link.png

ID:

ola-finance-10

Date:

Status:

Incident Count:

March 31, 2022

Verified

1

info.png
target.png
REKT

Contributor:

chain.png

zerofriction.io

KYC By:

KYC:

No

info.png

Audit By:

Audits:

Solidified

Loss Amount:

3,500,000

info.png

Recovered:

-

Rewards:

Currency:

USD

info.png

Key Indicators

Platform:

Type:

Category:

Method:

Data Sources:

Fuse Network, Ethereum

Protocol

Yield

Contract Vulnerabilities

Extended Method:

Reentrancy attack

info.png

Days in Operation:

548

(1.50 Years)

chain.png
chain.png
chain.png
chain.png
datasource.png

Ola Finance / Voltage Finance is investigating an exploit that took place on the @Fuse_network. All other lending networks remain unaffected, and we have pre-emptively paused borrowing capabilities to mitigate any risk. The breach was originally reported by Voltage Finance - ... aware of a breach on the @voltfinance lending platform around 3 hours ago leading to the theft of $4M in $USDC, $FUSD, $BUSD, $WBTC, $WETH & $FUSE. Voltage Finance is collaborating with our Lending-as-a-Service partner, @ola_finance, for preliminary investigation.

The initial funds to launch the hack are withdrawn from TornadoCash and tunneled to Fuse network via Fuse Bridge. The gains are tunneled via Fuse Bridge and currently funds still stay in the hacker’s account

More details of the exploit were provided by BlockSec.

https://twitter.com/BlockSecTeam/status/1509466576848064512/photo/1

In the code logic of the borrow() function, the related internal states are updated after an external call. Specifically, the doTransferOut() function will invoke the transfer() function of the ERC677-based token, which will eventually lead to an external call.

https://twitter.com/BlockSecTeam/status/1509466583781232643/photo/1

info.png

DISCLAIMER: While web3rekt has used the best efforts in aggregating and maintaining this database, this web site makes no representations or warranties with respect to the accuracy or completeness of its information and data herein, and specifically disclaim any implied warranties of merchantability or fitness for any particular purpose. 

Under no circumstances, shall web3rekt be liable for any loss of profit or funds, any regulatory or governmental penalties, any legal costs, or any other commercial and non-commercial damages, including but not limited to special, incidental, consequential, or other damages from any or all usage of the data and information derived from this database.