지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

Stablecoin Stumble: The Code Bug Led to $6.5 Million Loss on DeuS Finance

보고서 ·사고 분석 ·
Stablecoin Stumble: The Code Bug Led to $6.5 Million Loss on DeuS Finance

Project name: Deus​​ Finance

Project type: DEX and Stable Coin

Date of exploit: May 5th, 2023

Asset loss: ~ $ 6,500,000

Vulnerability: code logic issue

Date of audit report publishing: Jun 23rd, 2021

Conclusion: Out of audit scope

Details of the Exploit

Background

DEUS Finance is a platform for decentralized financial services, including an AMM product and a stablecoin product called “DEIStablecoin”. The stablecoin is designed to follow the ERC20 standard that contains a feature to allow others to spend money.

Nature of the Vulnerability

The DEUS stablecoin DEIStablecoin contains the following vulnerable burnFrom function. To align with the ERC20 standard and “_approve()” operation, the “currentAllowance” should be “_allowances[account][_msg.sender()]” , instead of “_allowances[_msg.sender()][account]”. As a result of this bug, an attacker could manipulate the stable coin’s allowance by taking advantage of the incorrectly implemented burnFrom function, ultimately using the victim's tokens without authorization.

CertiK Audit Overview

Screenshot 2024-01-08 at 5.22.09 AM

Conclusion

On May 5th, 2023, the Deus stablecoin was attacked due to issues within its code logic, leading to a loss of $6,500,000.

CertiK Audited the AMM product of the Deus Finance. However, the exploit was due to the vulnerability in the Stablecoin product, which is a different product from what CertiK has audited. Therefore, it is out of the audit scope.

References

Reket.news: https://rekt.news/deus-dao-r3kt/

관련 블로그

Stablecoin Compliance in the Age of Agentic Commerce

Stablecoin Compliance in the Age of Agentic Commerce

In February 2026, an AI agent named Lobstar Wilde gave away tokens worth up to $450,000 to a stranger on X. The stranger had posted a sob story about needing 4 SOL for his uncle's tetanus treatment. Lobstar Wilde, an autonomous agent running on Solana with a live wallet, read the post and sent 52 million tokens. Not 4 SOL. Five percent of its entire token supply. The developer later explained that a session crash had wiped the agent's memory. It forgot what it owned, misread a social media post as a legitimate request, and signed an irreversible on-chain transfer. No compliance system flagged the transaction. No human reviewed it. The money just moved. This is a preview of what agentic commerce looks like without proper compliance infrastructure.

The Importance of Having a Bug Bounty Program for Your Blockchain Project

The Importance of Having a Bug Bounty Program for Your Blockchain Project

Learn why having a bug bounty program is crucial for your blockchain project. Discover how it helps identify vulnerabilities, improve security, and build trust with users.

What are Stablecoins?

What are Stablecoins?

Types of stablecoins, how they work, use cases, and common risks, including de-pegs, liquidity, and compliance. Learn more about stablecoins before you transact with them.