Ultimate magazine theme for WordPress.

FBI sounds alarm as DeFi hacks dominate crypto crime: $1.3B stolen in Q1 2022

Neither the author, Tim Fries, nor this website, The Tokenist, provide financial advice. Please consult our website policies before making any financial decisions.

DeFi hacks are so widespread that the FBI issued a warning to crypto investors. The agency cited an April Chainalysis report showing that cybercriminals stole $1.3 billion worth of cryptocurrency in the first three months of 2022 alone.

Not only is this a 71% increase from 2021, but 97% of all crypto exploits affected DeFi platforms.

Unlike the conservative bitcoin, decentralized finance runs on more flexible and diverse smart contracts. This flexibility seems to come at the expense of security. What types of DeFi platforms are most at risk and what does the FBI recommend developers and investors do?

The most common DeFi exploits discovered by the FBI

Over the past decade, the FBI has steadily expanded its cyber department. As of this year, it has over 1,000 cybersecurity specialists in 56 field offices. In yesterday’s PSA, the FBI urged crypto investors to report cybercrimes to their local office by filling out the form with the Internet Crime Complaint Center (IC3).

In the PSA, the agency summarized all the typical cryptocurrency scams and DeFi exploits that the tokenist has been reporting on for years: flash loans, token bridge exploits, and token pair exploits. The latter involves price manipulation on DEXs by exploiting smart contracts responsible for slippage checks.

Slippage occurs in token pair liquidity pools like ETH/WBTC when the price of tokens varies between submitted and validated transactions. Attackers can exploit poorly coded slippage checks and circumvent them with leveraged trades.

The resulting pricing error then allows exploiters to drain liquidity pools. However, the FBI found that only $35 million was lost in these types of exploits, completely overshadowed by the other two.

flash loan

Flash loans represent a blockchain novelty that was previously impossible and was launched in January 2020. By using smart contracts, a borrower can issue and repay a loan within the same transaction (block of data). If the borrower does not repay it immediately, the transaction will be reversed as if the loan had never been granted.

While not useful for general lending purposes, flash loans are vital for daily traders who are strengthening their positions as they engage in arbitrage opportunities. Typically, hackers take advantage of poor coding to buy enough crypto assets to trigger sell-offs without first having to post collateral. After the price of the token is suppressed, they go to another DEX to sell it for a profit.

In April, hackers used this method to steal $182 million from Beanstalk Farms. The platform issues the algorithmic stablecoin BEAN, but uses loans instead of collateral to back them. Because the platform is decentralized, buying tokens means buying voting rights, which allowed hackers (exploiters) to change governance rules and siphon off $182 million.

After funds dried up, the bond collapsed, but later stabilized in August. The Bean team even asked the exploiter to return the money and keep 10% as a bounty for whitehats (ethical hackers).

Collapse of the stablecoin BEAN shortly after the heist. Not being backed by hard cash reserves, decentralized algorithmic stablecoins often struggle to maintain their peg to the dollar. Photo credit: CoinGecko

In July, Solana-based Nirvana Finance suffered $3.5 million in damage from a flash loan attack that also involved algorithmic stablecoin NIRV. This year alone, over 17 such attacks took place on various DeFi platforms.

Join our Telegram group and don’t miss any red hot digital asset story.

Token Bridge exploits

Since each blockchain network has its own governance rules, validators, and even smart contract standards, transferring digital assets from one to another is problematic. This is where blockchain bridges come into play. They are protocols that perform smart conversion contracts, allowing a token to be sent from one blockchain to another.

For example, if Bitcoin were to be used as collateral on Ethereum’s dApp, BTC would first have to be made compatible with Ethereum’s ERC-20 token standard. Responsible for this conversion is a cross-chain smart contract like Binance Bridge. The user would simply deposit bitcoins, and the bridge’s smart contract would convert them into Wrapped Bitcoin (wBTC).

In this way, the newly minted wBTC matches the value of the deposited BTC and is tied to the same price movements, but comes with ERC-20 token functionality and compatibility.

Similarly, decentralized protocols like Zapper or Celer can be used to send funds across dozens of different blockchain networks. The problem with this is that these token bridges serve as repositories, i.e. as central points of failure. Surprisingly, the FBI failed to cite the latest August Chainalysis report showing that token bridge attacks accounted for 69% of all funds stolen this year.

In August, Chainalysis reported up to $2 billion stolen in 13 cross-chain bridge hacks/exploits. Photo credit: chain analysis

On August 2, attackers exploited the Nomad Bridge smart contract and stole almost $200 million from it. Tom Robinson of blockchain security firm Elliptic found that cross-chain bridges represent the least secure part of blockchain infrastructure.

“These bridges have been breached by hackers in a variety of ways, suggesting their level of security has not kept pace with the value of the assets they hold.”

The record holder remains the Ronin Bridge hack, which connects Axie Infinity’s Ronin sidechain to Ethereum. North Korean hackers stole $600 million worth of ETH and USDC stablecoins. Additionally, Elliptic reported that open-source RenBridge was (abused) to launder up to $540 million in crypto funds, of which $153 was destined for ransomware payments.

The FBI’s recommendations for avoiding DeFi birth pains

DeFi investors are caught between a rock and a hard place. On the one hand, everyone knows that the early bird gets the overvalued token later. After all, this is how Ethereum went from under $1 billion in February 2020 to $111 billion TVL in November 2021.

On the other hand, new DeFi projects are rushing to tap into FOMO growth, with security and coding best practices often losing priority. Because of this, the FBI encourages investors to take responsibility and research each project before jumping in.

Part of this research is finding out if the platform has performed independent code audits to identify smart contract vulnerabilities. In the case of the Ronin Bridge hack, Sky Mavis opened the bridge after two external audits by Verichains and Certik and one internal. Also, the fewer validators a protocol has, the more open it is to an exploit, which is why Sky Mavis is increasing its validator pool to 21 from the previous 5-9.

The FBI also mentions rapidly deployed platforms as a red flag. The agency doesn’t go into much detail, but a perfect example of a fraudulent DeFi project trying to ape the success of a legitimate one was last week’s $815,000 SudoRare heist.

Finally, the FBI recommends an instant alert system for both developers and DeFi investors. With that in mind, it would be wise to follow Elliptic and Peckshield on Twitter. These blockchain security companies often warn about ongoing vulnerabilities or retweet others.

Finances are changing.

Find out how with Five Minute Finance.

A weekly newsletter covering the big trends in FinTech and Decentralized Finance.

Try it (free)

brilliant

You have signed up.

You’re well on your way to knowing.

Are you waiting or looking for new DeFi projects to be the first? Let us know in the comments below.

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: