• News
    • Bitcoin
    • Altcoins
    • DeFI
    • Blockchain
  • NFT
  • Metaverse
  • Analysis
  • Regulation
  • Learn
  • Market Cap
  • Shop
What's Hot

Algorand price surges over 12%

2023-03-30

Elizabeth Warren says she’s building an anti-crypto army in new campaign

2023-03-30

Billionaire Mike Novogratz Predicts ‘Substantially Higher’ Bitcoin and Crypto Prices Amid Banking Woes – Here’s His Timeline

2023-03-30
Facebook Twitter Instagram
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
Facebook Twitter Instagram
capitalcryptoacademy
  • News
    • Bitcoin
    • Altcoins
    • DeFI
    • Blockchain
  • NFT

    DAOs and NFT Projects That Incentivize Getting Active

    2023-03-29

    Runway Special Edition: Welcome to Metaverse Fashion Week

    2023-03-29

    Web3 creators at higher a loss for royalties than anticipated: data

    2023-03-29

    UK NFT Dropped Over Lack of Demand, Finance Minister Hunt Says

    2023-03-29

    NFT Inspect makes comeback after January shutdown with acquisition by JVH Technology

    2023-03-29
  • Metaverse

    Disney Metaverse Division Reportedly Scrapped

    2023-03-28

    Animoca Denies $200M Metaverse Fund Cut

    2023-03-27

    Metaverse Trading Hits All-Time High

    2023-03-24

    Exploring the Metaverse: A Guide to Investing in Metaverse Stocks

    2023-03-20

    A Guide to Virtual Land Staking in the Metaverse

    2023-03-20
  • Analysis

    Algorand price surges over 12%

    2023-03-30

    Billionaire Mike Novogratz Predicts ‘Substantially Higher’ Bitcoin and Crypto Prices Amid Banking Woes – Here’s His Timeline

    2023-03-30

    Quant Trading Firm Accumulates Nearly $800,000,000 Worth of USDC and Ethereum in One Month: On-Chain Data

    2023-03-30

    Crypto Whales Abruptly Move Over $186,000,000 in Ethereum Rival Solana – Here’s Where the Crypto Is Going

    2023-03-29

    Top Trader Says Shiba Inu (SHIB), Dogecoin (DOGE) and One Additional Memecoin Will Run Hard on Next Bitcoin Bounce

    2023-03-29
  • Regulation

    Elizabeth Warren says she’s building an anti-crypto army in new campaign

    2023-03-30

    SEC Chair Gary Gensler To Face Congress Over Strategy on Digital Assets

    2023-03-30

    Texas bill seeks to eliminate incentives for Bitcoin miners

    2023-03-30

    Biden Administration’s Crypto Actions Will Have Election Consequences, According to ARK Invest’s Cathie Wood

    2023-03-29

    SEC’s Gary Gensler seeks for more staff, resources to regulate crypto

    2023-03-29
  • Learn

    In Search of Legal Personality & Limited Liability

    2023-03-23

    Are There Any Free Play-to-Earn Crypto Games?

    2023-03-16

    What are the biggest Web3 crypto projects?

    2023-03-09

    Best Ways to Get Free NFTs

    2023-03-02

    What are Examples of Web3? The Future of the Internet

    2023-02-24
  • Market Cap
  • Shop
capitalcryptoacademy
Home»DeFI»Raydium announces details of hack, proposes compensation for victims
DeFI

Raydium announces details of hack, proposes compensation for victims

2022-12-21No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

The crew behind the Raydium decentralized alternate (DEX) has introduced particulars as to how the hack of Dec. 16 occurred and supplied a proposal to compensate victims.

In response to an official discussion board put up from the crew, the hacker was capable of make off with over $2 million in crypto loot by exploiting a vulnerability within the DEX’s good contracts that allowed complete liquidity swimming pools to be withdrawn by admins, regardless of current protections being to forestall such habits. 

The crew will use its personal unlocked tokens to compensate victims who misplaced Raydium tokens, often known as RAY. Nonetheless, the developer doesn’t have the stablecoin and different non-RAY tokens to compensate victims, so it’s asking for a vote from RAY holders to make use of the decentralized autonomous group (DAO) treasury to purchase the lacking tokens to repay these affected by the exploit.

