dForce hacker returns all $25 million stolen after failing to hide important metadata

After getting its entire $25 million balance drained, dForce has since recovered nearly all of its funds from the attacker who took advantage of a well-known vulnerability in the ERC-777 standard. The attacker used popular DEX aggregator 1inch.exchange to trade the newly stolen tokens, however, he leaked important metadata about himself in the process making it easy to track him down.

Why it matters

  • Since all funds have been returned, the lendf.me attack can be viewed as a positive development for DeFi since it once again highlighted the risk in these protocols while users didn’t have to face millions in losses. This should continue the trend of security and economic audits being more rigorously demanded before any protocol can accrue a substantial amount of user funds.
  • Even though no money was lost it still showed the relative ease at which a hacker can run away with millions of dollars. This could attract the attention of more hackers who see an easy payday, provided they can better obfuscate their information.
Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.

Suggested Research Based on your Watchlists

Create a new watchlist