link.png

ID:

sovryn-1196

Date:

Status:

Incident Count:

October 7, 2022

Verified

2

info.png
target.png
REKT

Contributor:

chain.png

web3rekt.com

KYC By:

KYC:

None

info.png

Audit By:

Audits:

Sovryn

Loss Amount:

1,109,645

info.png

Recovered:

-

Rewards:

Ticker:

USD

info.png

Sovryn is a Bitcoin-based decentralized finance protocol enabling non-custodial and permission-less smart contract-based system for bitcoin lending, borrowing, and margin trading. The Sovryn DAO is built on RSK, a Bitcoin sidechain, that provides Bitcoin ecosystem with EVM superpowers.

According to the site blog, the hacker exploited the legacy Lend/Borrow protocol to inappropriately withdraw funds. The attack was detected by Sovryn devs and the system placed into maintenance mode.

This attack allowed the attacker to withdraw RBTC and USDT from the lending pools in the following amounts:

44.93 RBTC
211,045 USDT

The exploit utilized a manipulation of the iToken price. This token price is updated every time there’s an interaction with one of its lending pool’s positions. The attacker first bought WRBTC with a flash swap from RskSwap and then borrowed WRBTC from the RBTC Sovryn lending contract using their own XUSD as collateral. The attacker then provided liquidity to the RBTC lending contract, closed their loan with a swap using their XUSD collateral, redeemed (burned) their iRBTC token, and sent the WRBTC back to RskSwap to complete the flash swap. This sequence of events manipulated the iRBTC price such that they were able to take out much more RBTC than they originally deposited.

Over $1 million in funds was drained using the described price manipulation exploit. Stolen funds were deposited into various AMM protocols and Tornado.Cash.

info.png

DISCLAIMER: While web3rekt has used the best efforts in aggregating and maintaining this database, this web site makes no representations or warranties with respect to the accuracy or completeness of its information and data herein, and specifically disclaim any implied warranties of merchantability or fitness for any particular purpose. 

Under no circumstances, shall web3rekt be liable for any loss of profit or funds, any regulatory or governmental penalties, any legal costs, or any other commercial and non-commercial damages, including but not limited to special, incidental, consequential, or other damages from any or all usage of the data and information derived from this database.