Cointime

Download App
iOS & Android

Web3 Infrastructure Platform Ankr Suffers $5M Exploit, Let’s Take a Closer Look

Validated Project

TL;DR

On December 02, 2022, the Ankr protocol on BNB chain suffered a governance key compromise, allowing an attacker to mint 10,000,000,000,000 $aBNBc tokens and drain the DEX pool, resulting in the loss of approximately $5 million.

Introduction to Ankr

Ankr is a decentralized Web3 infrastructure provider that helps developers, decentralized applications, and stakers interact easily with an array of blockchains.

Vulnerability Assessment

The root cause of the vulnerability is due to the compromise of their governance key.

Steps

  • The team had announced changes to all Reward Bearing and Earning Tokens token models prior to the incident.
  • The $aBNBc token is an upgradeable token contract, which means that the admin can change the code at any time.
  • The exploiter stole the key of Ankr Deployer and minted himself 10T $aBNBc tokens as viewed from this transaction.
  • The preparator transferred 1.125 $BNB tokens to Ankr Exploiter address as a gas fee by controlling the key of Ankr Deployer, and then began to dump $aBNBc.
  • The attacker also sent between $3 and $4 million involving multiple transactions to the ETH mainnet through the Celer bridge.
  • Additionally, the exploiter used PancakeSwap to exchange $aBNBc tokens for $BNB and $USDC before converting them to $ETH.
  • The $aBNBc-related pool on PancakeSwap has been depleted, and the exploiter has consequently ceased dumping aBNBc.

Aftermath

After the incident, the team issued a statement on Twitter mentioning that they were currently working with exchanges to immediately halt trading. The price of the $ANKR token plummeted and was last observed trading at $0.02168.

In addition, they stated that all the underlying assets on Ankr Staking were safe at this time, and all infrastructure services are unaffected. The team will be drafting a plan to compensating affected users.

How to prevent such an attack vector

The exploiter deployed an attack contract, changed the upgradeable aBNBc contract to the malicious implementation and then minted a massive amount of tokens for his wallet.

This can either be caused due to the compromise of the Deployer key during their migrations, or it could also potentially be an insider job where the attack was planned to coincide with the event.

Multisignature wallets and pause contract events are also industry standard for majority of blockchain team to mitigate against events of such nature to a greater extent.

Protocol, and Platform Security

Our security team at Neptune Mutual can validate your platform for DNS and web-based security, smart contract reviews, as well as frontend and backend security. We can offer you a solution to scan your platform and safeguard your protocol for known and unknown vulnerabilities that have the potential to have catastrophic long-term effects. Contact us on social media if you are serious about security and have the budget, desire, and feeling of responsibility to do so.

Comments

All Comments

Recommended for you

  • Brent Crude Oil Futures Rise to $126.09 per Barrel, Highest Since March 2022

    On April 30, according to Reuters quotes, Brent crude oil futures rose by more than $8 during the day to $126.09 per barrel, marking the highest level since March 2022. (Jinshi)

  • US Military Plans First Operational Deployment of Hypersonic Missiles Against Iran

    On April 30, Bloomberg reported that the US Central Command has submitted a request to deploy the 'Dark Eagle' hypersonic missiles to the Middle East. If approved, this would mark the first operational deployment of hypersonic missiles by the US, potentially aimed at striking ballistic missile launch systems deep within Iran.

  • US Treasury Secretary: America Seizes $450 Million in Iranian Crypto Assets

    On April 30, The Kobeissi Letter reported that US Treasury Secretary Scott Bessent stated that the United States has seized $450 million worth of Iranian crypto assets.

  • KKR Explores $10 Billion Sale of Flora Food Group

    On April 30, according to the Financial Times, private equity firm KKR is exploring a $10 billion sale of Flora Food Group.

  • U.S. Treasury Secretary: Kevin Warsh Will Bring a New Era to the Federal Reserve

    On April 30, Cointelegraph reported that U.S. Treasury Secretary Scott Basset stated, "Kevin Warsh will usher in a new chapter for the Federal Reserve, leading with accountability mechanisms, efficient governance, and sound policy-making at its core."

  • US Spot Bitcoin ETF Sees Net Outflow of $137.75 Million

    On April 30, according to monitoring by Trader T, the US spot Bitcoin ETF experienced a net outflow of $137.75 million yesterday.

  • US Spot Ethereum ETF Sees $87.72 Million Net Outflow

    On April 30, according to monitoring by Trader T, the US spot Ethereum ETF experienced a net outflow of $87.72 million yesterday.

  • Trump to Receive Briefing on New Military Plans Against Iran Including Strong Strikes and Control of Hormuz Strait

    On April 30, two informed sources stated that Trump plans to receive a briefing on Thursday from General Brad Cooper, the commander of U.S. Central Command, regarding new plans for potential military action against Iran. This briefing indicates that Trump is seriously considering the resumption of large-scale military operations to break the negotiation deadlock or deliver a decisive blow before ending the war. Three sources revealed that Central Command has prepared a plan for a 'short and powerful' strike against Iran, which may include targeting infrastructure. The expectation is that Iran would then show greater flexibility on nuclear issues and return to the negotiating table. Another plan expected to be presented to Trump involves controlling parts of the Strait of Hormuz to restore commercial shipping passage. One source indicated that such actions could involve ground troops. Another option that has been discussed in the past and may be presented in the briefing is to conduct special operations to ensure control over Iran's highly enriched uranium reserves. Cooper had previously briefed Trump on similar matters on February 26, and two days later, the U.S. and Israel launched a war against Iran. A person close to Trump stated that that briefing led to Trump's decision to go to war.

  • BTC Surpasses $76,000

    Market data shows that BTC has surpassed $76,000, currently priced at $76,008.59, with a 24-hour decline of 0.38%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.