Naveen retweeted

On Aug 1, the defi protocol @Convergence_fi was exploited for ~$210k when the hacker exploited a vulnerability in the CvxRewardDistributor contract.
In an official post on their ‘X’ handle, @Convergence_fi has advised its users not to interact with the protocol and withdraw assets staked on the platform.
The 58M CVG stolen by the exploiter were part of tokens dedicated to staking emissions. In addition, the hacker also got away with $2,000 of unclaimed rewards from Convex.
The attacker was initially funded through the infamous Tornado Cash by address
etherscan.io/address/0x912c…
After the exploit, the CVG token prices took a major hit and have not recovered since.
The Vulnerability
The vulnerable CvxRewardDistributor contract is responsible for minting CVG rewards to eligible stakers and and holding the rewards claimed from Convex, which in turn can be claimed by the stakers.
Due to a bug, the input given by the user in the function claimMultipleStaking() of the said contract was not being validated.
The hacker manipulated this bug to deploy a malicious contract to mint all tokens meant for staking emissions (58,000,000 CVG) only to dump the newly minted CVG into liquidity pools.
Why is this Bug not Fixed in the Audit?
To achieve gas optimization, the developers had modified/removed that line from the smart contract's code, which validated the user input given to the function claimMultipleStaking().
These changes were made post-audit; therefore, the auditors couldn’t have done anything to avoid the exploit.
Hack Technical Details
Attacker Address:
etherscan.io/address/0x0356…
Attack Txn:
etherscan.io/tx/0x636be30e5…
Attack Contract Address:
etherscan.io/address/0xee45…
Target contract: CvxRewardDistributor
etherscan.io/address/0x2b08…
#Hacked #exploited #crypto #CryptoInvestor #CryptoInvestment #CryptoInvesting #cryptomarket #CryptoCommunity #web3community #bugbountytips #Blockchain #Blockchain101 #WEB3 #web3community #web3jobs #BugBounty #blockchaintechnology #blockchaindevelopment #blockchaingaming #blockchainrevolution #blockchaineducation #blockchains #blockchaincommunity #blockchainjobs #blockchainsecurity #blockchaindevelopers #blockchainsolutions #blockchaintech #web3development #web3education #web3event #cryptocurrency #cryptocurrencynews #cryptocurrencies #cryptonews #bugbountytip #cryptowallet #smartcontracts

English


















