Technology Today

The Chinese decentralized finance (DeFi) protocol dForce has fallen victim to a well-known exploit of an Ethereum token which led to $25m worth of its customers' cryptocurrency being stolen.As reported by Decrypt, DForce recently announced that it had secured $1.5m in a seed funding round led by the crypto venture capital fund Multicoin Capital.
However, those funds were drained from the contracts of a lending protocol that is part of dForce called Lendf.Me.Lendf.Me is now offline and all of its smart contracts have been paused.
However, the hackers did return $126.014 of the stolen funds back to the lending platform with a note, which read Better luck next time.A similar attack was recently launched against the decentralized exchange Uniswap to steal over $300,000.
The exchange's smart contracts containing an Ethereum-based, tokenized version of Bitcoin run by TokenIon called imBTC were drained.
The connection between the two attacks deals with the fact that Lendf.ME integrated imBTC earlier this year.The Uniswap attack leveraged a known vulnerability in the ERC77 token standard.
As a result of the way Uniswap smart contracts are set up, a hacker could continually withdraw ERC77 funds from Uniswap before the balance updated which could allow them to drain the contracts of imBTC.While the dForce hack is entire separate from the Uniswap hack, it is believed that the same exploit was used in both attacks.
The vulnerability is not new and the firm ConsenSys conducted an extensive audit of Uniswap 16 months ago, concluding that it was a major issue.To make matters worse, the CEO of Compound, Robert Leshner claims that Lendf.Me had appropriated its open source code.
In a tweet, Leshner called out Lendf.Me's security, saying: If a project doesn't have the expertise to develop its own smart contracts, and instead steals and redeploys somebody else's copyrighted code, it's a sign that they don't have the capacity or intention to consider security.As of now, dForce has not discussed the hack on its social media channels and it looks like the rest of the stolen funds won't be returned anytime soon.Via Decrypt





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Apple fans rushing for £35 iPhone 16 Pro Max as Sky offers payday deal


'I visited Chinese city which is like sci-fi movie with robots and noiseless trains'


Top Tech: Amazon's best early Prime Day deals including Ring, Tefal and Nespresso


Brits now 'obsessed' with health tracking and say it's key to motivation


Virgin Media is distributing complimentary wise TVs in surprise seven-day sale


O2 confirms UK network switch off and the exact date your phone might quit working


Samsung and Google have a new Android competitor that's like Nothing you've seen before


'Spectacular' Samsung Galaxy S25 Ultra gets £10 a month price cut


Sky users given 48-hour cost alert and your costs could increase tomorrow


Never ever miss your favourite television series when on vacation with basic travel hack


Amazon may offer big reason to ditch your Fire TV Stick next week and try something new


Samsung and Google smartphone deals consist of free earbuds and smartwatches


Everyone using Google Chrome must restart their browser now - don't ignore new alert


iPhone users surprised after finding 'concealed' hack to organise home screen


Sky dishes out brand-new iPhone 16 at 'lowest ever' rate, not surprising that it's offering fast


Argos shoppers can get a free 40-inch Hisense TV by doing one thing


Immediate alert for everyone with a Gmail account - do not overlook 6 important brand-new rules


BBC iPlayer is rivalling Sky TV with a vital free upgrade - check your settings now