👀 家人們,每天看行情、刷大佬觀點,卻從來不開口說兩句?你的觀點可能比你想的更有價值!
廣場新人 & 回歸福利正式上線!不管你是第一次發帖還是久違回歸,我們都直接送你獎勵!🎁
每月 $20,000 獎金等你來領!
📅 活動時間: 長期有效(月底結算)
💎 參與方式:
用戶需爲首次發帖的新用戶或一個月未發帖的回歸用戶。
發帖時必須帶上話題標籤: #我在广场发首帖 。
內容不限:幣圈新聞、行情分析、曬單吐槽、幣種推薦皆可。
💰 獎勵機制:
必得獎:發帖體驗券
每位有效發帖用戶都可獲得 $50 倉位體驗券。(注:每月獎池上限 $20,000,先到先得!如果大家太熱情,我們會繼續加碼!)
進階獎:發帖雙王爭霸
月度發帖王: 當月發帖數量最多的用戶,額外獎勵 50U。
月度互動王: 當月帖子互動量(點讚+評論+轉發+分享)最高的用戶,額外獎勵 50U。
📝 發帖要求:
帖子字數需 大於30字,拒絕純表情或無意義字符。
內容需積極健康,符合社區規範,嚴禁廣告引流及違規內容。
💡 你的觀點可能會啓發無數人,你的第一次分享也許就是成爲“廣場大V”的起點,現在就開始廣場創作之旅吧!
DeFi Protocol Sturdy Finance Exploited for 442 ETH Worth Almost $800K
Sturdy Finance – a DeFi project promising up to 10x leverage on staked assets – has been exploited by a hit-and-run attack on its pricing oracle.
Although the amount stolen (worth about $800k at the time this article was written) pales in comparison to other, more high-profile attacks like the one on Atomic Wallet users just last week, it also ensures that laundering the profits will not be nearly as hard as it is for cybercriminals who have made off with much bigger takings.
Price Manipulation
The attack on Sturdy Finance was carried out via reentrancy exploit, a common method of attacking DeFi projects that entails repeatedly calling a function in a smart contract before the original call is completed.
In order to attack Sturdy Finance, the hacker first established the vulnerability of the protocol’s price oracle – the part of Sturdy’s eco that determines the current value of assets to be used in trading and loans – to reentrancy exploits. Once the vulnerability was established, a flashloan from AAVE provided the liquidity necessary for the attack.
This allows the bad actor to withdraw more funds than the smart contract should allow them to. In this case, the price of staked Ether (stETH) was manipulated three times in a row in order to enable the bad actor to withdraw more than the loan should allow them to, pay off the original loan, and cash out the extra funds. This process was then repeated on five occasions, each time using a different smart contract.
The exploit resulted in a loss of 442 ETH for Sturdy, a takeaway already on its way to Tornado Cash.
Post-Mortem in Progress
The security team at Sturdy confirmed that the exploit has been noted, and their operations have been paused for the moment to conduct a proper post-mortem. The team also asserted that no other funds are currently at risk of being stolen.
Sturdy’s community is understandably upset at the news, with some users proclaiming disbelief that attacks typical of the 2017 shitcoin boom era are still happening today.