Daniel Tan
Security Operation / Audit
2023-11-11 02:59:23 a.m., our MetaScout detected that the stablecoin protocol on #Ethereum, Raft, was under a flash loan attack. It resulted in ~6.7m stablecoin $R being minted and the protocol lost $3.6M. The root cause is the precision calculation issue when minting share tokens, which is used by the hacker to get extra share tokens. MetaTrust Labs conducted in-depth research and analysis on the exploit, revealing how the hacker exploits vulnerability.
2023-11-11 02:59:23 a.m. UTC +8:00, MetaScout detected that the stablecoin protocol on #Ethereum, Raft, was under a flash loan attack. It resulted in ~6.7m stablecoin $R being minted and the protocol lost $3.6M. The root cause is the precision calculation issue when minting share tokens, which is used by the hacker to get extra share tokens.
MetaTrust Labs conducted in-depth research and analysis on the exploit, revealing how the hacker exploits vulnerability.
Raft is a DeFi protocol that lets you generate R by depositing liquid staking tokens (LSDs) as collateral, providing a capital-efficient way to borrow while keeping your staking rewards. https://raft.fi/. As of the time of writing, its TVL has dropped 46% to $7M after today's attack. The price of $R has dropped 99.6% to $0.0036
https://etherscan.io/tx/0xfeedbf51b4e2338e38171f6e19501327294ab1907ab44cfd2d7e7336c975ace7
0xc1f2b71a502b551a65eee9c96318afdd5fd439fa
0x0a3340129816a86b62b7eafd61427f743c315ef8
InterestRatePositionManager: 0x9ab6b21cdf116f611110b048987e58894786c244
The root cause is the precision calculation issue when minting share tokens, which is used by the hacker to get extra share tokens. Because the index was amplified by the donation of $cbETH, the hacker's shares are worth more value, so the hacker can redeem a tiny $rcbETH-c for 6003 $cbETH and borrow tons of $R.
$3.6M
1570 $ETH was burned by the mistake of the hacker. As of the time of writing, there are 1.4M $R tokens (worth $4.6K) staying in the attacker's wallet.
MetaTrust Labs is a leading provider of Web3 AI security tools and code auditing services incubated at Nanyang Technological University, Singapore. We provide advanced AI solutions that empower developers and project stakeholders to protect Web3 applications and smart contracts. At MetaTrust Labs, we are committed to protecting the Web3 space so that builders can innovate with confidence and reliability.
Website: https://metatrust.io/
Twitter: https://twitter.com/MetatrustLabs
Daniel Tan
Security Operation / Audit
2023-11-11 02:59:23 a.m., our MetaScout detected that the stablecoin protocol on #Ethereum, Raft, was under a flash loan attack. It resulted in ~6.7m stablecoin $R being minted and the protocol lost $3.6M. The root cause is the precision calculation issue when minting share tokens, which is used by the hacker to get extra share tokens. MetaTrust Labs conducted in-depth research and analysis on the exploit, revealing how the hacker exploits vulnerability.