Hassan, a Cryptonews.com journalist with 6+ years of experience in Web3 journalism, brings deep knowledge across Crypto, Web3 Gaming, NFTs, and Play-to-Earn sectors. His work has appeared in...
Has Also Written
Last updated:
June 13, 2024
UwU Lend, a decentralized finance (DeFi) lending protocol, has suffered another significant security breach today, resulting in an approximately $3.7 million loss.This attack, executed similarly to the previous hack, targeted multiple liquidity pools and converted the stolen assets into Ethereum.This incident marks the latest high-profile breach affecting UwU Lend. At the time of writing, the Hacker still holds all the funds in the wallet.
UwU Lend Lost $3.7 Again 🚨ALERT🚨@UwU_Lend has suffered another security breach by the same attacker!
Total loss: $3.7M
Affected pools: uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, uUSDT
All stolen assets have been converted to $ETH and are located at the attacker's address: https://t.co/9TvwLh18P1
To learn… https://t.co/AjcMS1Cdyl
— 🚨 Cyvers Alerts 🚨 (@CyversAlerts) June 13, 2024
Today, UwU Lend suffered another significant security breach, losing approximately $3.7 million. The decentralized finance (DeFi) protocol, known for its lending services, was targeted by the same attacker responsible for a previous hack.
This most recent exploit affected several pools, including uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, and uUSDT, with all stolen assets converted to Ethereum (ETH) and currently residing at the attacker’s address “0x841ddf093f5188989fa1524e7b893de64b421f47.”
The attack occurred on June 13, 2024, at 07:46:23 AM +UTC. According to Cyvers Alerts, the attacker used a sophisticated method to bypass security measures, similar to the previous breach. The initial breach involved the attacker gaining access to UwU Lend’s smart contracts and manipulating them to drain funds from various liquidity pools.
The stolen assets, including multiple stablecoins and other tokens, were converted into Ethereum to obfuscate their trail. Currently, the assets are held in the attacker’s wallet, and efforts to trace and recover the funds are ongoing.
Previous Attacks on UwU LendOn June 10, UwU Lend was previously hacked for nearly $20 million. This exploit manipulated the protocol’s price oracle, particularly the sUSDe asset. The attacker utilized the Tornado Cash crypto-mixing protocol to fund the exploit, executing three transactions within six minutes to drain significant assets.The immediate response included pausing the protocol and adjusting borrowing and deposit rates to zero to prevent further losses. The UwU Lend team has been actively investigating the incident to understand the attack vector and bolster security measures.Despite efforts to mitigate the impact, the attacker exploited vulnerabilities effectively, converting stolen assets to Ethereum and complicating recovery efforts.In response to the previous attack, Michael Patryn, known as 0xSifu and the founder of UwU Lend, proposed a deal to the hacker on June 11. He offered to drop potential charges in exchange for the return of about $16 million in stolen funds.As of the time of writing, no update has been received regarding the last hack, and the hacker of this new hack still holds the fund in a wallet.
TLDR UwU Lend, a DeFi lending protocol, suffered another hack, losing approximately $3.5 million to $3.7 million, just days after a previous $20 million exploit. The ongoing exploit targeted multiple asset pools, including uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, and uUSDT, with the stolen funds being converted to Ethereum. The attack occurred during the reimbursement process for the previous hack victims, with UwU Lend having already repaid over $9.7 million in bad debt. The initial exploit was caused by price manipulation, while the latest exploit is a consequence of the attacker holding sUSDE tokens gained from the first attack. UwU Lend’s total losses from both hacks amount to around $23 million, causing a significant decline in the value of its governance token, UWU. UwU Lend, a decentralized finance (DeFi) lending and liquidity protocol, has fallen victim to yet another significant security breach, just days after suffering a $20 million exploit.
The latest attack, which occurred on June 13, 2024, has resulted in an additional loss of approximately $3.5 million to $3.7 million, bringing the total losses to around $23 million within a single week.
The ongoing exploit targeted multiple asset pools within the UwU Lend protocol, including uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, and uUSDT.
The stolen funds, amounting to roughly $3.5 million, have been converted to Ethereum (ETH) and are currently held in the attacker’s wallet address, “0x841dDf093f5188989fA1524e7B893de64B421f47.”
????ALERT????@UwU_Lend has suffered another security breach by the same attacker!
