Another DeFi protocol is exploited, losing all $25 million locked

dForce, a decentralized financial platform, had its core product lendf.me attacked draining the entire pool of capital. Early reports state that the attacker took advantage of imBTC, a collateralized version of bitcoin that uses the ERC-777 standard, to post “unlimited collateral” to then drain all the assets in the pool. This re-entrancy attack was the same one used in the infamous DAO exploit and was highlighted in a recent Uniswap audit.

Why it matters

  • This attack comes just a matter of days after dForce announced a funding round led by Multicoin Capital. With fresh capital and jumping to the 7th largest DeFi platform, dForce was looking to become a prominent player. However, an attack of this magnitude could be crippling, making it incredibly difficult to regain user trust.
  • This is not the first major attack in DeFi and almost certainly won’t be the last. Over time, market participants will only continue to learn through these types of attacks that these nascent protocols carry substantial risk. While it may lead some to exit entirely, for those who still want to experiment in DeFi, it highlights the need to take adequate risk management measures.
Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.

Suggested Research Based on your Watchlists

Create a new watchlist