Advertisement
AD

Main navigation

Solana-Based App Lost $50 Million Due to Fake Account Exploit, Here's How

Advertisement
Wed, 23/03/2022 - 12:25
A
A
A
Solana-Based App Lost $50 Million Due to Fake Account Exploit, Here's How
Cover image via stock.adobe.com
Read U.TODAY on
Google News
Advertisement

Solana-based decentralized app CashioApp has lost approximately $50 million in cryptocurrency because of an exploit that was previously noticed by blockchain experts on other Solana-based applications, as Paradigm's samczsun reports.

The researcher described in detail the method that allowed hackers to gain access to users.

Fake account exploit

For minting new CASH tokens, users deposit a certain amount of collateral that falls under the cross-program invocation that transfers tokens from the account to the protocol. The program also checks if two accounts have the same type of token on their balance; otherwise, the transfer gets rejected.

Samczsun showed his followers the exact way to validate assets that remain on the sender account. The "crate_collateral_tokens" function compares two accounts that should hold the same type of token.

Advertisement

But unfortunately, the functions of minting new tokens were never validated, which makes all steps described above meaningless since the primary function is not being validated by the process mentioned above.

Related

After the hacker noticed the issue in the contract code, he or she started creating a chain of fake accounts before finally making a fake account, crate_collateral_tokens. In a nutshell, because of a flaw in Cashio's code that did not establish a root of trust for all accounts used, the attacker was able to steal at least $50 million.

DeFi projects under attack

Recently, PeckShield blockchain security firm shared a number of warnings to protect owners and users based on Binance Smart Chain. Projects like OneRing and UmbNetwork were targeted by hackers that stole millions worth of assets from their balances. The estimated loss is approximately $1.8 million.

The most common reason behind almost every exploit is a flawed code in the smart contracts of the projects, including SafeMath issues.

Disclaimer: The opinions expressed by our writers are their own and do not represent the views of U.Today. The financial and market information provided on U.Today is intended for informational purposes only. U.Today is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.

A
A
A

Related articles

Advertisement
TopCryptoNewsinYourMailboxSubscribe
TopCryptoNewsinYourMailboxSubscribe
Advertisement
Advertisement
Subscribe to daily newsletter

Recommended articles

Latest Press Releases

Our social media
There's a lot to see there, too

Popular articles

Advertisement
AD