See More

DeFi Apps Represent 24/7 Multi-Million Dollar Hacker Honeypots

2 mins
Updated by Max Moeller
Join our Trading Community on Telegram
A recent smart contract exploit resulted in the loss of 1,193 ETH. The incident has prompted questioning of the security of the rapidly evolving DeFi sector.
Over the weekend, the exploitation of a smart contract vulnerability forced developers at Ethereum-based app Fulcrum to partially disable its smart contract. A recent postmortem of the security breach shows that the attacker used a series of complex trades across multiple applications to exploit the vulnerability. [bZx] This caused researchers to conclude that the attacker possessed an “extremely in-depth knowledge of every DeFi protocol.”

The Viability of DeFi

As BeInCrypto has previously reported, the incident prompted some to question the viability of the DeFi sector. Charlie Lee, the founder of Litecoin, said the fact that so-called decentralized applications have an admin key to pause contracts amounted to ‘decentralization theatre.’ Lightning Network developer Alex Bosworth shared a similar opinion: Whether claims of absolute decentralization are accurate or not, the incident points at a much larger and more fundamental problem within the industry. Although the report by researchers at bZx states that all user funds are safe and that they have implemented a patch to stop future attackers using the same exploit, such reactive fixes do nothing to prevent future vulnerabilities. As financial applications, the likes of Fulcrum represent vast honeypots for hackers. Running constantly and with increasingly complex functions, the fact that so many smart contracts have already fallen victim to exploits proves that they make an alluring target. DeFi Ethereum Reporter and industry observer Larry Cermak highlighted the issue via Twitter earlier Tuesday. He describes current DeFi applications as a constant “multi-million dollar bounty open 24/7 and with very little consequences.” Cermak concludes that creating a DeFi application must be an enduring headache for developers: The bZx developers themselves seem to agree with the above. Kyle J Kistner, CVO of bZx writes:
“The space is evolving quickly, and security is becoming increasingly more dire as the barriers to entry to executing an exploit drop to zero. There is no analog to this in the traditional financial system. We are now in uncharted territories.”

Untested Waters

Meanwhile, others have argued that people that the industry is still far too untested for people to be investing such large sums of money in new, complex dApps. In the following Twitter thread, Taylor Monahan, CEO of MyCrypto.com, details how bZx has been at the heart of several previous vulnerabilities: Ultimately, she concludes that past DeFi exploits should be enough to steer people away from the industry. She also argues for greater accountability in the industry. However, with interest and subsequent investments in decentralized finance growing rapidly, and the applications also growing in complexity, it is undoubtedly a matter of when rather than if a similar incident to the Fulcrum hack will occur again.
Top crypto platforms in the US | March 2024
Coinbase Coinbase Explore →
AlgosOne AlgosOne Explore →
Chain GPT Chain GPT Explore →
iTrustCapital iTrustCapital Explore →

Trusted

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.

c8d670c5ace3fefdd9c2b09519d3b3c7?s=120&d=mm&r=g
A former professional gambler, Rick first found Bitcoin in 2013 whilst researching alternative payment methods to use at online casinos. After transitioning to writing full-time in 2016, he put a growing passion for Bitcoin to work for him. He has since written for a number of digital asset publications.
READ FULL BIO
Sponsored
Sponsored