Total loss: $3.7M
Affected pools: uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, uUSDT
All stolen assets have been converted to $ETH and are located at the attacker's address: https://t.co/9TvwLh18P1
To learn… https://t.co/AjcMS1Cdyl
— ???? Cyvers Alerts ???? (@CyversAlerts) June 13, 2024
The attack took place during the reimbursement process for victims of the previous $20 million exploit. UwU Lend had already repaid over $9.7 million in bad debt, including 481.36 wETH worth more than $1.7 million for the Wrapped Ether (wETH) market alone.
The initial exploit, which occurred on June 10, was caused by price manipulation. The attacker used a flash loan to swap USDe for other tokens, leading to a lower price of Ethena USDe (USDE) and Ethena Staked USDe (SUSDE).
By depositing the tokens to UwU Lend and lending more SUSDE than expected, the attacker drove the USDE price higher, ultimately stealing nearly $20 million in tokens.
According to CertiK, a crypto security firm, the latest exploit is not due to the same vulnerability but rather a consequence of the first attack. The attacker gained a significant number of sUSDE tokens from the initial exploit and, despite the protocol being paused, UwU Lend still considered sUSDE as legitimate collateral.
This oversight allowed the attackers to exploit the remaining sUSDE and drain the remaining pools.
The series of hacks has had a significant impact on UwU Lend’s governance token, UWU, which has shed 14.5% of its value over the past seven days and 81% in the past year, now holding a market cap of just $26 million.
Oliver Dale
Editor-in-Chief of Blockonomi and founder of Kooc Media, A UK-Based Online Media Company. Believer in Open-Source Software, Blockchain Technology & a Free and Fair Internet for all. His writing has been quoted by Nasdaq, Dow Jones, Investopedia, The New Yorker, Forbes, Techcrunch & More. Contact [email protected]
The UwU Lend hacker returns to swipe another $3.7 million.The lending protocol was hacked using a flash loan for $23 million on Monday.UwU Lend users rejoiced on Wednesday after the lending protocol said it was able to fully reimburse victims of its recent $23 million exploit.
But their celebrations were cut short when at 7:46 am London time, the same hacker returned to take another $3.7 million.
That’s despite UwU Lend offering the hacker a 20% bounty — worth $4 million — to return users’ funds from a Monday hack.
According to Yaron Velner, CEO of risk management project B.Protocol, the hacker was able to drain more money from the protocol using its intended functions due to an oversight from its developers.
“The operation today did not entail any manipulation. Just a malicious intent, and erroneous configuration on UwU side,” he told DL News.
It comes after UwU Lend said in a June 12 X post that it had identified and fixed the vulnerability in its sUSDe market that the hacker previously exploited.
“All other markets have been re-reviewed by industry professionals and auditors with no issues or concerns found,” the protocol said.
UwU Lend did not return a request for comment.
UwU Lend began repaying users on Wednesday after the $23 million exploit forced it temporarily offline.
As of 5 am on Thursday, the protocol said it had repaid about $9.7 million stolen in the first hack.
“The protocol will repay all bad debt, as quickly as reasonably possible,” UwU Lend said. “We are happy to announce that no user funds have been lost due to this process.”
UwU Lend’s controversial founder Michael Patryn, better known by his pseudonym 0xSifu, had previously offered to drop any charges if the hacker returned 80% of the stolen crypto, worth about $18 million.
Oracle attackOn Monday, a hacker used a $4 billion flash loan to manipulate the price of certain tokens on UwU Lend, which allowed them to drain the protocol.
A flash loan is a type of DeFi transaction where a user borrows funds from a lending protocol and repays them in the same transaction.
While flash loans are often used by market makers to quickly arbitrage price differences in DeFi markets, they also make possible exploits that require large amounts of capital to perform.
Zircuit co-founder Martin Derka — who co-developed a tool to detect flash loan-based exploits while at crypto security firm Quantstamp — said such exploits were notorious in DeFi.
“These kinds of vulnerabilities are usually very difficult to discover during smart contract audits, because they require in-depth knowledge of multiple protocols — those that one is auditing, and those that are being used as oracles,” he told DL News.
“There are also not enough automated tools that are capable of discovering such vulnerabilities.”
Launched in 2022, UwU Lend is a fork of Aave, the largest DeFi lending protocol with $12.4 billion of deposits.
