Cointime

Download App
iOS & Android

Web3 Infrastructure Platform Ankr Suffers $5M Exploit, Let’s Take a Closer Look

Validated Project

TL;DR

On December 02, 2022, the Ankr protocol on BNB chain suffered a governance key compromise, allowing an attacker to mint 10,000,000,000,000 $aBNBc tokens and drain the DEX pool, resulting in the loss of approximately $5 million.

Introduction to Ankr

Ankr is a decentralized Web3 infrastructure provider that helps developers, decentralized applications, and stakers interact easily with an array of blockchains.

Vulnerability Assessment

The root cause of the vulnerability is due to the compromise of their governance key.

Steps

  • The team had announced changes to all Reward Bearing and Earning Tokens token models prior to the incident.
  • The $aBNBc token is an upgradeable token contract, which means that the admin can change the code at any time.
  • The exploiter stole the key of Ankr Deployer and minted himself 10T $aBNBc tokens as viewed from this transaction.
  • The preparator transferred 1.125 $BNB tokens to Ankr Exploiter address as a gas fee by controlling the key of Ankr Deployer, and then began to dump $aBNBc.
  • The attacker also sent between $3 and $4 million involving multiple transactions to the ETH mainnet through the Celer bridge.
  • Additionally, the exploiter used PancakeSwap to exchange $aBNBc tokens for $BNB and $USDC before converting them to $ETH.
  • The $aBNBc-related pool on PancakeSwap has been depleted, and the exploiter has consequently ceased dumping aBNBc.

Aftermath

After the incident, the team issued a statement on Twitter mentioning that they were currently working with exchanges to immediately halt trading. The price of the $ANKR token plummeted and was last observed trading at $0.02168.

In addition, they stated that all the underlying assets on Ankr Staking were safe at this time, and all infrastructure services are unaffected. The team will be drafting a plan to compensating affected users.

How to prevent such an attack vector

The exploiter deployed an attack contract, changed the upgradeable aBNBc contract to the malicious implementation and then minted a massive amount of tokens for his wallet.

This can either be caused due to the compromise of the Deployer key during their migrations, or it could also potentially be an insider job where the attack was planned to coincide with the event.

Multisignature wallets and pause contract events are also industry standard for majority of blockchain team to mitigate against events of such nature to a greater extent.

Protocol, and Platform Security

Our security team at Neptune Mutual can validate your platform for DNS and web-based security, smart contract reviews, as well as frontend and backend security. We can offer you a solution to scan your platform and safeguard your protocol for known and unknown vulnerabilities that have the potential to have catastrophic long-term effects. Contact us on social media if you are serious about security and have the budget, desire, and feeling of responsibility to do so.

Comments

All Comments

Recommended for you

  • ETH breaks through $3100

    the market shows ETH breaking through $3100, currently at $3100.29, with a 24-hour increase of 1.74%. The market is highly volatile, please manage your risks accordingly.

  • BTC breaks through $91,000

     the market shows BTC breaking through $91,000, currently at $91,011.99, with a 24-hour increase of 1.78%. The market is highly volatile, please manage your risk accordingly.

  • BTC breaks $90,000

    market shows BTC breaking through $90,000, currently at $90,009.99, the 24-hour decline narrowed to 0.57%, market volatility is high, please manage your risk properly.

  • The US spot Bitcoin ETF saw a net inflow of $54.8 million yesterday.

    according to data monitored by Farside Investors, the US spot Bitcoin ETF had a net inflow of 54.8 million USD yesterday.

  • The US spot Ethereum ETF saw a net outflow of $75.2 million yesterday.

     according to data monitored by Farside Investors, the US spot Ethereum ETF had a net outflow of 75.2 million USD yesterday.

  • Economists expect the Federal Reserve to cut interest rates in December, with two more cuts possible in 2026.

    according to economists surveyed, Federal Reserve officials are expected to vote next week to cut interest rates again to guard against the rising risk of a sharp deterioration in the labor market. The median of respondents shows that the Fed is expected to implement two more 25 basis point rate cuts within the year starting from March 2026. Next week's rate cut will continue the momentum of rate cuts from the policy meetings in September and October. A considerable majority also expect Fed officials to once again reiterate the statement that "the downside risks to employment have increased in recent months," as they did in October. The Federal Reserve will announce its decision at 2 PM Washington time on December 10, followed by a press conference held by Chairman Jerome Powell.

  • Bank of America: Markets will soon digest expectations of a Fed rate cut in January.

    Bank of America stated the market may soon price in the Federal Reserve's rate cut expectation in January. (Jin10)

  • He Lifeng held a video call with U.S. Treasury Secretary Bessant and Trade Representative Greer.

    He Lifeng, China's lead for China-US economic and trade relations and Vice Premier of the State Council, held a video call with the US leads, Treasury Secretary Janet Yellen and Trade Representative Katherine Tai. The two sides had in-depth and constructive exchanges on implementing the important consensus reached by the Chinese and US heads of state at the Busan meeting and the November 24 call, focusing on carrying out pragmatic cooperation and properly addressing mutual concerns in the economic and trade field. Both sides positively evaluated the implementation of the outcomes of the China-US economic and trade consultations in Kuala Lumpur, stating that under the strategic guidance of the two heads of state, they will continue to make good use of the China-US economic and trade consultation mechanism, continuously extend the cooperation list, reduce the list of issues, and promote the sustained, stable, and positive development of China-US economic and trade relations. 

  • Hassett: No discussion with US President Trump regarding the Federal Reserve Chair (selection)

    Director of the White House National Economic Council, Hassett, stated: He has not discussed the Federal Reserve Chair (candidate) issue with U.S. President Trump and supports Bassett's views on the Federal Reserve Chair. 

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.