Close Menu
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Metaverse
  • Defi
  • Blockchain
  • Regulations
  • Trading

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

UK Gold Miner Bluebird Pioneers Bitcoin Reserve Move

June 6, 2025

Crypto Is ‘The Future,’ House Financial Services Oversight Subcommittee Chair Says

June 5, 2025

BREAKING: Uber Explores Global Stablecoin Transfers as CEO Hails Bitcoin ‘Proven’ Store of Value

June 5, 2025
Facebook X (Twitter) Instagram
CredBit.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Metaverse
  • Defi
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
CredBit.com
Home » DeFi Protocol Dough Finance Exploit Swipes $1.96 Million
Defi

DeFi Protocol Dough Finance Exploit Swipes $1.96 Million

July 13, 20243 Mins Read
Facebook Twitter WhatsApp Pinterest Telegram LinkedIn Tumblr Email Reddit VKontakte
DeFi Protocol Dough Finance Exploit Swipes .96 Million
Share
Facebook Twitter LinkedIn Pinterest Telegram Email

Another DeFi protocol fell victim to an exploit on Friday morning. Dough Finance, an open-source protocol to create non-custodial liquidity markets, suffered a flash loan attack that took nearly $2 million in user funds. The project’s team announced they are working to resolve the situation promptly.

Dough Finance Protocol Loses $1.96 Million

On July 12, online reports concerning activity from Dough Finance were called out. Web3 blockchain security platform Cyvers informed us that it had detected multiple suspicious transactions involving the DeFi protocol.

Per the report, the hacker manipulated Dough Finance’s smart contract and stole $1.8 million in USDC. The attacker, funded through the zero-knowledge (ZK) protocol Railgun, swapped the misappropriated funds to Ethereum (ETH), initially obtaining 608 ETH.

Olympix, a Web3 security provider, revealed that the exploit occurred due to “calldata within the ConnectorDeleverageParaswap contract.” Seemingly, the contract didn’t properly check the flash loan calls data.

The unvalidated calldata allowed the exploiter to manipulate the contract’s data and send the funds to an Externally Owned Account (EAO). Following the initial reports, a second batch of attacks occurred.

Dough Finance's funds flow after the exploit. Source: Breadcrumbs.app on X

These attacks resulted in the loss of another $141,000 in USDC, raising the total crypto heist to $1.96 million. Nonetheless, Cyvers confirmed that lending protocol Aave’s pools remained unaffected.

Scammers Target DeFi Projects

After the initial reports, the DeFi protocol acknowledged the attack and urged users to withdraw their remaining funds from the protocol. Later, Dough Finance announced it had identified and closed the exploit.

The project confirmed that “a few early Dough DeFi Smart Accounts (DSAs)” were victim to a sophisticated exploit. Moreover, the post assured that Dough Finance’s team is actively working to address the incident, recover the funds, and make investors whole.

Online reports revealed that the team reached out to the exploiter. In an on-chain message, the Defi protocol informed the exploiter it had contacted the appropriate authorities.

The team's on-chain message to the exploiter. Source: Evgenii on X

The team also offered to discuss a bounty if the attacker had “exploited this vulnerability as a white or grey hat,” and attached the address where the funds should be directly transferred.

The exploiter has until Monday, July 15, 2024, at 23:00 UTC to contact the DeFi protocol. Per the message, if the team doesn’t receive an answer, they will “assume you appropriated the funds with unlawful intent and will pursue all criminal, legal, and administrative avenues available” to recover the misappropriated funds.

Scammers have heavily targeted the sector. This week, various DeFi projects, including Compound Finance, were compromised in a phishing attack. Seemingly, the projects were victims of a DNS domain attack that redirected users to a fake website.

The copy website was a drainer tool that could drain users’ funds if they interacted with it. As a result, the projects’ teams urged customers not to interact with the websites until further notice.

Ethereum is trading at $3,126 on the three-day chart. Source: ETHUSDT on TradingView

Featured Image from Unsplash.com, Chart from TradingView.com

Credit: Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Reddit VKontakte Telegram WhatsApp

Related Posts

Interactive quests make DeFi learning engaging and rewarding: Here’s how

July 30, 2024

Solana’s $61 Billion staking system is leading the DeFi

July 30, 2024

Interview: Iakov Levin of rivo.xyz explains how DeFi and blockchain may evolve moving forward

July 30, 2024

How Is DeFi Addressing Scalability Challenges?

July 30, 2024

Bitcoin, Ethereum, And Solana On Traders’ Radar: What’s Going On?

July 30, 2024

Solana near yearly high after 27% July gain and SOL price ‘double bottom’

July 29, 2024

Comments are closed.

Editors Picks

UK Gold Miner Bluebird Pioneers Bitcoin Reserve Move

June 6, 2025

Crypto Is ‘The Future,’ House Financial Services Oversight Subcommittee Chair Says

June 5, 2025

BREAKING: Uber Explores Global Stablecoin Transfers as CEO Hails Bitcoin ‘Proven’ Store of Value

June 5, 2025

Shiba Inu’s Shibarium Reaches New Record But SHIB Whales Are Exiting – What’s Happening?

June 5, 2025
© 2025 - credbit.com - All Rights Reserved!
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.