Categories: News

$pickle in a pickle as attacker swipes $20 million in “evil jar” exploit

The perils of decentralized finance in the spotlight yet again after the latest major DeFi exploit

In yet another attack on a major decentralized finance (DeFi) protocol, farming project Pickle Finance has been exploited today to the tune of $20 million. 

The attack transpired roughly two hours ago, and ETH-savvy Twitter users were quick to notice that pickle’s cDAI jar — Pickle’s term for a yield-bearing vault — had been emptied:

Unlike other recent attacks however, this particular exploit did not feature flashloans — an increasingly maligned DeFi tool that allows would-be exploiters additional liquidity with which to manipulate on-chain prices. Instead, this hacker swapped funds between a malicious copycat contract and the cDAI jar. 

In an interview with Cointelegraph, Emiliano Bonassi — a self-described whitehat hacker and the co-founder of DeFi Italy — explained that the attacker created “evil jars, ” smart contracts which “have the same interface of traditional jars but do bad things.”

The attacker then swapped funds between his “evil jar” and the real cDAI jar, making off with the $20 million in deposits.

Particularly after the attack on Harvest Finance, Pickle Finance had looked to be on its way towards becoming one of the preeminent farming protocols. As of press time, Pickle’s stats website reported nearly $75 million total value locked remaining on the books, while the price of pickle, Pickle Finance’s governance token, is down 50% on the day to $11.16.

Pickle Finance’s woes are just the latest in a troubling trend across the DeFi space. Recent exploit victims in just the last few weeks include Harvest Finance, Value DeFi, Akropolis, Cheese Bank, and Origin Dollar, among others.

Perhaps, however, the vulnerabilities of one DeFi vertical might lead to the success of another. Said one Twitter trader:

[…]
Learn more

crypto

Leave a Comment

Recent Posts

The Governor of the Banque de France obtains the prestigious Tulip Prize

The Tulip Prize [1] was awarded yesterday to François Villeroy de Galhau for a speech…

2 years ago

United States: The offensive of a group of senators against cryptocurrencies

Senator Elizabeth Warren, supported by other senators, today introduced a bill titled the “Digital Asset…

2 years ago

Ukraine: Volodymyr Zelensky signs a law "on virtual assets"

President Volodymyr Zelensky today signed the “virtual assets” law adopted by the Ukrainian parliament on…

2 years ago

US: A central bank digital dollar project

Joe Biden today signed an executive order asking the federal government to assess the risks…

2 years ago

Ethereum: 100,000 transactions per second

After the implementation of the Ethereum blockchain in the consensus Proof-of-Stake model called “Beacon Chain”,…

2 years ago

First major correction of 2021 for cryptos

It hung in the face of investors, this correction. And if the movements of Bitcoin…

3 years ago