Tuesday, January 13, 2026
No Result
View All Result
The Crypto HODL
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
No Result
View All Result
The Crypto HODL
No Result
View All Result

Decoding Hopelend’s $835k Exploit

November 3, 2023
in DeFi
Reading Time: 3 mins read
0 0
A A
0
Home DeFi
Share on FacebookShare on Twitter


Learn Time: 3 minutes

Abstract:

On the 18th of October 2023, HopeLend Protocol on the Ethereum chain was attacked. The assault was made attainable by a Precision Loss vulnerability. Round $835k was stolen from the exploit.

About Venture:

HopeLend is a decentralized, non-custodial lending protocol. To be taught extra about them, try their documentation.

Vulnerability Evaluation & Influence:

On-Chain Particulars:

Attacker Handle:  0x1F23eb80f0c16758E4A55D48097c343bD20Be56f 0xa8bbb3742f299b183190a9b079f1c0db8924145b, 0x9a9122Ef3C4B33cAe7902EDFCD5F5a486792Bc3A, 

Sufferer Contract:  0xc74b72bbf904bac9fac880303922fc76a69f0bb4

Assault Transaction: 0x1a7ee0a7efc70ed7429edef069a1dd001fbff378748d91f17ab1876dc6d10392

The Root Trigger: 

The basis trigger was the lack of precision loss in Htoken’s contract. 

The attacker took the benefit of lack of precision in calculating liquidity index throughout execution of  _handleFlashLoanRepayment 

Assault Course of:

First, the attacker took a FlashLoan of 2k WBTC. adopted by including that into the Pool contract’s reserve’s liquidity index 

The attacker was in a position to change the liquidity index of hEthWBTC  from 1e27 to 7,560,000,001e27

The attacker improve it’s revenue by borrowing belongings from completely different markets.

This resulted in hacker profiting by paying much less collateral of WBTC on account of precision loss 

Move of Funds: 

Right here is the fund movement throughout and after the exploit. You may see extra particulars right here.

Attacker’s Wallets: 

It’s value noting {that a} Generalized frontrunner 0x9a9122Ef3C4B33cAe7902EDFCD5F5a486792Bc3A was in a position to frontrun the unique transaction by paying a bribe of 263ETH to one of many validatiors managed by Lido 

Here’s a snippet of the pockets handle

After the Exploit

The Venture acknowledged the hack by way of their Twitter.

Incident Timelines

Oct-18-2023 11:48:59 AM +UTC  – The malicious transaction occurred 

Oct-18-2023 11:48:59 AM +UTC – The unique transaction was frontrunned.

How may they’ve prevented the Exploit?

It’s suggest to examine all of the instances for precision loss

If attainable, protocols are requested to give attention to complete invariant testing 

The Crucial Want for Web3 Safety

As a Web3 safety agency QuillAudits, we embrace the essence of decentralization by providing transparency, and we would like that spirit to shine by means of in our companies too.

Need extra Such Safety Blogs & Studies?

Join with QuillAudits on :

Linkedin | Twitter | Web site | Publication | Discord | Telegram

Associate with QuillAudits :

152 Views



Source link

Tags: 835kDecodingexploitHopelends
Previous Post

British Museum to digitise collection as over two million objects are found to be undocumented

Next Post

Whales Holding at Least $1,572,000,000 in Ethereum Now Own Nearly 33% of Total ETH Supply, Says Santiment

Related Posts

Equifax UK Partners with Greek Credit Bureau Tiresias
DeFi

Equifax UK Partners with Greek Credit Bureau Tiresias

January 13, 2026
Bilt Embeds Loyalty at Checkout with Verifone
DeFi

Bilt Embeds Loyalty at Checkout with Verifone

January 9, 2026
Finovate Global Egypt: New Partnerships, New Products, New Markets
DeFi

Finovate Global Egypt: New Partnerships, New Products, New Markets

January 10, 2026
Transforming Business Banking with US Bank’s Shruti Patel
DeFi

Transforming Business Banking with US Bank’s Shruti Patel

January 9, 2026
Clover Selects Wink to Offer Biometric-Powered Payments
DeFi

Clover Selects Wink to Offer Biometric-Powered Payments

January 11, 2026
Partnership with FIS Brings UK Paytech Modulr to the US
DeFi

Partnership with FIS Brings UK Paytech Modulr to the US

January 11, 2026
Next Post
Whales Holding at Least $1,572,000,000 in Ethereum Now Own Nearly 33% of Total ETH Supply, Says Santiment

Whales Holding at Least $1,572,000,000 in Ethereum Now Own Nearly 33% of Total ETH Supply, Says Santiment

USDC Issuer Circle Releases Crypto Upgrades to Remove Cost, Frictions for Users, Web3 App Developers

USDC Issuer Circle Releases Crypto Upgrades to Remove Cost, Frictions for Users, Web3 App Developers

Make Music Count embeds watsonx to make perfect music with math  

Make Music Count embeds watsonx to make perfect music with math  

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn Telegram RSS
The Crypto HODL

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at The Crypto HODL

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Mining
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Videos
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Crypto Marketcap

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In