Cointime

Download App
iOS & Android

An Account of the Recent White Hat Attack on DeFi Protocol Tender.fi

Validated Project

In the latest development in the world of Decentralized Finance (DeFi), Tender.fi, a DeFi lending protocol, fell victim to a white hat attack. The alleged ethical hacker behind the attack had managed to drain a whopping $1.6 million from the platform, forcing the service to halt borrowing while it attempts to recover its assets.

The attack, which took place on Mar-07-2023 at 08:21:38 AM +UTC, has caused significant concern among the DeFi community. According to Numen Cyber’s on-chain monitoring, the attacker siphoned 198 ETH, 541700 USDC, 16 WBTC, 8798 UNI, 50011 DAI, 36700 USDT, 24975 FRAX, and 16,203 LINK, causing the native token of the Tender.fi (TND) project to fall by over 30% before recovering slightly after the recovery of funds.

Timeline of Events

Tender.fi confirmed an incident on March 7th that led to the depletion of funds after various community users raised concerns. Tender.fi took to Twitter to acknowledge the issue and announced that they were investigating an unusually high amount of borrows, which led to the depletion of funds. As a result, the platform temporarily halted all borrowing activities until the investigation was complete.

The native token of Tender.fi (TND) plummeted over 30% in response to news of a suspected black hat hacking incident. The market reacted swiftly, with investors reacting to the news of the platform’s loss of funds.

Vulnerability Details

The attack on Tender.fi has exposed a critical flaw in the platform’s smart contract code, specifically its price oracle, which allowed the attacker to exploit the system and make off with $1.6 million worth of cryptocurrencies. The attacker was able to obtain tGMX tokens by purchasing them with initial funds and then proceeded to borrow using the tETH.borrow method. However, the borrowing process had an error in the price calculation, specifically in the GMXPriceOracle.getUnderlyingPrice method.

The initial price was multiplied by both 1e20 and 1e10, resulting in a significant increase in the price of tGMX tokens. This allowed the attacker to borrow large sums of money, which eventually led to the loss of millions of dollars in funds for Tender.fi.

Attacker’s address:

https://arbiscan.io/address/0x896DF3759205C141c97640B2B7345FA479FEB1aB

Transaction:

https://arbiscan.io/address/0x896DF3759205C141c97640B2B7345FA479FEB1aB

Transaction Details

Post-Mortem

Tenderfi has rewarded a bounty of 62 ETH, which is approximately 6% of the exploited funds, to the White Hat. This amount is consistent with the industry standard for rewarding white hats who find and report security vulnerabilities. The White Hat who discovered the exploit promptly notified the Tenderfi team, who then worked quickly to repay the exploited funds.

Following the transaction’s completion, Tender.fi took to Twitter to confirm that their funds were officially secure. The platform also announced that it would conduct a post-mortem analysis of the attack to identify areas of improvement and prevent similar incidents in the future. Their native token, TND has since bounced back slightly since the recovery of funds.

Conclusion

The swift and cooperative response from both the White Hat and the Tenderfi team is highly commendable. This type of collaboration between security researchers and blockchain companies is critical to creating a safer and more secure ecosystem.

Comments

All Comments

Recommended for you

  • Cross-border money laundering group laundered HK$88 million, 8 people arrested

    The Hong Kong Police Commercial Crime Bureau locked onto a cross-border money laundering group in November 2023. The investigation found that the group recruited mainlanders to open puppet bank accounts in Hong Kong from September 2023 to March 2024. They used various types of fraud, such as telephone scams, nude chat scams, investment scams, and job scams to defraud victims. The victims were instructed by the fraudsters to deposit the stolen money into the puppet accounts controlled by the criminal group. The group would then withdraw the stolen money from the puppet accounts in cash and buy cryptocurrencies on the over-the-counter (OTC) market. They would also open accounts on overseas cryptocurrency platforms with false identities and deposit the cryptocurrencies purchased with the stolen money before transferring them to multiple cryptocurrency wallets to launder the criminal proceeds. The police also pointed out that the group used 72 local puppet bank accounts to launder more than HKD 88 million in criminal proceeds, of which HKD 6.7 million was related to 48 fraud cases. As of yesterday, the police arrested 7 men and 1 woman aged between 26 and 51 for conspiring to launder black money. They claimed to be a lifeguard, photographer, telephone programmer, salesperson, and unemployed. Six of them were core members, and two were puppet account holders.

  • Sharp Alpha Advisors Raises $25M for Second Fund Targeting Early Stage Software Companies in Sports, Gaming, and Entertainment Industries

    New York-based venture capital firm Sharp Alpha Advisors has secured $25 million for its second fund, which will primarily invest in early stage software companies in the sports, gaming, and entertainment sectors. The fund aims to invest between $1 million and $2 million in 15 startups that fall under the category of "competitive entertainment," such as technology firms catering to sports betting, fantasy sports, streaming platforms, and video games. Sharp Alpha has already invested in London-based technology startup C15 Studio, which operates and distributes streaming channels for Formula 1 and One Championship, and plans to make further investments over the next three to five years. Additionally, the firm has a sidecar vehicle for limited partners to invest more money in individual companies within the fund.

  • Russian authorities plan to impose heavy fines on cryptocurrency miners operating in residential apartments

    Russian authorities have proposed imposing huge fines on cryptocurrency miners suspected of operating in residential properties. The authorities may also consider revising the Code of Administrative Offenses to hold those who abuse electricity accountable.

  • TheoriqAI Completes $6.2 Million Super-Seed Round of Financing, Led by Hack VC

    On May 14th, TheoriqAI, a modular AI agent infrastructure, announced on X platform that it has completed a $6.2 million Super-Seed round of financing. Hack VC led the investment, with participation from Foresight Ventures, HTX Ventures, Figment Capital, HASH CIB, Inception Capital, Antalpha Ventures, NewTribe Capital, Stateless Ventures, Bitscale Capital, Construct Ventures, Hypersphere, IOSG Ventures, LongHash Ventures, HashKey Capital, SNZ Holding, Chainlink.

  • Basel banking regulator delays crypto asset rules for banks until 2026

    The Basel Committee on Banking Supervision's governing body, the Group of Central Bank Governors and Heads of Supervision (GHOS), has delayed the compliance deadline for new rules on bank crypto assets by one year. The latest date for the project has been changed to January 1, 2026.

  • LayerZero CEO: Up to 100,000 addresses have been recognized as witches

    LayerZero CEO Bryan Pellegrino stated on social media that up to 100,000 addresses have been identified as witches. Previously reported on May 4th, LayerZero officials stated that all witch users were given a chance to self-report within the next 14 days and those who did would receive an expected distribution of 15%.

  • Niobium, a fully homomorphic encryption chip provider, completes $5.5 million seed round of financing, led by Fusion Fund

    Niobium, a custom encryption chip provider specializing in zero-trust computing, has announced the completion of a $5.5 million seed round of financing, led by Fusion Fund, with participation from Morgan Creek Capital, Rev1 Ventures, Ohio Innovation Fund, and Hale Capital. It is reported that Niobium is building a fully homomorphic encryption (FHE) accelerator chip and will commercialize it. The new funds will be used to explore the commercial applications of FHE in industries such as healthcare, finance, and blockchain, and also plan to showcase the solution and launch pilot projects in the fourth quarter of this year.

  • RunPod Completes $20 Million Seed Round of Financing, Led by Intel Capital and Others

    According to distributed GPU cloud computing AI training model project RunPod announced the completion of a $20 million seed round of financing, jointly led by Intel Capital and Dell Technologies Capital, with participation from Julien Chaummond, Nat Friedman, Adam Lewis and others. RunPod uses global distributed GPU cloud computing services to train, deploy, and scale AI models, thereby reducing the workload of developers. According to its official website, RunPad accepts cryptocurrency payments, but reminds users to strongly recommend setting up a crypto.com account as part of the risk management process and conducting any necessary KYC checks in advance.

  • Blockchain Asset Management announces launch of a dedicated blockchain fund for accredited investors

    Blockchain Asset Management, a cryptocurrency fund with a scale of $100 million, announced the launch of an exclusive blockchain fund for qualified investors. The specific amount of funds raised by the fund has not been disclosed yet, but it is said to have reached "eight figures", which means it is in the tens of millions of dollars. In addition, the investment threshold for the new fund is $100,000, and all investors are required to meet the approved standards (annual income exceeding $200,000, net assets exceeding $1 million).

  • Chainlink Digital Asset Insights: Q1 2024

    The Web3 ecosystem has recently seen a dramatic rise in activity through total value locked in decentralized finance (“DeFi”), volumes on decentralized exchanges (“DEXs”), and stablecoin activity (see the Appendix). Looking at the first quarter of the year, we examine prominent events in the space, including: