Title: A Brief Analysis of the Ecological Security Incident of Binan Intelligent Chain
原文来源: 田七
Recently, the dApps on BSC have been frequently attacked by hackers. The security issue of smart contract caused by this has attracted wide attention and heated discussion in the whole industry. Security is like the sword of Damocles, hanging over everyone's head.
According to a list of project losses on Rekt. news, there were 10 projects involved in BSC with a total loss of $220 million. The project that lost the most was Uranium Finance, which lost $57.2 million. Merlin Labs, after the first attack and emergency repair, was attacked again, and was visited by hackers twice in just two days. What's more, Value Defi, which has been attacked three times, has become the back garden of hackers.

这些项目究竟暴露哪些被黑客利用的漏洞?事后他们又做出怎样的应对措施?造成了哪些影响?对我们普通用户有什么教育及警示意义?接下来让我们逐一分析。
Pancakebunny is a machine gun pool protocol based on Pancakeswap and Venus, which was once the BSC's largest machine gun pool protocol with the largest number of locked tanks. On May 19, 2021, hackers borrowed a lot of BNBs through a flash loan and formed an LP with BUSD on Pancakeswap, and then exchanged BNBs for BUSD to manipulate the value of the LP tokens, Then, by calling the GetReward function of VaultFliptoFlip, you can get 6.97 million BUNNY of mining income. Finally, you can sell this part of BUNNY and make 45 million dollars.
After the event, Pancakebunny first suspends user deposits and withdrawals from the affected pool and then deploys a compensation pool from which affected users can collect their payments. In order to eliminate the impact of lightning lending on price manipulation, ChainLink is integrated to obtain reliable price information data through ChainLink.
Uranium Finance is a forked Uniswap, a decentralized trading platform clone of the BSC. But when they upgraded V2, they made minor tweaks to the original Uniswap code, one line of code missing a 0, allowing the hackers to withdraw a larger share of liquidity with a smaller amount of tokens on April 28, 2021, resulting in a $57.2 million loss to the liquidity pool.
Uranium Finance later published a vulnerability analysis article and called on users to remove their money as soon as possible and stop providing liquidity to their contracts. Uranium Finance's official Twitter account has not been updated since.
The loophole in the program is that anyone can become the owner of the vault and withdraw all the money. So on March 4, 2021, the attackers used an initial call to impersonate themselves as the owner of the vault, taking Busd and WBNB from the vault, which was worth $32 million.
The project owner first claimed that this was a hacking attack, then deleted the claim and quit the cable group. Later, a developer claiming to be a member of the project said it was a stress test to raise security awareness among users, and funds would be refunded in an orderly way within a new cable cluster. But when I tried to open the cable group link, I could not find the group. It is clear that this was a premeditated escape, and that the user's trust in the developer resulted in a loss of personal funds.
This is a synthetic asset agreement, hackers on May 2 through the flash loan into the BNB, and a part of the BNB converted into SPARTA, and then formed LP. By taking advantage of the Spartan pool share calculation loophole, the Spartan pool lost 30.5 million dollars by taking a larger share with a smaller share.
The team released a new token, SPARTA, and upgraded the liquidity pool to V2, which is still up and running.
Value Defi is a machine gun pool protocol deployed across multiple chains. It was first attacked on the Ethereum chain on November 14, 2020. After that, hackers attacked Value Defi on BSC on May 3 and May 5, 2021 respectively, racking up $28 million. The attack on May 3 was because the initialize function of the protocol contract forgot to set the initialized state variable to true, resulting in the attacker being able to control the VBWAP /BUSD liquidity pool and then remove the liquidity of the pool. Converting the RenbTC bridge connects to the BTC chain to escape. The attack on May 5th involved an erroneous use of Bancor's formula, which allowed hackers to exchange fewer coins for a larger one.
The actions taken by Value Defi after the event include using the team's own funds for compensation and restarting the online plan. At present, the affected users can go to their official website to receive compensation, while the restart time will wait for the subsequent announcement.
Bearn is a cross-chain machine gun pool protocol, and the attack on it took place on May 16, 2021. By exploiting the unit of measure vulnerability, that is, when assets are removed from the contract, the design is in IBBUSD unit, but the actual implementation code is in BUSD unit. Since ibBUSD is more expensive than BUSD, the hacker is able to fetch more ibBUSD than he should. When the hackers used flash loans to borrow large amounts of Busd for repeated refilling operations, the pool was quickly drained, eventually making a profit of $18 million.
Later, Bern published an article to analyze the above-mentioned loopholes and formulated a follow-up compensation plan. The compensation is divided into two parts. First, the compensation is made with the current Treasury fund, which can be claimed at present. Secondly, BDOv2 and BDEX are used for compensation. This part is expected to be online in the middle of June. So far, the project is still in operation.
BugerSwap, a Dex on BSC, was hacked on May 28, 2021 using 14 transactions, resulting in a loss of $7.2 million. The flaw occurred when the hacker was able to reenter and reconvert the pool reserve funds before they were updated. This is because Buger uses the constant product X * Y = K algorithm, but removes X * Y * GT from the code. K check.
BugerSwap's reaction included suspending trading, fixing the bug, and airdropping new dollars to compensate.
On May 29, 2021, Belt Finance was exploited by hackers because of the BellipsisBusd policy pool balance calculation vulnerability, using the lightning loan to manipulate the BeltBusd price and steal the Busd worth 6.3 million dollars.
After the event, BELT suspended contract related operations, and reopened on June 2, at the same time the announcement will be cast a new currency for compensation.
Merlin Labs is a fork Pancakebunny protocol with a vulnerability similar to that of Pancakebunny, which was hacked on May 26, 2021 using Cake in the wallet as a policy benefit, Swindled the Merl mining revenue from the Merlin contract and made $680,000 through the loop call. However, when Merlin claimed to fix the vulnerability and redeployed it online, the repaired code exposed the vulnerability again. This time, it was because when calculating the price, it multiplied by 10 billion, and the cumulative loss of the two attacks was 1.23 million dollars.
Merlin Labs just made a compensation plan for the first attack, and now the compensation has to cover the second attack again.
AutoShark, another PancakeBunny fork, also inherited the Bunny vulnerability and was similarly hacked to steal $745,000 on May 25, 2021.
AutoShark's response includes restarting the protocol after a fix and airdropping tokens to compensate.
When combing these attacked projects, Impossible Finance was stolen 500,000 dollars by hackers on BSC one after another. The code vulnerability was the same as BugerSwap. Eleven Finance lost more than $5 million due to a failure to execute a function destroy vulnerability.
From the analysis of the above projects, we find that their characteristics are as follows:
1. The loss amount is relatively large, and it is easy to cause users' doubts about the safety of the project party, BSC and even the whole industry, and the impact is far-reaching.
2. Hackers often choose to flee across the chain, making hacker identity tracking and fund recovery almost impossible, resulting in permanent loss of users;
3. Similar vulnerabilities have been repeated many times, including the use of flash credit to manipulate prices and the use of code logic flaws to attack, and other types of vulnerabilities have occurred in Ethereum;
4. Instead of giving up, most project participants have taken various measures to save themselves.
As an average user, you may not be able to read code or understand complex economic models. So, how to prevent the risk of being attacked as much as possible in the future?
1. The key point is to focus on the predictor selected by the project party. The predictor is a key component to obtain price information. The quality of the predictor determines the quality of price data. The many protocols that use Chainlink's decentralized predictor have been largely immune to price-fixing attacks.
2. Use protocols that have just been introduced with caution, as they have not been tested over time and are difficult to determine whether they are safe or not.
3. Go to zero and get involved with projects with money you can afford to lose.
4. Beware of projects with super-high returns, keep reasonable expectations for the returns, and be willing to miss rather than make mistakes.
It has been less than a year since BSC was officially launched, and its development has been beyond many people's expectations. When a new thing is in its initial stage, it will inevitably encounter some difficulties and challenges. The security holes in some applications of BSC do not mean that there is something wrong with BSC itself, and we should not give up for fear of throwing out the doubt on all applications of BSC. Exposing security vulnerabilities in advance also means avoiding greater losses in the future. After paying painful lessons and heavy costs, both project parties and users will pay more attention to security issues and put security work in the top priority. I hope there will be less and less security accidents in the future, and users will be more and more assured to use all kinds of applications.
This article was submitted and does not reflect the views of Rhythm Blockbeats
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia