Nirvana Finance, a Solana-based yield protocol, suffered a $3.5 million exploit using flash loans to manipulate and drain its liquidity pools, blockchain data shows.
The price of the protocol’s native ANA token has fallen over 80% in the past few hours, while its NIRV stablecoin lost its peg to the US dollar, falling to 8 cents at the time of writing, data from CoinGecko shows.
Nirvana allowed users to earn over 100% annual returns on their locked assets by creating and destroying tokens based on user demand as the ANA tokens were bought by the protocol and sold to the protocol. ANA, worth over $3.5 million, was suspended from the record before Thursday’s attack.
Flash loans are a popular method for attackers to get the funds to run exploits on decentralized finance (DeFi) systems. In April, $182 million was withdrawn from Beanstalk’s stablecoin protocol, and more than $1.2 million was withdrawn from Inverse Finance last month.
The loans allow traders to borrow unsecured funds from lenders using smart contracts instead of third parties. They do not require collateral as the contract does not consider the transaction complete until the borrower repays the lender. This means that a borrower defaulting on a flash loan would result in the smart contract reversing the transaction and returning the funds to the lender.
Data from blockchain explorers shows the attack used over 10 million USDC obtained from lending tool Solend in a flash loan. At this point, over $10 million worth of ANA was minted or created, and the entire amount was traded to receive $3.5 million worth of Tether (USDT) from Nirvana’s Treasury wallet.
This was possible because the Treasury Department believed the $10 million USDC infusion to be genuine. This was not the case, however, and Protocol was thus tricked into releasing the liquidity of its treasury.
The attacker raised over $10 million USDC in a flash loan, draining Nirvana’s cash pool. (SolanaFM)
The total value locked (TVL) on Nirvana fell to 7 cents in the European morning hours after the attack. Its entire liquidity pool has effectively been drained, data from DeFi Llama shows.
The story goes on
The locked value on Nirvana fell to 62 cents after the attack. (DeFi Llama)
The 10 million USDC was returned to Solend after the exploit. The stolen funds were transferred to the Ethereum network using Wormhole, a blockchain tool that connects Solana to other networks, and converted to DAI, an Ethereum-based stablecoin, blockchain data shows.
The attacker’s address — 0xB9AE2624Ab08661F010185d72Dd506E199E67C09 — currently has over $3.5 million worth of DAI, blockchain data shows.
Nirvana’s trading features were suspended after the attack by developers, according to messages from admins on the protocol’s Telegram channel.
Nirvana had not responded to requests for comment as of the time of publication.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.