Lending Rate Manipulation: Investigating the FilDA Finance Attack

리서치 사고 분석
Lending Rate Manipulation: Investigating the FilDA Finance Attack

Project name: FilDA

Project type: Lending

Date of exploit: April 22, 2023

Asset loss: $700K

Vulnerability: Exchange rate manipulation

Date of audit report publishing: June 1, 2021

Conclusion: Out of audit scope

Details of the Exploit

Background

FilDA provides a lending protocol where users can deposit token as collateral then borrow tokens.

Nature of the Vulnerability

The exchange rate is calculated by exchangeRate = (Cash + totalBorrows - totalReserves)/totalSupply. The attacker manipulated the exchange rate by donating a large amount of htHBTC tokens to the contract. Since Cash in the above formula is the amount of htHBTC that the Filda htHBTC contract has, the exploiter donates a large amount of htHBTC to inflate the exchangeRate. As a result, the attacker can borrow more than its collaterals from the pool.

CertiK Audit Overview

Screenshot 2024-01-08 at 5.28.30 AM

Conclusion

On April 22, 2023, FilDA Finance was attacked, leading to a loss of around $700K. The attacker manipulated the exchange rate in the lending pool and drained funds from it. CertiK has audited the FilDA’s Flashloan contracts. However, the vulnerability lies in the lending pool contract, which is a new product that is not within CertiK's audit scope.

References

FilDA exploit statement: https://fildafinance.medium.com/filda-exploit-statement-49ec69e34c53

관련 블로그

Post Mortem: Onyx Protocol

Post Mortem: Onyx Protocol

On Nov 1, 2023, Onyx Protocol was attacked, leading to a loss of around $2.1M. The Onyx team added a new PEPE market without any initial funds, so the hacker was able to manipulate the exchange rate of the PEPE market and borrow assets from other Onyx markets, also got back all the collateral due to rounding errors in solidity, causing bad debts in these markets. This vulnerability was identified in CertiK's audit report, and CertiK recommended that the project team add a new contract capable of minting fresh shares when the contract is deployed. The Onyx team acknowledged this issue and decided not to perform any action on the contract.

Lending Contract Exploits: A Retrospective

Lending Contract Exploits: A Retrospective

In traditional finance, lenders provide funds in return for interest on their deposits, while borrowers pay interest for immediate access to funds. DeFi lending operates on the same principle, but uses smart contracts. This approach means DeFi is accessible to everyone without the need for personal details or trusting a third party to hold funds. This report examines several past exploits analyzed by CertiK

2022 Year in Review: Lending Protocols

2022 Year in Review: Lending Protocols

DeFi lending protocols suffered a number of major attacks in 2022. In this article, we recap these incidents and offer a number of proactive security solutions.