BTC $64,078.49 -1.01%
ETH $1,861.01 -0.93%
BNB $561.10 -0.95%
XRP $1.08 -1.64%
SOL $73.95 -2.32%
TRX $0.3302 +1.08%
DOGE $0.0689 -0.50%
ADA $0.1630 -3.68%
BCH $209.38 -0.03%
LINK $8.33 -1.53%
HYPE $58.27 -0.67%
AAVE $93.92 -1.65%
SUI $0.7117 -4.15%
XLM $0.1768 -2.86%
ZEC $493.51 -3.07%
BTC $64,078.49 -1.01%
ETH $1,861.01 -0.93%
BNB $561.10 -0.95%
XRP $1.08 -1.64%
SOL $73.95 -2.32%
TRX $0.3302 +1.08%
DOGE $0.0689 -0.50%
ADA $0.1630 -3.68%
BCH $209.38 -0.03%
LINK $8.33 -1.53%
HYPE $58.27 -0.67%
AAVE $93.92 -1.65%
SUI $0.7117 -4.15%
XLM $0.1768 -2.86%
ZEC $493.51 -3.07%

originate

All
Article
Flash

Axelar responds to security incident: Axelar and IBC are unaffected, the vulnerability originates from a third-party token contract's "infinite minting" issue

The cross-chain protocol Axelar Network released a statement regarding the recent security incident related to Secret Network, stating that there is a misunderstanding within the community about the event. Both Axelar and the Inter-Blockchain Communication Protocol (IBC) were not attacked or compromised. The affected token smart contracts were neither developed, deployed, nor maintained by Axelar, and Axelar's firewall mechanism also prevented the impact from spreading to other chains.It is reported that the exploited contract is a forked version based on CW20-ICS20, but the developers removed two core security checks, resulting in an "infinite minting" vulnerability. By deleting the verification mechanisms originally used to prevent such issues, this fork altered the original trust model of the contract and did not undergo a new security audit.Axelar Network explained that anyone can deploy contracts for cross-chain asset wrapping through IBC, and similar contracts have also been used to wrap tokens from other chains into Secret Network. However, the Secret side fork version in this incident has vulnerabilities due to the removal of key security checks. This incident is not a unique logical flaw, nor is it an issue with the IBC protocol itself, but rather a security risk introduced by modifications to third-party contracts.

Venus Protocol: THE market event originated from a supply cap vulnerability, not a flash loan attack

Venus Protocol released a statement regarding the THE market event, stating that this incident was not a flash loan attack, but rather a result of the attacker exploiting a supply cap vulnerability in the old code of the protocol. The team indicated that the attacker had been accumulating THE tokens for about 9 months, gradually establishing a dominant supply position on Venus.The announcement pointed out that the attacker bypassed the normal deposit process by directly transferring THE tokens into the protocol contract, thereby breaking through the supply cap limit of 14.5 million THE. They manipulated DEX prices by taking advantage of the low on-chain liquidity. As the external price was gradually reflected by the TWAP oracle, the attacker borrowed assets (such as CAKE, BNB, etc.) against the inflated collateral value, then bought more THE to drive up the price, and continuously transferred THE into the vTHE market to increase the collateral value. This cycle once pushed the price from about $0.27 to about $0.53, ultimately leaving bad debt in the protocol after the positions were liquidated.Venus stated that it has currently suspended the THE market, reduced its collateral factor to 0, and suspended withdrawals. Additionally, as a precautionary measure, the collateral factors for 8 markets including BCH, LTC, AAVE, POL, FIL, TWT, UNI, and lisUSD have also been reduced to 0. The team and security partners are continuing to investigate and will release a complete post-analysis report in the future.
app_icon
ChainCatcher Building the Web3 world with innovations.