Curve Conundrum: The dForce Attack via a Read-Only Reentrancy Vector Exploit

리서치 사고 분석
Curve Conundrum: The dForce Attack via a Read-Only Reentrancy Vector Exploit

Project name: dForce

Project type: Lending

Date of exploit: Feb 9, 2023

Asset loss: $3.7M

Vulnerability: Price manipulation (Read-only Reentrancy)

Date of audit report publishing: Feb 21, 2021

Conclusion: Out of Audit Scope

Details of the Exploit

Background

dForce is a DeFi project providing services including stablecoin, lending, trading, and governance. In the dForce lending protocol, the amount of tokens a user can borrow depends on the value of their collaterals, which is calculated using external price Oracles. In this exploit, the external price Oracle is a Curve protocol.

Nature of the Vulnerability

  • A manipulated asset price incorrectly calculates the attacker's collateral value, so the attacker can borrow more than its collateral to drain the vault.
  • The asset price is provided by a Curve protocol, which has a read-only reentrancy issue in its implementation.
  • The attacker manipulated the token price by triggering external calls to update its collateral in dForce's lending protocol in the process of withdrawing liquidity from the Curve pool.

CertiK Audit Overview

Screenshot 2024-01-08 at 5.47.56 AM

Screenshot 2024-01-08 at 5.49.26 AM

Conclusion

On Feb 9, 2023, dForce's lending protocol was attacked, leading to a loss of $3.7M. The attacker made use of a read-only reentrancy vector to manipulate the price in the lending protocol to drain funds from the pool. The vulnerability lies in the dependency on the Curve protocol, which was used as price Oracles in dForce's lending protocol, and has been widely recognized by the community. The dependency on the Curve protocol is not in CertiK's audit scope.

References

dForce's announcement: https://twitter.com/dForcenet/status/1623904209161830401

관련 블로그

Curve Finance Hack Incident Analysis

Curve Finance Hack Incident Analysis

Curve Finance was compromised on August 9, 2022 for approximately ~$612K in total loss due to a cloned malicious site

Conic Finance Incident Analysis

Conic Finance Incident Analysis

On 21 July, 2023 the Conic Finance ETH Omnipool was exploited for 1724 ETH (\$3.2 million) via a read-only reentrancy vulnerability. Despite having reentrancy guards in place, an incorrect assumption led to a reentrancy guard being bypassed. Conic paused the ETH Omnipool but a few hours later they lost a further \$300,000 to MEV arbitrage in the crvUSD Omnipool.

CertiK 101: Non-Fungible Tokens (NFTs)

CertiK 101: Non-Fungible Tokens (NFTs)

Over $150M worth of NFTs has been traded so far. The popular ERC721 standard is here to stay and here's everything you should know about it to stay ahead of the curve!