Conic Finance, a protocol that offers diversified exposure to liquidity pools on Curve, a popular DEX, has lost two-thirds of its deposits since suffering two exploits late last week.
In a postmortem on July 23, the team said it lost $4.1 million in two separate attacks on its pools two days earlier. The incidents shook investor confidence in Conic, causing the company's total value to plunge 72% to $43 million, from $157 million as of July 21. Its native token CNC has also fallen by 57% over the same period.
Conic Finance users flee after hackers steal $4 million
Deposits on Conic remain disabled, with the team saying it wants to “carefully address any security issues” before allowing new capital inflows. Users can make withdrawals and existing liquidity providers continue to earn returns as usual.
The incident serves as a reminder of the risk-reward trade-off for DeFi farmers chasing yield. While protocols like Conic can offer higher rewards compared to the ease of depositing assets with battle-tested protocols like Curve Finance, the additional yield comes from the increasing complexity of smart contracts and therefore the ability for hackers to identify and exploit attack vectors.
Novel Omnipools
Conic's Omnipools distribute users' deposits across multiple Curve pools and stake the corresponding LP tokens on Convex Finance to generate additional returns. In addition to trading fees on Curve, users receive rewards in the form of CRV tokens from Curve, CVX from Convex, and CNC tokens from Conic. The protocol went live in March.
Conic said it was contacted on July 21 by Hexagate, a Web3 threat intelligence company, after the company identified early signs of a possible exploit targeting Conic's ETH Omnipool through a reentry attack.
A reentry attack is a malicious maneuver in which an attacker repeatedly calls a function within a smart contract before the previous function call completes, exploiting the contract's logic to siphon funds or manipulate data.
The hacker was able to manipulate the price of the rETH Curve LP token on Conic, allowing him to mint more cncETH LP tokens than his rETH collateral should allow.
The story goes on
“They were able to execute this attack in a loop, making deposits and withdrawals at a positive exchange rate to withdraw funds from the Omnipool,” Conic said. The attack resulted in a loss of $3.2 million for the protocol.
Conic said that although there are safeguards in place to protect against reentry attacks, the attack exploited an incorrect technical assumption regarding Curve v2 pools in its code.
Conic was later alerted to suspicious transactions targeting its crvUSD Omnipool, leading the team to close all of its Omnipools after discovering a loss of 11 ETH from a complex sandwich attack. In total, around $934,000 was stolen from the crvUSD Omnipool, giving the attacker a profit of around $300,000.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.