News

Published on October 4th, 2019 📆 | 2077 Views ⚑

0

Critical MakerDAO bug would’ve let hackers steal all your money


iSpeech

Crypto funds held in a soon-to-be launched MakerDAO smart contract could have been completely drained by a malicious attacker, it was revealed Thursday.

MakerDAO issues the DAI stablecoin, which is backed by ether (ETH) and nominally pegged to the US dollar. The platform will soon allow users to generate ā€œmulti-collateralā€ DAI tokens backed by a variety of cryptocurrencies.Ā 

On Thursday, a security researcher disclosed a flaw in the multi-collateral contract that would have allowed a hacker to steal all of the funds staked.

The flaw was embedded in the smart contractā€™s auction function, the process by which stakeholders auction off their crypto funds when DAI holdersā€™ collateral drops in value. If the value of that collateral drops too far, the stablecoin won't be fully backedā€”which is problematic, to say the least. A liquidation mechanism stops the whole system falling apart.

Be the first to get Decrypt Members. A new type of account built on blockchain.





A white hat hacker found that throughout this auction processā , for mere pennies, the smart contract could be exploited to siphon off all the collateral. ā€œThe cost of performing the attack is almost zeroā€”just the minimal denomination of each type of gem stolen plus gas,ā€ wrote the researcher who discovered the flaw.

Thatā€™s a lot of money at riskā€”MakerDAOā€™s smart contracts currently account for $270 million worth of ether, the only cryptocurrency that can currently be deposited into contracts.

But allā€™s well that ends wellā€”the code was patched in early September, with the researcher pocketing a $50,000 bug bounty. Which they can stake on MakerDAO, if the mood takes them.

Source link

Tagged with: ā€¢ ā€¢ ā€¢ ā€¢ ā€¢



Comments are closed.