Post Mortem: Thoreum Finance

리서치 사고 분석
Post Mortem: Thoreum Finance

Project name: Thoreum Finance (Jan 19th)

Project type: Token

Date of exploit: Jan 18th, 2023

Asset loss: Around 2,260 WBNB

Vulnerability: Logic issue

Date of audit report publishing: Jul 1st, 2021

Conclusion: Out of Audit Scope

Details of the Exploit

Background

Thoreum Finance is a DeFi project providing multiple services such as liquidity mining to its users. Its token contract was upgraded to v4 on Jan 18 and got hacked after the upgrade.

Nature of the Vulnerability

  • The new implementation of Thoreum is unverified, but the _transfer() function is likely flawed when from == to. The sender's balance increases as much as the sent amount.

CertiK Audit Overview

Screenshot 2024-01-11 at 8.31.38 PM

Conclusion

On Jan 18, 2023, Thoreum Finance's token contract v4 was exploited, leading to a loss of around 2,260 WBNB. The attacker took advantage of the flawed implementation in the token contract's transfer function and manipulated its balance.

Based on the announcement from Thoreum team, the vulnerability was raised in the newly updated contract(unverified) deployed on Jan 18th, 2023.

References

관련 블로그

Post Mortem:  TerraPort Finance

Post Mortem: TerraPort Finance

On April 10th, 2023, the Terraport project team was alarmed breach detected with the Terraport Liquidity wallet. The total loss is around $4M.

Post Mortem: Telcoin

Post Mortem: Telcoin

​​On Dec 26th, 2023, Telcoin experienced a loss of ~$1.25M attack. The vulnerable contract is due to a vulnerability in the proxy implementation of wallet contracts, which is a different application from what CertiK has audited.

Post Mortem: Sushiswap

Post Mortem: Sushiswap

On April 9th, 2023, the RouteProcessor2 in Sushiswap was exploited due to missing validation on the input with processRoute function. The total loss is around $ 3.3 M.