A fork is where a developer team uses the open-source code from an existing DeFi protocol to launch a similar protocol — often on a different blockchain or with minor changes.
But the changes to Aave’s code allowed the hacker to drain UwU Lend. The protocol used easily manipulated oracles — software that provides it with the prices of various tokens.
UwU Lend’s UWU token is down 15% over the past week, and trades at around $2.70.
Update, June 13: This article was updated to include comments from B.Protocol CEO Yaron Velner that clarify the $3.7 million theft was not caused by a separate exploit. An earlier version misstated the name of the blockchain Martin Derka co-founded; it is Zircuit, not Circuit.
Aleks Gilbert is a DeFi Correspondent at DL News. Got a tip? Email him at [email protected].
UwU Lend, a blockchain lending platform, suffered a second exploit just as it began reimbursing victims from a recent $20 million hack. The initial attack on June 10 involved hackers manipulating the prices of USDe tokens to steal other cryptocurrencies from the platform.
On June 13, the protocol announced on X that it had started the payouts for all bad debts in the $wETH market, which totaled around 481.36 $wETH ($1,734,042). It also said it has refunded victims 80% of their assets on the network before the attack.
During this process, hackers struck the platform again, draining more funds from the protocol.
Cyvers, an on-chain data analytics firm, detected irregularities on the protocol and immediately alerted UwU Lend. The company confirmed that the attackers behind this new breach were the same individuals responsible for the earlier $20 million theft.
🚨ALERT🚨Hey @UwU_Lend, you are being targeted again by same hacker!
Look at this trx: https://t.co/RstdittKpK
More info will follow!
Want to keep your company off our alerts radar? Learn how to secure your assets: Book a Demo 🚀 https://t.co/uUbFkFTp4h#CyversAlert pic.twitter.com/mMMTByHNkK
— 🚨 Cyvers Alerts 🚨 (@CyversAlerts) June 13, 2024
Details of the Second Exploit The latest exploit has already drained $3.5 million from various asset pools, including uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, and uUSDT. At the time of writing, the criminals have successfully swapped the stolen assets for Ethereum (ETH).
The timing of this attack could not be worse for UwU Lend. Just as the team was making progress in repaying their debt, they now face additional losses and heightened security concerns. However, the protocol was able to repay a total of $9,715,288 before the second attack.
On June 12, UwU Lend announced that it had identified the cause of the first exploit, which led to the suspension of all activities on the network. According to the platform, the cause of the first attack was “unique to the USDe market oracle”.
The platform claimed it had fixed the bug and would gradually restart the network, adding that other market oracles on the platform were “re-reviewed by industry professionals and auditors with no issues or concerns found”.
Ongoing Challenges Despite these claims, the hackers still found a way to exploit the platform again. UwU Lend has yet to publicly acknowledge the second attack and the cause is still unknown.
Meanwhile, the repeated breaches on UwU Lend underscore the vulnerabilities within decentralized finance (DeFi) platforms. Many platforms in the DeFi ecosystem have suffered massive exploits this year.
In March, cybercriminals stole $8.75 million from Woofi when attackers exploited vulnerabilities in its Swap Synthetic Proactive Market Making (sPMM). Another platform, Hedgey Finance, a token infrastructure protocol, was hit with two parallel exploits resulting in the loss of $44.7 million worth of cryptocurrencies. According to CertiK, the first three months of 2024 witnessed a series of hacks that wiped out more than $502 million worth of digital assets from the industry.
Disclaimer: Coinspeaker is committed to providing unbiased and transparent reporting. This article aims to deliver accurate and timely information but should not be taken as financial or investment advice. Since market conditions can change rapidly, we encourage you to verify information on your own and consult with a professional before making any decisions based on this content.
Cybersecurity News, News
Chimamanda is a crypto enthusiast and experienced writer focusing on the dynamic world of cryptocurrencies. She joined the industry in 2019 and has since developed an interest in the emerging economy. She combines her passion for blockchain technology with her love for travel and food, bringing a fresh and engaging perspective to her work.
Decentralized finance protocol UwU Lend has suffered another exploit from the same attacker, costing it $3.7 million worth of stolen funds.
UwU Lend, an Ethereum-based lending and liquidity protocol, has apparently suffered another hack from the same attacker, who exploited the protocol two days ago for nearly $20 million.
