ID:
ola-finance-10
100 pts
Platform:
Type:
Category:
Method:
Data Sources:
Fuse Network, Ethereum
Protocol
Yield
Contract Vulnerabilities
Extended Method:
Reentrancy attack
Days in Operation:
548
(1.50 Years)





100 pts each
Ola Finance / Voltage Finance is investigating an exploit that took place on the @Fuse_network. All other lending networks remain unaffected, and we have pre-emptively paused borrowing capabilities to mitigate any risk. The breach was originally reported by Voltage Finance - ... aware of a breach on the @voltfinance lending platform around 3 hours ago leading to the theft of $4M in $USDC, $FUSD, $BUSD, $WBTC, $WETH & $FUSE. Voltage Finance is collaborating with our Lending-as-a-Service partner, @ola_finance, for preliminary investigation.
The initial funds to launch the hack are withdrawn from TornadoCash and tunneled to Fuse network via Fuse Bridge. The gains are tunneled via Fuse Bridge and currently funds still stay in the hacker’s account
More details of the exploit were provided by BlockSec.
https://twitter.com/BlockSecTeam/status/1509466576848064512/photo/1
In the code logic of the borrow() function, the related internal states are updated after an external call. Specifically, the doTransferOut() function will invoke the transfer() function of the ERC677-based token, which will eventually lead to an external call.
https://twitter.com/BlockSecTeam/status/1509466583781232643/photo/1
DISCLAIMER: While web3rekt has used the best efforts in aggregating and maintaining this database, this web site makes no representations or warranties with respect to the accuracy or completeness of its information and data herein, and specifically disclaim any implied warranties of merchantability or fitness for any particular purpose.
Under no circumstances, shall web3rekt be liable for any loss of profit or funds, any regulatory or governmental penalties, any legal costs, or any other commercial and non-commercial damages, including but not limited to special, incidental, consequential, or other damages from any or all usage of the data and information derived from this database.