Post Mortem: DefiLabs

Research Incident Analysis
Post Mortem: DefiLabs

Project name: DefiLabs

Project type: DeFi

Date of rug pull: July 27th, 2023

Asset loss: $1.6M

Vulnerability: Rug pull

Date of audit report publishing: Aug 25th, 2022

Conclusion: Out of Audit Scope

Details of the Exploit

Background

DefiLabs is a DeFi project providing various DeFi services such as staking and exchange.

Nature of the Vulnerability

There is a privileged function withdrawFunds allowing the funder to withdraw all funds in the pool.

CertiK Audit Overview

defi1 defi2

Conclusion

On July 27th, 2023, DefiLabs was rug-pulled by a privileged function in the vPoolv6 contract, which is not audited by Certik.

Related Blogs

Post Mortem: Thoreum Finance

Post Mortem: Thoreum Finance

On Jan 18, 2023, Thoreum Finance's token contract v4 was exploited, leading to a loss of around 2,260 WBNB. The attacker took advantage of the flawed implementation in the token contract's transfer function and manipulated its balance.

Post Mortem:  TerraPort Finance

Post Mortem: TerraPort Finance

On April 10th, 2023, the Terraport project team was alarmed breach detected with the Terraport Liquidity wallet. The total loss is around $4M.

Post Mortem: Telcoin

Post Mortem: Telcoin

​​On Dec 26th, 2023, Telcoin experienced a loss of ~$1.25M attack. The vulnerable contract is due to a vulnerability in the proxy implementation of wallet contracts, which is a different application from what CertiK has audited.