Low | Medium | High | Critical | Total | |
---|---|---|---|---|---|
Not fixed | - | - | - | - | 0 |
Fixed | 8 | 5 | 1 | - | 14 |
Total | 8 | 5 | 1 | 0 | 14 |
Click to show description
Quick Summary An attacker exploited dYdX, Aave v2, Compound, and Curve in a complex flash loan attack, resulting in a significant manipulation of funds. Details of the Exploit The attacker initiated the exploit by flash loaning 116k ETH from dYdX and 99k ETH from Aave v2. They then borrowed 134M USDC and 129M DAI using the loaned ETH as collateral on Compound. The attacker added these funds to the 3crv Curve pool and withdrew 165M USDT. This process was repeated five times, each time depositing less DAI to the yDAI vault and withdrawing less DAI from it. In the final iteration, the attacker withdrew 39M DAI and 134M USDC instead of USDT. The attacker then repaid the debts on Compound and the flash loans on dYdX and Aave v2. Block Data Reference The attacker's transactions: https://etherscan.io/tx/0x59faab5a1911618064f1ffa1e4649d85c99cfd9f0d64dcebbc1af7d7630da98b https://etherscan.io/tx/0xf6022012b73770e7e2177129e648980a82aab555f9ac88b8a9cda3ec44b30779
# | Name | Auditor | Date | Chains | Issues |
---|---|---|---|---|---|
1 | yETH Governance | ChainSecurity | 2023/11/03 | Off-Chain (Private) | No active critical issues |
2 | ERC4626 Router | ChainSecurity | 2023/08/29 | Off-Chain (Private) | No active critical issues |
3 | yETH Periphery | ChainSecurity | 2023/08/29 | Off-Chain (Private) | No active critical issues |
4 | yETH | ChainSecurity | 2023/06/26 | Off-Chain (Private) | No active critical issues |
5 | yBAL | ChainSecurity | 2023/06/13 | Off-Chain (Private) | No active critical issues |
6 | Yearn Tokenized Strategy | ChainSecurity | 2023/05/04 | Off-Chain (Private) | No active critical issues |
7 | Yearn V3 Vaults | ChainSecurity | 2023/05/04 | Off-Chain (Private) | No active critical issues |
8 | oYfi | ChainSecurity | 2023/03/07 | Off-Chain (Private) | No active critical issues |
9 | yCRV and ZapYCRV | ChainSecurity | 2022/09/06 | Off-Chain (Private) | No active critical issues |
10 | Partner Tracker | ChainSecurity | 2022/01/18 | Off-Chain (Private) | No active critical issues |