Cointime

Download App
iOS & Android

SharkTeam: Analysis of the Midas Capital Attack Incident

On June 18, 2023, Beijing time, Midas Capital was targeted in an attack, and the attackers have profited approximately $600,000.

SharkTeam conducted an immediate technical analysis of this incident and summarized security measures. We hope that future projects can learn from this and strengthen the security defenses in the blockchain industry.

1. Incident analysis

Attacker address: 0x4b92cc3452ef1e37528470495b86d3f976470734

Attack contract: 0xc40119c7269a5fa813d878bf83d14e3462fc8fde

Attacked contract: 0xF8527Dc5611B589CbB365aCACaac0d1DC70b25cB

Attack transactions: 0x1ebc03f0f2257c275f4990b4130e6c3e451125aa98ee8bbde8aba5dc0320c659

Attack Process:

(1) The attacker (0x4b92cc34) invokes the function 0x117741f7 of the attack contract (0xc40119c7), and first calls the mint function of the targeted contract (0xF8527Dc5) to convert 518,614,966,827,953,435,094 sAMM-HAY/BUSD tokens into 2 fsAMM-HAY-BUSD tokens, which are the collateral tokens.

Select an Image

(2) Subsequently, the attacker calls the redeemUnderlying function of the targeted contract (0xF8527Dc5) to extract 518,614,966,827,953,435,091 sAMM tokens. However, instead of extracting all of them, they leave 3 tokens behind. It's important to note that at this point, only 1 fsAMM token has been transferred out of the attack contract.

Select an Image

(3) Then, the attacker calls the redeemUnderlying function of the targeted contract (0xF8527Dc5) again, extracting an additional 518,096,869,957,995,439,653 sAMM tokens. Since there is still 1 fsAMM token remaining in the attack contract (0xc40119c7) account, the extraction is successful.

Select an Image

(4) The above operations are repeated in a loop, and as the arbitrage process progresses, the quantity of minted tokens doubles, and the number of calls to the redeemUnderlying function also doubles.

Select an Image

(5) After multiple rounds of attack transactions, the obtained sAMM tokens are ultimately exchanged for profits by exiting with BUSD, HAY, ANKR, WBNB, ankrBNB, and other assets.

Select an Image

2. Vulnerability Analysis

Since the logic contract of the targeted contract (0xF8527Dc5) is currently not open-source, we can only rely on traces and previous logic contracts to find clues. We found that the code forked Compound's code and shares similarities with Hundred Finance, introducing a third-party math library.

Select an Image

In the divUInt function, the division operation a/b is used, which is fine in terms of calculation. However, due to Solidity's lack of support for floating-point arithmetic, the result is rounded down. The attacker (0x4b92cc34) strictly controls the input quantity every time they call the redeemUnderlying function. This leads to a situation where the calculated result becomes 1.99999999999... but is rounded down to 1 by default.

In the third step, the attack contract (0xc40119c7) retrieves slightly fewer sAMM tokens. As a result, the calculated result becomes 1. Consequently, each time the attacker (0x4b92cc34) stakes and extracts the principal, it doubles.

3. Security Recommendations

The root cause of this incident was the integration of a math library in the targeted contract (0xF8527Dc5), where the redeemUnderlying function rounds down the quantity of fsAMM tokens that the attacker (0x4b92cc34) needs to transfer. This resulted in the attacker (0x4b92cc34) halving the cost they would otherwise have to pay and enabling them to repeatedly exploit the arbitrage opportunity.

To prevent similar attacks, it is essential to follow the following considerations during the development process:

(1) Solidity does not support floating-point arithmetic. When implementing integer operations, it is recommended to perform multiplication before division or use appropriate precision mechanisms.

(2) Before deploying a project, seek technical assistance from professional third-party audit teams to conduct a thorough security review.

About us

SharkTeam’s vision is to comprehensively protect the security of the Web3 world. The team is composed of experienced security professionals and senior researchers from all over the world. They are proficient in the underlying theory of blockchain and smart contracts, and provide services including smart contract auditing, on-chain analysis, and emergency response. It has established long-term cooperative relationships with key players in various fields of the blockchain ecosystem, such as Polkadot, Moonbeam, polygon, OKC, Huobi Global, imToken, ChainIDE, etc.Official website: https://www.sharkteam.org/Twitter: https://twitter.com/sharkteamorgDiscord: https://discord.gg/jGH9xXCjDZTelegram: https://t.me/sharkteamorg

Comments

All Comments

Recommended for you

  • Tether CEO posts job openings, sparking speculation that a mobile encrypted wallet is on the horizon.

    Tether CEO Paolo Ardoino posted on the X platform stating that Tether has started recruiting a senior software engineer who will be responsible for Tether's mobile crypto wallet-related products, which will be supported by artificial intelligence, Wallet Development Kit (WDK), and QVAC technology. Later, Paolo Ardoino also posted a suspected wallet product screenshot in another tweet, which shows "Own your Money".

  • Bloomberg analysts: Among the top 25 US equity ETFs with the highest annual inflows, BlackRock IBIT is the only ETF with negative returns.

    Eric Balchunas, a senior ETF analyst at Bloomberg, posted the annual top 25 U.S. stock ETFs by fund inflows on the X platform. Among them, BlackRock's Bitcoin exchange-traded fund IBIT is the only ETF with a negative return, with an annual return rate of -9.59%. It is worth noting that despite the negative return, IBIT's annual fund inflow still ranks sixth, even surpassing the GLD ETF with a 64% return. In the long run, this is a very good sign, as it received over $25 billion in fund inflows during the bear market phase, indicating greater potential once the market turns bullish.

  • Hassett's chances of becoming the next Federal Reserve Chairman have once again surged significantly.

    Golden Finance reports that the increased, rising to 54% on Polymarket and 51% on Kalshi, with the probabilities of Walsh and Waller being nominated by Trump ranking second and third respectively.

  • China Merchants Bank: The yen carry trade may undergo a sustained reversal, exerting long-term downward pressure on global asset liquidity.

    China Merchants Bank released a research report stating that on December 19, the Bank of Japan raised interest rates by 25 basis points, raising the policy rate to 0.75%. Although the Bank of Japan is highly likely to remain very cautious in its pace of rate hikes, the reversal of yen liquidity and the Japanese bond market will continue to suppress global financial conditions.

  • A new address withdrew $2.5 million worth of LINK from Binance.

    according to on-chain analyst Ai Yi's monitoring, the new address "0xf44…b1CC43" withdrew 199,517 LINK from Binance hours ago, worth 2.5 million USD.

  • ETH breaks $3,000

     the market shows ETH breaking through $3000, currently at $3002.51, with a 24-hour increase of 2.19%. The market is highly volatile, please manage your risk accordingly.

  • BTC breaks through $89,000

    the market shows BTC breaking through $89,000, currently at $89,017.66, with a 24-hour increase of 1.03%. The market is highly volatile, please manage your risk accordingly.

  • BTC breaks through $88,500

     the market shows BTC breaking through $88,500, currently at $88,549.08, with a 24-hour increase of 0.69%. The market is highly volatile, please manage your risks accordingly.

  • Nasdaq-listed Mangoceuticals plans to launch a $100 million SOL digital asset treasury.

     Nasdaq-listed company Mangoceuticals announced it will cooperate with Cube Group to establish a subsidiary, Mango DAT, to advance the strategy of building a $100 million SOL digital asset treasury (DAT). The related funds will be raised through an ATM financing plan and the sale of common stock. It is reported that the company has also submitted a "MULTI-DAT" trademark application to the United States Patent and Trademark Office to promote a series of strategic digital asset and DeFi plans.

  • BTC breaks through $88,000

    the market shows BTC breaking through $88,000, currently at $88,016.61, with a 24-hour increase of 1.59%. The market is highly volatile, please manage your risk accordingly.