.47 +2.32%
SOL $88.80 +1.24%
TRX $0.3272 +0.23%
DOGE $0.0988 +0.85%
ADA $0.2575 +0.93%
BCH $455.28 +1.00%
LINK $9.60 +1.74%
HYPE $45.40 +4.42%
AAVE $115.30 +1.45%
SUI $0.9969 +0.89%
XLM $0.1737 +4.51%
ZEC $336.66 +0.35%

anc

Rhea Finance disclosed the reason for the attack, a flaw in the slippage protection logic led to a loss of 18.4 million dollars

According to RHEA Finance's official disclosure, the NEAR ecosystem lending protocol RHEA Finance (formerly known as Burrow Finance) experienced a margin trading feature hack, resulting in a loss of approximately $18.4 million.The attacker began laying the groundwork several days prior by creating multiple fake token pools on Ref Finance and injecting liquidity, constructing a malicious exchange route that exploited a vulnerability in the protocol's slippage protection mechanism—this mechanism did not account for the scenario where intermediate tokens were reused when calculating the minimum output of multi-step exchanges—leading to the borrowed debt tokens being directed into fake token pools controlled by the attacker, triggering a large-scale forced liquidation that ultimately drained the protocol's reserve pool. During the attack, the attacker deleted a total of 55 intermediate accounts to cover their tracks. Currently, the attacker has returned approximately 3.359 million USDC and 1.564 million NEAR to the RHEA lending contract, while another 4.34 million USDT has been frozen (of which Tether froze 3.291 million and NEAR Intents froze 1.053 million). The protocol contract has been suspended, and the team is collaborating with centralized exchanges for joint tracking and has notified relevant law enforcement agencies.
app_icon
ChainCatcher Building the Web3 world with innovations.