Acala Network Resumes Full Operations After Exploit

  • All three phases of Acala’s plan to resume operations have been executed, and all services on the network are now reopened.
  • All aUSD from the error mints had been recovered with the exception of 5.8 million tokens, which were re-collateralized using the team’s own funds.
acala network

Shutterstock

Almost two months after experiencing a major security exploit, Polkadot’s Acala parachain has finally completed the final step in its plan to resume all operations, the platform said via Twitter on 5 October.

Back in August, decentralized finance (DeFi) platform Acala Network suffered from a security exploit due to a code misconfiguration in a liquidity pool smart contract, which allowed liquidity providers to “error mint” more than 3 billion aUSD. Shortly after the exploit was detected, Acala’s team suspended all activities on the network through an emergency governance vote, with 99% of the “erroneously minted aUSD” remaining on the Acala parachain.

Days later, the Acala team revealed they had recovered around 2.97 billion aUSD tokens that were minted during the security incident, which were promptly burned after a community vote was passed. The platform then adopted a phased approach to resuming its operations, with each phase requiring approval from a governance vote to be executed.

The first step was taken on 26 September, when the Acala team allowed liquidity providers to unstake or withdraw their liquidity from the network. On 29 September, the community referendum for phase 2 was passed, allowing vault owners to manage their debt positions to ensure they were safe before liquidations were enabled. Other services, such as DEX trading, transfers, LDOT instant redeem, xcm, and EVM+ were also enabled through that vote.

Today, the Acala team finally completed phase 3 of their plan, enabling oracles, liquidation, and CDP borrowing on the network. The team had previously said that all aUSD tokens in circulation were fully backed 1:1 by crypto assets, noting that all error mints had been recovered with the exception of 5.8 million tokens, which were re-collateralized by the team using their own funds.

Discussion
Related Coverage
Unibot to Compensate Users Affected by Exploit
  • Popular Telegram bot Unibot, which is used to snipe trades on Uniswap, became a victim of a token approval exploit earlier today, when it was switching to a new router.
  • After confirming the exploit, Unibot assured users that their keys and wallets were safe, and that the project will compensate all affected users.
October 31, 2023, 3:01 PM
unlock

Shutterstock

Balancer Exploited After Giving Warning
  • DeFi protocol Balancer confirmed it was exploited almost a week after disclosing a critical vulnerability affecting several of its boosted pools.
  • The platform did its best to mitigate some of the risks but was unable to pause the affected pools, and an estimated $980,000 in DAI were stolen in an attack.
Zunami Protocol’s Stablecoin Pools Exploited, Suffers $2.1M Loss
  • DeFi yield aggregator Zunami Protocol confirmed that a hacker had attacked its “zStables” pools on Curve Finance using a price manipulation exploit.
  • Security firm PeckShield has estimated that over $2.1 million was lost during the attack, while SlowMist said it had informed Zunami of the vulnerability two months ago.