According to data from Cyvers Alerts, the hacker drained $3.7 million in liquidity from pools including uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, and uUSDT. All stolen assets have been converted to ETH and are currently held at the attacker’s address, the firm added.
As noted by an X user under the alias @CryptoEvgen, the hacker used funds “stolen during the first hack for this new attack.” The cause of the latest incident remains unclear, and UwU Lend has yet to make a public statement on the matter.
The latest incident comes just two days after UwU Lend lost $20 million worth of crypto, what the protocol described as a “sophisticated attack.” As crypto.news reported, the attacker seemingly utilized Curve LlamaLend as the “exit liquidity” for the attack.
UwU Lend was founded by Michael Patryn, also known as Omar Dhanani or “0xSifu,” who is a co-founder of the ill-fated QuadrigaCX exchange. Based on the open-source AAVE v2 code, UwU Lend offers lending, borrowing, and staking services, and shares platform revenues with users through its native token, UwU.
Ethereum (ETH)-based decentralized finance (DeFi) protocol UwU Lend just suffered a security breach that siphoned $23 million worth of crypto from its platform.
In a post on social media platform X, the team behind UwU Lend says the protocol will be paused until the investigation of the exploit has concluded.
[adinserter block="1"]
“Yesterday UwU Lend was the target of an exploit involving a sophisticated attack. The team reacted swiftly and the protocol was paused within minutes. Rates for borrows and deposits have been set to 0% so users’ positions will not be affected by this pause.”
UwU Lend already made an offer to the hacker and is now awaiting a response. In an on-chain message, the lending and liquidity protocol says the exploiter will get a white hat bounty in exchange for returning the stolen assets.
“UwU Lend would like to discuss a bounty with any parties involved in the recent UwU Lend exploit. We are offering a 20% white hat bounty of any funds taken, which you may keep if you return the remaining 80% to uwulend.eth. You will face no risk of us pursuing this further and no risk of law enforcement issues.”
The exploiter has until 5 PM on June 12th to voluntarily return the assets. Otherwise, UwU Lend says it will offer the bounty to the public and reward 20 percent to anyone who can identify the hacker in a way that will lead to a conviction in court.
UwU Lend suffers a second exploit this week, resulting in a $3.7 million loss. The same exploiter is believed to be responsible.
The UwU Lend protocol, previously targeted in a nearly $20 million hack on June 10, is facing an ongoing cryptocurrency exploit that has so far resulted in the theft of $3.7 million.
This development comes as the protocol has been making efforts to reimburse its users following the $19.3 million June 10 hack.
$3.7 Million Hack Cyvers, an on-chain data analytics platform, was the first to alert UwU Lend about the ongoing exploit. According to its findings, the bad actors behind this latest incident appear to be the same as those responsible for the earlier $19.3 million heist.
ALERT@UwU_Lend has suffered another security breach by the same attacker!
Total loss: $3.7M
Affected pools: uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, uUSDT
All stolen assets have been converted to $ETH and are located at the attacker’s address: https://t.co/9TvwLh18P1
To learn… https://t.co/AjcMS1Cdyl
— Cyvers Alerts (@CyversAlerts) June 13, 2024
The stolen funds, sourced from various asset pools, including uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, and uUSDT, have already been converted into Ethereum and transferred to the attacker’s address.
Following the initial breach on June 10, the development team at UwU Lend notified the community that they had implemented immediate measures to mitigate the damage. The protocol was temporarily paused while investigations were conducted into the vulnerabilities exploited by the hackers.
In an update shared on June 12 via a thread on X, the UwU developer team disclosed that they had identified the specific vulnerability related to the sUSDe market oracle and claimed to have resolved it.
You may also like: Important Ripple (XRP) Deadline Concerning Many Users Jaredfromsubway Hacker Ignores 50% Bounty, Routes Funds to Tornado Cash Sahara AI Denies Security Issues as Token Price Drops Over 60% (1/5)
The team has now identified the vulnerability, which was unique to the sUSDe market oracle and has now been . All other markets have been re-reviewed by industry professionals and auditors with no issues or concerns found.
— UwU Lend (@UwU_Lend) June 12, 2024
They added that independent audits of all other markets had been conducted without discovering additional issues, assuring users that all functions would resume promptly and emphasized that no user funds had been permanently lost during the incident.
