Hacker Drains $500k From Two Balancer Pools; A Case of DeFi Arbitrage on the Rise?

  • Two multi-token Balancer pools have been drained up to $500k after a hacker manipulated the deflationary nature of STA tokens that were part of the portfolio.
  • As the DeFi market balloons to what some now compared to the 2017-2018 ICO boom, its vulnerabilities continue to be exposed, especially in light of arbitrage markets.

Balancer, which is the 4th largest DeFi as of press time, is a product of Balancer Labs and runs liquidity pools that enable users to execute token swaps automatically. This Ethereum based project has since come out to acknowledge the attack, noting that they had warned the crypto community about the unintended effects of deflationary tokens,

“Although we were not aware this specific type of attack was possible, we have consistently in our docs, discord, and other channels warned about the unintended effects ERC20s with transfer fees could have in the protocol.”

The Hack in Detail

According to a medium post by 1inch, an ETH built exchange; the hacker deployed a complex smart contract on Ethereum's mainnet hence taking advantage of the exposure in the ‘transfer fee' DeFi model. Notably, this hacker used the smart contract to automate multiple DeFi actions within one execution,

“At first step, the attacker got a FlashLoan of 104k WETH from dYdX. These funds were used to swap WETH to STA token back and forth 24 times which drained STA balance from the pool and it became 1 weiSTA (0.000000000000000001 STA). ” details the post.

This event was possible due to the manipulation of Balancer's Pool record keeping contract. It is designed to keep track of token balances as well as receive transfer fees like in the case of swapping STA tokens, a 1% fee is charged on the recipient. Given this underlying, the hacker went on to create misbehavior between the two exchanging parties, which resulted in Balancer Pools not receiving the expected STA transfer fees.

It did not end there; the hacker further swapped 1 weiSTA to WETH multiple times. In doing so, they were able to drain WETH from the pool and eventually repeated the process to drain LINK, SNX, and WBTC tokens as well. Finally, the initial flash loan was repaid, and the hacker acquired a bigger share within Balancer’s pool by depositing weiSTAs to initiate a token swap to WETH for liquidation,

“Then he swapped collected Balancer Pool token to 136k STA via Uniswap V2, and then he swapped 136k STA to 109 WETH again.”

Balancer Set to Take Action

Following the incident, Balancer has said that it will begin adding ‘transfer fee’ tokens to its UI blacklist; the list is set to be non-exhaustive with the possibility of new tokens being added at any time. In addition to this, the Ethereum-built protocol will increase available documentation on the risks involved in operating Balancer Pools. The protocol has since undergone two full audits with a third scheduled for today as part of ongoing review processes to boost its efficiency amidst the rise of crypto arbitrage in the DeFi markets.

Get Free Email Updates!

*Action* Enter Best Email to Get Trending Crypto News & Bitcoin Market Updates

I will never give away, trade or sell your email address. You can unsubscribe at any time.

Edwin Munyui
Edwin Munyui
Edwin is a FinTech enthusiast with a particular interest in blockchain technology and cryptocurrencies. He has worked as an author in the blockchain space since 2017 and enjoys creating content that both crypto veterans and newbies can understand. His simple writing style and financial market knowledge have made him a reputable fundamental and technical analyst with the ability to handle any topic around blockchain and crypto over the years.

[Alert] Use the author's self-conducted information at your own risk, do you own research, never invest more than you are willing to lose.

[Disclosure] The published news and content on BitcoinExchangeGuide should never be used or taken as financial investment advice. Understand trading cryptocurrencies is a very high-risk activity which can result in significant losses. Editorial Policy \\ Investment Disclaimer

LEAVE A REPLY

Please enter your comment!
Please enter your name here

3,471FansLike
2,795FollowersFollow
4,194FollowersFollow

Live Bitcoin Price & Latest BTC Charts

Today's Latest Crypto News

Bitcoin Adoption Explosion in Africa, Led by Nigeria, Kenya, and South Africa

Bitcoin continues to gain traction in Africa, with Kenya being the most bitcoin maximalist country, with 94.7% dominance. The top 10 list also contains...

DeFi App Growth Boosts Total Transactions On DApp Blockchains By $4.5B In Q2 2020: DAppRadar Report

In a report by DApp Radar, the total transactional volume on DApps touched the $12 billion mark in Q2 2020, representing a $4.5 billion...

Bitcoin to Follow the Equities Market Up or Down? One-Month Correlation Spikes to an All-Time High

Yet another week of weak price movement. The world’s leading digital asset is trading at $9,072, in red with 24 hours ‘real’ volume of just...

Public Mint Launches Its Blockchain; Over 200 Banks Plan to Support Its Digital Money

vPublic Mint, a firm founded by CNET founder Halsey Minor, has announced the launching of its ‘fiat-native’ public blockchain, which enables anyone to easily...

BTC Halving Week Brings in Record Monthly New Accounts & Doubles the Revenue for BlockFi

The past two months have been incredibly dull for the price of bitcoin, but it didn’t affect the businesses in the cryptocurrency space. The...

BitcoinExchangeGuide is a hyper-active daily crypto news portal with care in cultivating the cryptocurrency culture with community contributors who help rewrite the bold future of blockchain finance. Subscribe on Google News, see the mission, authors, editorial links policy, investment disclaimer, privacy policy. Got News? Contact us, we are human too. Note: nothing here is financial advice, do your own research thoroughly.

Start Using Crypto Today