As the cryptocurrency decentralized finance ecosystem reeled on Sunday after Curve Finance stole $52 million, a trading bot entered the fray. His mission: to wholesale copy the attackers, secure millions of dollars in cryptocurrencies before they disappear, and then give it all back in an apparent white hat intervention.
There is an issue with the Vyper programming language used to write smart contracts on the Ethereum blockchain a window of opportunity for exploits related to liquidity pools on Curve Finance, one of DeFi's preferred exchanges.
At the time of writing, Curve has a total value of $1.6 billion, down 42% from the last day, but still represents a significant portion of Ethereum's $23 billion DeFi landscape makes up DefiLlama.
Attackers manipulated the price of tokens in multiple liquidity pools where one token can be exchanged for another. Youngest Reports Blockchain security company PeckShield estimates that $52 million was lost. But the attackers didn't get away with the entire supply.
Someone used the exploit on Curve’s CRV ETH liquidity pool—where Ethereum can be exchanged for the exchange's governance token, Curve DAO (CRV).—to exploit the exploiters, so to speak. The transaction cost about $32 worth of crypto in transaction fees but produced a return 2,879 Ethereum – a profit of around $5.4 million.
The 2,879 Ethereum was ultimately returned to Curve by a bot named “c0ffeebabe.eth.” Etherscan. By default, Ethereum addresses are a long string of alphanumeric characters, but the bot's owner gave it a human-readable name using Ethereum naming service. PeckShield also credits the bot with looting an additional $1.6 million from synthetic asset protocol Metronome, and a representative from the security firm told Decrypt that 90% of those funds have now been returned as well.
The bot's action was a lucrative split-second arbitrage game involving flash loans and decentralized exchanges Uniswapsaid Yixin Cao, senior data scientist at DeFi analytics platform EigenPhi Decipher.
The story goes on
“Not many actors can do that,” she said. “There are many sophisticated attackers, but this type of arbitrage requires very in-depth knowledge.”
Uniswap and Balancer
EigenPhi's tear down The transaction details 16 different steps the bot took – but the game depended on two different DeFi projects.
C0ffeebabe.eth's split-second trading initially used Balancer, a liquidity protocol, for a quick loan of 100 Ethereum. Flash loans are unsecured and require the borrower to repay them as part of the same transaction.
Then Uniswap was essential, Cao said, because it allowed c0ffeebabe.eth to capitalize on the discrepancy between the CRV price on Uniswap and the Curve it wanted to create using the Vyper bug. The bot exchanged 70 Ethereum for over 190,000 CRV via Uniswap.
An initial breakout of 30,000 CRV aimed at Curve's CRV-ETH pool caused the Vyper bug to knock it off balance. The unbalanced condition of the pool is permitted c0ffeebabe.eth trades its remaining CRV for 2,949 Ethereum – 317x what it otherwise could have gotten without the exploit.
After repaying the quick loan, c0ffeebabe.eth made a significant profit.
The Vyper exploit turned a small game into a massive game, Cao said. Without exploiting the vulnerability, c0ffeebabe.eth would have only received 9.3 Ethereum, according to a simulation conducted by EigenPhi.
On-chain hope
Shortly after the deed was done, c0ffeebabe.eth sent a message using Internal Data Messages (IDM), which allows messages to be sent on the Ethereum blockchain.
““If funds are moved to the cold wallet for the time being, affected protocols can contact via the Etherscan chat,” said the person behind the bot said on-chain, signaling that they would securely store the stolen funds in a digital wallet whose private keys are isolated from the internet.
“Deployer from Curve”, an Ethereum account replied in the chain and identifies as part of the Curve team. “One broadcast you brought to the forefront was a hack of the CRV/ETH pool. Can a refund be made?”
This is what several blockchain security experts said Decipher that the c0ffeebabe.eth trade did not appear to be an example of leadership. Regardless, the bot ultimately walked away from what would have been its biggest payday ever.
According to EigenPhi, c0ffeebabe.eth had made a profit of around $29,000 through various arbitrage transactions before Sunday Account Profiler. Even though Sunday's takeaway dwarfed the bot's previous performance, it did not stop c0ffeebabe.eth from fulfilling its selfless white-hat service.
Editor's note: This story was updated after publication to include commentary from PeckShield.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.