Reimbursement Efforts Following the incident, UwU initiated reimbursement efforts, informing users that “The protocol will repay all bad debt as quickly as reasonably possible. We will keep users up to date about progress and the next steps.”
In a final update on June 13, the team reported that they had successfully reimbursed a total of $9,715,288 to affected users thus far. The breakdown included specific amounts returned in various cryptocurrencies such as DAI, crvUSD, USDT, and wETH.
UwU Lend, a fork of the open-source AAVE v2 protocol, offers its users various decentralized finance services such as lending, borrowing, and staking. One of its unique features includes a revenue-sharing token called UwU, which allows users to earn a portion of the platform’s revenues directly.
UwU Lend has put up a $5 million bounty in ETH for anyone who can apprehend the hacker behind the recent heists.
This move comes after the efforts to get the hacker to release the stolen funds proved futile.
UwU Lend Offers $5M to Catch Hacker UwU Lend, a decentralized lending protocol, is offering a $5 million bounty in Ethereum for ‘the first person to identify and locate’ the hacker who has been carrying out attacks lately. In the announcement made through Input Data Message (IDM) on Ethereum, there is no demand for the recovery of funds or facing the criminal charges.
This bounty comes after unsuccessful talks with the hacker where UwU Lend proposed to give the hacker 20% of the stolen funds if the rest 80% would be returned. The hacker did not follow the offer that was made to him/her, and therefore UwU Lend had to step up its actions.
Source: IDM
On Monday, the exploiter utilized a flash loan attack to hack UwU Lend, and the platform lost $20 million. Another raid occurred on Thursday, resulting in the loss of another $3.7 million. According to blockchain security experts, the same person is behind both attacks.
Previous Offers and Deadlines UwU Lend at first tried to settle the dispute without involving the police by offering the exploiter a deal. If the hacker decided to return 80% of the stolen amount, he would be allowed to retain the 20% and be let off the hook.
This offer was extended with a deadline of Wednesday, 1 p.m. ET (17:As at 00:00 UTC, which was the agreed time to shut down the system, the hacker did not do so.
By Thursday, UwU Lend informed that the repayment period has been over and, therefore, the protocol had to think about other options which resulted in the creation of the $5 million bounty.
Repeated Exploits and Security Concerns The first incident on June 10 was a flash loan attack that manipulated price oracles of sUSD stablecoin which left the platform to lose $20 million. After this, UwU Lend came out and said that the problem has been noted and fixed. However, another attack on June 13 resulting in a loss of $3.7 million, showed that the security issues had not been fully addressed. Both of these attacks have caused concerns in the DeFi industry on the effectiveness of security measures that have been put into place in decentralized platforms.
Due to its connection with Michael Patryn, also known as Omar Dhanani and 0xSifu, co-founder of the collapsed cryptocurrency exchange QuadrigaCX, UwU Lend has attracted criticism. This background has compounded the problem of rebuilding user trust in the wake of the exploits.
We have made an offer to the hacker and are awaiting a response. The protocol will remained paused until the investigation has concluded. Thank you for your patience during this time.
List of approximate assets and values taken listed below.
— UwU Lend (@UwU_Lend) June 11, 2024
The experts advise the application to utilise better real-time tracking and stronger security measures to reduce the risk to the users’ valuables. However, in light of the recent breaches, UwU Lend has ensured its clients that their funds are secure and that all the losses incurred will be recovered at the earliest.
The company has also thanked security firms such as Hypernative Labs for their timely notifications that allowed the company to act quickly to minimize the effects of the exploits. UwU Lend has also ceased and is slowly bringing back its markets, and working on getting back to normalcy.
Read Also: Bitcoin Book Spurs US Bill to Abolish Federal Reserve
In a Thursday broadcast, UwU Lend consents to a $5 million bounty reward in ETH to whoever discovers the identity of the hacker(s) who breached their protocol. The DeFi protocol has reportedly suffered another breach, which cost $3.72 million.
UwU Lend suffers $23 million breach, sets bounty reward of $5 million for hacker reveal Based on an Input Data Message on Thursday via Etherscan, UwU Lend established a bounty reward for anyone who can reveal the identity of the hacker who breached through their walls. The reward, which is $5 million in ETH, will be delivered upon exposure of the exploiter.
