Cointime

Download App
iOS & Android

Recklessness Comes at a Cost? Zunami Protocol Attacked for Price Manipulation with a Loss of Over $2.1 Million

On August 14, 2023, Beosin EagleEye detected a price manipulation attack on the Zunami Protocol, a protocol on the Ethereum blockchain. The attack resulted in a loss of 1152 ETH($2.1 million).

It is understood that the Zunami Protocol is a platform that distributes stablecoins to users. It can be seen as a decentralized yield aggregator, providing more beneficial solutions for stablecoin holders.

There is an interesting twist to this incident. A security company had previously warned about vulnerabilities, but the project team did not take these warnings seriously, displaying a nonchalant attitude. As a consequence, by the time the incident occurred, it was already too late.

Beosin security team promptly analyzed the security incident and reported the following findings:

Attack-related Information:

● Attack Transactions:

Tx1: 0x2aec4fdb2a09ad4269a410f2c770737626fb62c54e0fa8ac25e8582d4b690cca

Tx2: 0x0788ba222970c7c68a738b0e08fb197e669e61f9b226ceec4cab9b85abe8cceb

● Attacker's Address:

0x5f4c21c9bb73c8b4a296cc256c0cde324db146df

● Attack Contract:

0xa21a2b59d80dc42d332f778cbb9ea127100e5d75

● Targeted Contract:

0xe47f1cd2a37c6fe69e3501ae45eca263c5a87b2b

Vulnerability Analysis:

The cause of this attack was the vulnerability in the contract where LP (Liquidity Provider) price calculation depended on the contract's own CRV balance and the exchange ratio of CRV in the wETH/CRV pool. The attacker manipulated the LP price by injecting CRV into the contract and manipulating the exchange ratio of the wETH/CRV pool.

Attack Process:

Taking transaction 0x2aec4... as an example:

Attack Preparation:

1. The hacker borrowed 6811 ETH using a balancer:Vault flash loan as attack funds.

2.  They exchanged 300 ETH borrowed through a flash loan for 84 zETH, preparing for the subsequent increase in zETH value

Attack Phase:

1. They exchanged 11 ETH for 35293 CRV and transferred it to the sEthFraxEthCurveConvex contract, enabling the attacker to manipulate the CRV balance in the sEthFraxEthCurveConvex contract for later manipulation.

2. They repeatedly exchanged 406 ETH for CRV in the wETH/CRV pool, causing the price of CRV to increase by approximately 10 times.

3. The value calculation of zETH (LP) depended on the price of CRV tokens and the valuation of CRV to ETH calculations in the sEthFraxEthCurveConvex contract.

4. The attacker manipulated the CRV price and the CRV balance in the vulnerable contract, causing the final _assetPriceCached to increase.

5. Due to the increased _assetPriceCached, the value of 84 zETH increased to 221 zETH.

6. They exchanged the CRV obtained in step 4 back to ETH to repay the flash loan.

7. They exchanged the increased 221 zETH (LP) for 389 ETH.

8. They repaid the 6811 ETH flash loan and other fees, resulting in a profit of 26 ETH.

Funds Tracing:

As of the time of writing, the Beosin security analysis team found that the stolen funds had all been transferred to Tornado cash.

Summary:

In response to this incident, the Beosin security team recommends:

1.  Similar projects should consider different token pool dependencies when calculating LP value.

2.  Before the launch of a project, it's advisable to engage a professional security auditing company for comprehensive security audits to mitigate security risks.

Beosin is a leading global blockchain security company co-founded by several professors from world-renowned universities and there are 40+ PhDs in the team, and set up offices in 10+ cities including Hong Kong, Singapore, Tokyo and Miami. With the mission of "Securing Blockchain Ecosystem", Beosin provides "All-in-one" blockchain security solution covering Smart Contract Audit, Risk Monitoring & Alert, KYT/AML, and Crypto Tracing. Beosin has already audited more than 3000 smart contracts including famous Web3 projects PancakeSwap, Uniswap, DAI, OKSwap and all of them are monitored by Beosin EagleEye. The KYT AML are serving 100+ institutions including Binance.

Contact

If you need any blockchain security services, welcome to contact us:

Offiial Website Beosin EagleEye Twitter Telegram Linkedin

Comments

All Comments

Recommended for you

  • 38,244.04 DMD Permanently Burned in the Past 7 Days

    On June 25, 2026, the latest on-chain data from DMDAO revealed that a total of 38,244.04 DMD has been permanently burned through the established transaction and wealth management burn mechanisms over the past 7 calendar days.

  • BTC Falls Below $60,000

    Market data shows that BTC has fallen below $60,000, currently priced at $59,954.84, with a 24-hour decline of 4.19%. The market is experiencing significant volatility, so please ensure proper risk management.

  • ETH Drops Below $1600

    Market data shows that ETH has fallen below $1600, currently priced at $1597.55, with a 24-hour decline of 3.81%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Billionaire Philippe Laffont Prefers Investing in Space Over Bitcoin

    Philippe Laffont, founder and portfolio manager of Coatue Management, stated on the Squawk Box program that he is currently unable to determine his stance on Bitcoin. He mentioned that he is rethinking Bitcoin's positioning and expressed a preference for investing in space over Bitcoin. (thestreet)

  • Tech Giants' Data Center Leasing Commitments Exceed $850 Billion

    On June 24, an analysis by Bloomberg of regulatory filings revealed that as tech giants compete to expand their server clusters, the total amount of future data center leasing commitments by large cloud computing companies has continued to rise over the past year, surpassing $850 billion. Last quarter, Meta added leasing commitments of $79 billion, a 76% increase from the previous period; as of March 31, the total reached $182.9 billion. Meta CEO Mark Zuckerberg has stated that the company plans to invest hundreds of billions of dollars in AI infrastructure by 2030. Microsoft followed closely, adding over $41 billion in leasing commitments, bringing its total to $196.6 billion.

  • Address with $34.61 Million Long Position in 21,000 ETH Faces $1.696 Million Loss at 18x Leverage

    According to on-chain analyst Ai Yi, a certain address took a long position of 21,000 ETH with 18x leverage yesterday, amounting to approximately $34.61 million. Currently, it is facing an unrealized loss of $1.696 million, with an opening price of $1,728.5 and a liquidation price of $1,590.1.

  • U.S. 10-Year Treasury Yield Falls to 4.4138%, Lowest Since May 11

    On June 24, the yield on U.S. 10-year Treasury bonds fell to 4.4138%, the lowest level since May 11. The yield on U.S. 30-year Treasury bonds dropped to 4.8572%, the lowest since April 15.

  • Crypto Market Liquidations Reach $134 Million in the Last Hour, with $125 Million in Long Liquidations

    According to CoinGlass data, the total liquidation amount across the network in the last hour reached $134 million, with long liquidations accounting for $125 million and short liquidations amounting to $8.539 million.

  • BTC Falls Below $61,000

    Market data shows that BTC has fallen below $61,000, currently priced at $60,986.03, with a 24-hour decline of 2.88%. The market is experiencing significant volatility, so please ensure proper risk management.

  • International Oil Prices Plunge as U.S. Oil Futures Fall Below $70

    On June 24, international crude oil prices continued to decline, with U.S. WTI crude oil futures falling below the $70 per barrel mark during trading, down 4.4% for the day, reaching a new low since March 2, and reverting to levels seen before the outbreak of the Iran conflict. Brent crude oil futures for August dropped 4.5%, settling at $73.6 per barrel. Market expectations of easing tensions in the Middle East, a recovery in Iranian oil supply, and rising interest rate expectations due to U.S. inflation have pressured oil prices.