{"id":125654,"date":"2023-07-21T16:46:00","date_gmt":"2023-07-21T16:46:00","guid":{"rendered":"https:\/\/dripp.zone\/news\/conic-finance-loses-3-2m-to-reentrancy-attack-on-eth-omnipool-crypto-news\/"},"modified":"2023-07-21T16:46:02","modified_gmt":"2023-07-21T16:46:02","slug":"conic-finance-loses-3-2m-to-reentrancy-attack-on-eth-omnipool-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/conic-finance-loses-3-2m-to-reentrancy-attack-on-eth-omnipool-crypto-news\/","title":{"rendered":"Conic Finance loses $3.2M to reentrancy attack on ETH Omnipool\n &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<p>DeFi protocol Conic Finance <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/ConicFinance\/status\/1682385596700844032?s=20\">confirmed<\/a> that it was exploited via a reentrancy attack earlier today for an undisclosed sum.<\/p>\n<p>A reentrancy attack allows an attacker to drain funds of a vulnerable contract by repeatedly calling the withdraw function before it updates its balance.  This attack has been commonly used to <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/sturdy-finance-halts-market-after-800000-exploit-linked-to-faulty-price-oracle\/\">exploitation<\/a> several DeFi protocols.<\/p>\n<p>Conic Finance stated that it initially disabled the front end of its Omnipool Ethereum deposits, adding that it has initiated a fix. <span style=\"color: #333333\">to the affected contract.<\/span><\/p>\n<blockquote>\n<p>\u201cThe root cause was a re-entrancy attack that was able to be performed because of a wrong assumption as to what address is returned by the Curve Meta Registry for ETH in Curve V2 pools.\u201d<\/p>\n<\/blockquote>\n<p>Curve Finance also <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/CurveFinance\/status\/1682366303149912069?s=20\"><span class=\"s4\">added<\/span><\/a>  that only the ETH Omnipool was affected.<\/p>\n<p>According to its website, Conic Finance allows liquidity providers to diversify their exposure to multiple Curve pools easily.  Any user can provide liquidity into a Conic Omnipool, which allocates funds across the Curve in proportion to protocol-controlled pool weights.<\/p>\n<p>Conic Finance did not respond to <em>CryptoSlate&#8217;s<\/em> request for additional commentary as of press time.<\/p>\n<p>Meanwhile, blockchain security firm Decurity <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/DecurityHQ\/status\/1682344909875847169?s=20\">stated<\/a> that the exploit led to the loss of 1724 <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/coins\/ethereum\/\">eth<\/a> worth $3.2 million.<\/p>\n<p>Decurity noted that the exploiter was active yesterday and performed a series of small hacks before attacking the CNCETH pool today.  They also tried an unsuccessful transaction 10 minutes before successfully exploiting Conic Finance.<\/p>\n<p>BlockSec <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/BlockSecTeam\/status\/1682355195894976514?s=20\">corroborated<\/a> the report, noting that the hacker was labeled as the Lady Pepe Exploiter by MetaDock.<\/p>\n<p>This exploit continues a relatively busy month for hackers targeting crypto projects.  Data from DeFillama <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/defillama.com\/hacks\">shows<\/a> that over $100 million in digital assets have been stolen from several protocols, including the cross-chain bridge <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/multichain-halts-services-after-126m-exploit\/\">multichain<\/a> ,<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/coins\/multichain\/\">multi<\/a>,<\/p>\n<p>The post <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/conic-finance-loses-3-2m-to-reentrancy-attack-on-eth-omnipool\/\">Conic Finance loses $3.2M to reentrancy attack on ETH Omnipool<\/a> appeared first on <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\">CryptoSlate<\/a>,<\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>DeFi protocol Conic Finance confirmed that it was exploited via a reentrancy attack earlier today for an undisclosed sum. A reentrancy attack allows an attacker to drain funds of a vulnerable contract by repeatedly calling the withdraw function before it updates its balance. This attack has been commonly used to exploitation several DeFi protocols. Conic [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":125655,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[274,273,272,244,266,271,268,270,269,267],"class_list":["post-125654","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-de-fi","tag-crypto-finance","tag-decentralized-finance","tag-liquidity","tag-metamask","tag-pancake","tag-slippage","tag-sushiswap","tag-tronlink","tag-trust-wallet","tag-uniswap"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/125654","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=125654"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/125654\/revisions"}],"predecessor-version":[{"id":125656,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/125654\/revisions\/125656"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/125655"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=125654"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=125654"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=125654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}