Read more: AAVE price tumbles 20% in 2024 despite doubling its total value locked
The decentralized finance platform had previously attempted to resolve the issue with the hacker without pressing charges, given that the culprit would return 80% of the funds extracted on Monday. This message was released via an IDM on Monday following the breach, with an ultimatum of 17:00 UTC on Wednesday to return the funds.
As the unknown hacker failed to heed a settlement request from UwU Lend, the platform proceeded with the bounty reward approach.
Also read: Why Bitcoin remains sideways despite record BTC ETF inflows
“The repayment deadline for the funds you stole has passed. $5 Million bounty to the first person to identify and locate you, paid in ETH. No recovery of funds or charges is required. Have a nice day,” the announcement stated.
UwU Lend experienced a breach on Monday, which led to an exploit of $19.3 million. The DeFi platform was reported to have suffered another breach of $3.72 million earlier today, totaling $23 million, according to blockchain security firm SlowMist.
Read more: SEC Chair says Ethereum ETF S-1 approvals likely to come over the summer
This breach is the latest among several reported attacks targeted at crypto protocols. A recent report from Cointelegraph stated that the total estimate for breaches among crypto firms totaled $19 billion over the last 13 years, dating back to 2011.
The same hacker that exploited $20 million from UwU Lend earlier this week stole another $3.7 million using the funds stolen in the first exploit to carry out the second attack.
The hacker used the sUSDe tokens from the first hack to drain UwU Lend’s pools in the second attack.
Shutterstock
Posted June 13, 2024 at 9:10 pm EST.
UwU Lend, the decentralized finance (DeFi) protocol that lost $20 million in an exploit on June 10, has been attacked again by the same hacker in the midst of a reimbursement process for affected users.
Blockchain security firm Cyvers alerted users on X to the ongoing exploit on Thursday, with onchain data showing that the attacker stole a further $3.7 million from the UwU Lend protocol.
The attacker exploited uDAI, uWETH, uLUSD, uFRAX, uCRVUSD and uUSDT asset pools and has already converted the stolen funds to ether.
The June 10 exploit was carried out by way of a flash loan attack, where the attacker swapped the USDe stablecoin for other tokens, manipulating the price of USDe and sUSDe.
The UwU Lend team said on June 12 they had identified and resolved that the vulnerability was unique to the sUSDe market oracle, and had unpaused the protocol and started paying off the protocol’s bad debt and reimbursing users.
UwU Lend repaid $9.7 million worth of bad debt, but because the protocol still treated the hacker’s funds as legitimate collateral and attacker still held a significant amount of these tokens from the first exploit, the attacker was still able to drain UwU Lend’s other pools.
Web3 security firm MetaTrust Labs noted that the hacker used 60 million sUSDe from the previous hack as collateral to drain the pool, and still holds 5 million sUSDe tokens.
UwU Lend was created by collapsed crypto exchange QuadrigaCX co-founder Michael Patryn or “0xSifu,” who offered the hacker a 20% bounty in exchange for returning 80% of the stolen funds.
That offer appears to be off the table based on Sifu’s latest blockchain message to the hacker.
“Repayment deadline for the funds you stole has passed. Five million dollar bounty to the first person to identify and locate you, paid in ETH,” wrote Sifu.
Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure
DeFi lending protocol UwU Lend has suffered two attacks in the past three days. The second exploit occurred on Thursday during the protocol’s reimbursement process from the first hack. The ongoing saga has taken around $23 million from the protocol.
DeFi Protocol Hit With $20 Million Exploit On June 10, DeFi project UwU Lend was hit by a sophisticated attack that took $19.3 million. The attack seemingly involved the use of flash loans to exploit the protocol. The project quickly addressed the situation by pausing the protocol and assured users that most assets were safe.
UwU Lend acknowleges $20 million exploit. Source: UwU Lend on X Additionally, the team offered a $4 million white hat bounty for the return of the funds. The list of stolen assets included Wrapped Ethereum (wETH), Wrapped Bitcoin (wBTC), Curve DAO (CRV), Tether (USDT), Staked USDe (sUSDE), and others.
Blockchain security firm Beosin revealed that the attacker manipulated the price of USDe (USDE) by swapping it for other tokens through flash loans. Seemingly, this move lowered USDe and sUSDE’s price.
Following the price manipulation, the hacker deposited part of the tokens to UwU Lend and “lent more $sUSDe than expected,” driving USDe’s price higher. Similarly, the attacker deposited the sUSDE to the DeFi protocol and borrowed CRV.