1/ Replace on remediation of funds for latest exploit

First, thanks for everybody’s persistence to this point

An preliminary proposal on a manner ahead has been posted for dialogue. Raydium encourages and appreciates all suggestions on the proposal.https://t.co/NwV43gEuI9

— Raydium (@RaydiumProtocol) December 21, 2022

In response to a separate autopsy report, the attacker’s first step within the exploit was to gain management of an admin pool personal key. The crew doesn’t know the way this key was obtained, however it suspects that the digital machine that held the important thing turned contaminated with a trojan program.

As soon as the attacker had the important thing, they known as a operate to withdraw transaction charges that might usually go to the DAO’s treasury for use for buybacks of RAY. On Raydium, transaction charges don’t mechanically go to the treasury in the mean time of a swap. As an alternative, they continue to be within the liquidity supplier’s pool till withdrawn by an admin. Nonetheless, the good contract retains observe of the quantity of charges owed to the DAO by parameters. This could have prevented the attacker from having the ability to withdraw greater than 0.03% of the overall buying and selling quantity that had occurred in every pool for the reason that final withdrawal.

However, due to a flaw within the contract, the attacker was capable of manually change the parameters, making it seem that your complete liquidity pool was transaction charges that had been collected. This allowed the attacker to withdraw all the funds. As soon as the funds have been withdrawn, the attacker was capable of manually swap them for different tokens and switch the proceeds to different wallets beneath the attacker’s management.

Associated: Developer says initiatives are refusing to pay bounties to white hat hackers

In response to the exploit, the crew has upgraded the app’s good contracts to take away admin management over the parameters that have been exploited by the attacker.

Within the Dec. 21 discussion board put up, the builders proposed a plan to compensate victims of the assault. The crew will use its personal unlocked RAY tokens to compensate RAY holders who misplaced their tokens as a result of assault. It has requested for a discussion board dialogue on how one can implement a compensation plan utilizing the DAO’s treasury to buy non-RAY tokens which were misplaced. The crew is asking for a three-day dialogue to happen to determine the problem.

The $2 million Raydium hack was first found on Dec. 16. Preliminary stories mentioned that the attacker had used the withdraw_pnl operate to take away liquidity from swimming pools with out depositing LP tokens. However since this operate ought to have solely allowed the attacker to take away transaction charges, the precise methodology by which they may drain complete swimming pools was not recognized till after an investigation had been performed.

Source link

Announces compensation Details Hack Proposes Raydium victims
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

OKB Chain by OKX Goes Live in Testnet: Details

2023-03-28

Problems galore for DeFi ecosystem as another protocol gets compromised

2023-03-27

AAVE outperforms LDO as DeFi TVL reaches YTD high, more inside

2023-03-25

Metaverse Project Proposes On-chain Reputation Scores for NFT Projects

2023-03-24
Add A Comment

Leave A Reply Cancel Reply

Top Posts

Top Crypto Influencers To Follow on Twitter for Beginners and Experts 

2022-08-01

Crypto.com continues its worldwide registration push with Brazilian EMI license

2022-12-16

Dogecoin Holders Increased By 100K In Just Three Months

2022-10-23

Subscribe to Updates

Get the latest news and Update from Capital Crypto Academy about Crypto, Metaverse and NFT.

About
About

Capital Crypto Academy is a platform with most important news, articles and other content about cryptocurrencies and blockchain today. We deliver up-to-date, breaking crypto news about the latest Bitcoin, Ethereum, Blockchain, NFTs, and Alt-coin trends and Regulations .

Facebook Twitter Instagram Pinterest YouTube
Top Insights

Algorand price surges over 12%

2023-03-30

Elizabeth Warren says she’s building an anti-crypto army in new campaign

2023-03-30

Billionaire Mike Novogratz Predicts ‘Substantially Higher’ Bitcoin and Crypto Prices Amid Banking Woes – Here’s His Timeline

2023-03-30
Get Informed

Subscribe to Updates

Get the latest news and Update from Capital Crypto Academy about Crypto, Metaverse and NFT.

  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
© 2023 capitalcryptoacademy.com - Al rights reserved

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$20,113.003.45%
  • ethereumEthereum(ETH)$1,351.592.35%
  • tetherTether(USDT)$1.00-0.29%
  • binancecoinBNB(BNB)$295.582.60%
  • usd-coinUSD Coin(USDC)$1.00-0.02%
  • rippleXRP(XRP)$0.4784555.24%
  • binance-usdBinance USD(BUSD)$1.00-1.17%
  • cardanoCardano(ADA)$0.4337331.85%
  • solanaSolana(SOL)$34.233.63%
  • dogecoinDogecoin(DOGE)$0.0608981.18%
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage vendors Read more about these purposes
View preferences
{title} {title} {title}