On Wednesday, UwU Lend informed users that its team had identified the vulnerability. Per the post, it was a vulnerability unique to the sUSDE market oracle and had been resolved at the time of the report.
As a result, the protocol was unpaused, and the markets were slowly relaunched to return to their normal operations. The DeFi project also announced it would repay all its bad debt and that users’ funds had not been lost during the exploit, claiming that their funds “are safu at UwU Lend.”
Do You Get DéFì Vu? What seemed to be the end of the story turned out to be the first installment of a saga. On Thursday, reports of a second attack on UwU Lend appeared as the protocol carried out its reimbursement process.
According to the reports, the same attacker drained another $3.7 million from the DeFi protocol before converting the funds to ETH again. The affected pools included uDAI, uWETH, uLUSD, uFRAX, UCRVUSD, and uUSDT.
The crypto community expressed their concern about the second attack, with many questioning if their funds were indeed safe. Users started to joke that funds were not “safu” but were “with Sifu” instead.
Crypto community shares memes about the attack. Source: ZachXBT on X UwU Lend was founded by Michael Patryn, also known as Sifu. Patryn was the co-founder of the now-collapsed QuadrigaCX. As reported by Bitcoinist, Canadian authorities were pursuing an unexplained wealth order (UWO) against Sifu for his involvement in the exchange’s criminal activities.
The DeFi project has paused the protocol for the second time this week, and the situation is being investigated. However, online reports claim that the second exploit was caused by a vulnerability similar to the first attack.
MetaTrust Labs explained the hacker seemingly used 60 million uSUSDE obtained from Monday’s hack “as collateral to drain the pool.”
The news caused users to wonder whether the UwU Lend team was unaware of the tokens in the attacker’s wallet. Some also questioned why they didn’t stop supporting the sUSDE collateral.
At the time of writing, an official explanation for the second exploit has not been published.
ETH is trading at $3,447 on the three-day chart. Source: ETHUSDT on TradingView Featured Image from Unsplash.com, Chart from TradingView.com
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.
UwU Lend, a DeFi lending protocol, suffers a second $3.7 million hack during reimbursement efforts from a previous $19.3 million attack, raising security concerns.UwU Lend, a DeFi lending protocol, has suffered two attacks within three days, losing a total of $23 million. The second attack occurred on Thursday while the protocol was trying to reimburse users from the first hack.
On June 10, UwU Lend was struck by a sophisticated attack, resulting in a loss of $19.3 million. The attackers used flash loans to exploit the protocol. In response, UwU Lend paused its operations and assured users that most assets were secure. They also offered a $4 million white hat bounty for the return of the stolen funds. The stolen assets included Wrapped Ethereum (wETH), Wrapped Bitcoin (wBTC), Curve DAO (CRV), Tether (USDT), Staked USDe (sUSDE), and others.
Blockchain security firm Beosin revealed that the attacker manipulated the price of USDe (USDE) by swapping it for other tokens using flash loans. This devalued USDe and sUSDE. After the price manipulation, the hacker deposited some tokens into UwU Lend and borrowed more $sUSDe than expected, driving USDe’s price higher. Similarly, the attacker deposited the sUSDE to UwU Lend and borrowed CRV.
By Wednesday, UwU Lend announced they had identified and fixed the vulnerability, unique to the sUSDE market oracle. The protocol was unpaused, and markets were gradually reopened. The team assured users that their funds were safe and that all bad debts would be repaid.
Just as the situation seemed under control, a second attack was reported on Thursday during the reimbursement process. This time, the same attacker drained another $3.7 million from the protocol and converted the funds back to ETH. The affected pools included uDAI, uWETH, uLUSD, uFRAX, UCRVUSD, and uUSDT.
The crypto community reacted with concern, questioning the safety of their funds. Many joked that the funds were not “safu” but were “with Sifu,” referring to UwU Lend’s founder Michael Patryn, also known as Sifu. Patryn, a co-founder of the collapsed QuadrigaCX, is currently under investigation by Canadian authorities for his involvement in the exchange’s criminal activities.
UwU Lend has paused the protocol again this week to investigate. Reports indicate that the second exploit was caused by a vulnerability similar to the first attack. MetaTrust Labs explained that the hacker used 60 million uSUSDE obtained from Monday’s hack as collateral to drain the pool.
This series of events led users to question whether the UwU Lend team knew about the tokens in the attacker’s wallet and why they didn’t stop supporting the sUSDE collateral.
As of now, UwU Lend has not provided an official explanation for the second exploit. Users are left wondering how a similar attack could happen so soon after the first and whether the protocol’s security measures are adequate to prevent future breaches.
The challenges faced by UwU Lend highlight the vulnerabilities in DeFi protocols and the importance of strong security measures. As the investigation continues, the DeFi community will be closely watching to see how UwU Lend addresses these issues and what steps they take to restore user confidence.
UwU Lend’s recent experiences highlight the risks involved in DeFi protocols. The quick succession of attacks has shaken user confidence and raised important questions about the protocol’s security. As the investigation unfolds, UwU Lend must address these vulnerabilities and implement stronger safeguards to protect their users and assets. The outcome will have significant implications for the broader DeFi ecosystem, emphasizing the need for continuous improvement in security practices and protocols.
Cryptocurrencies are highly volatile and involve significant risk. You may lose part or all of your investment.
All information on Coinpaprika is provided for informational purposes only and does not constitute financial or investment advice. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions.
Coinpaprika is not liable for any losses resulting from the use of this information.
Decentralized lending protocol UwU Lend has unveiled a $5 million bounty to “identify and locate” the exploiter.
Developers of UwU Lend are promising to pay up to $5 million “to the first person to identify and locate” a hacker, who exploited the protocol for over $23 million worth of crypto. The bounty was announced shortly after the attacker missed the deadline set by the UwU Lend team, who expected the return of 80% of the stolen funds in exchange for a 20% reward.
As crypto investigator @CryptoEvgen noted in their X account, the hacker started funneling the stolen assets via Tornado Cash, a mixing service sanctioned by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) for facilitating approximately $7 billion in crypto laundering since 2019.
As of press time, it’s understood that the hacker has already laundered at least 500 ETH, valued at approximately $1.7 million at current market prices.
UwU Lend, which leverages the open-source AAVE v2 code, suffered two separate attacks from the same hacker in less than three days, executing what appears to be flash loan attacks that compromised multiple liquidity pools.
Founded by Michael Patryn, also known as Omar Dhanani or “0xSifu” — a co-founder of the now-defunct QuadrigaCX exchange — UwU Lend provides lending, borrowing, and staking services while distributing platform revenues through its native token, UwU.
The leading cryptocurrency is trading at $66,700, and altcoin sales have weakened. One of this week’s most significant developments was the UwU Lend attack. The Curve CEO made important statements to clear up misinformation. What did he say?
The Curve CEO spoke about the UwU Lend hack and the CRV token burn. Michael Egorov has been in the spotlight during many market downturns. Speculative traders targeting the liquidation price of his DeFi position have often triggered significant losses in the CRV Coin price through social media discussions.
Egorov made the following statements regarding recent events:
“This was not an exploitation of Curve Finance. It was an exploitation of a separate project (UwU Lend). As part of the cash-out game, the hacker deposited the CRVs taken from UwU into lendcurvefi (LlamaLend) and disappeared with the funds, leaving the debt in the system.”
To prevent similar attacks in the future, he suggested “revalidating all contracts and having them reviewed by good security auditors.”
CRV Coin BurnThere was a lot of misinformation, which also triggered recent CRV Coin price fluctuations. Egorov made statements on this matter as well. These statements were crucial to preventing the spread of false information on social media:
“This information was tweeted by a fake (impersonator) account, accompanied by a scam link. Several journalists did not verify the news and published it.”
So, what are the positions of the Curve CEO?
“The CRVs sent as collateral for loans likely accounted for about 30% of the circulating supply; half of this was in Curve, so indeed some doubtful receivables were formed. It was already repaid. No one was affected. For smaller cryptos (e.g., not BTC or ETH as collateral), debt ceilings should probably be provided; data shows that Curve-specific markets can be well parameterized to withstand these conditions.”
Egorov also mentioned that steps could be taken regarding open-source liquidation bots in the future.
“It seems the industry’s heavyweights did not fully know how to handle liquidations; they did not attempt partial hard liquidations for my position in Curve. I had to do it myself in the end. In the future, this area could be better with open-source liquidation bots.”
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.