Ankr’s Exploit Enabled an Attack on Stablecoin Issuer Helio

  • A hacker targeted a vulnerability in DeFi protocol Ankr to mint trillions of aBNBc tokens, which he eventually swapped for 5 million USDC.
  • The event caused the price of aBNBc to plummet by 99%, which allowed another individual to steal $15.5 million from stablecoin issuer Helio as it did not have up-to-date pricing on aBNBc.
hack

Shutterstock

BNB Chain-based decentralized finance (DeFi) protocol Ankr was hit by a multi-million dollar exploit, which also affected stablecoin issuer Helio Protocol, Ankr said via Twitter on 2 December.

According to the announcement, a hacker targeted a vulnerability in Ankr’s smart contract to mint trillions of aBNBc — a reward token tied to the price of the BNB token — which he then used to drain all of its liquidity from decentralized exchanges on BNB Chain, and get away with roughly $5 million worth of digital assets. Ankr quickly got in touch with exchanges to halt trading of the token, and assured users that the underlying assets on Ankr Staking were safe.

On-chain analytics firm Lookonchain has suggested that the exploit was made possible not only through a vulnerability in Ankr’s smart contract code, but also through a compromised private key, which allowed the attacker to modify the protocol’s smart contracts. Ankr is currently working on resolving the issue, and has proposed to purchase $5 million worth of BNB to compensate liquidity providers that have been affected by the exploit.

The event caused the price of aBNBc to fall by more than 99%, which allowed an opportunistic trader to cash in on the exploit. Lookonchain reported that an individual took advantage of the crashed price of aBNBc to purchase 183,885 tokens with only 10 BNB, which he then deposited to stablecoin issuer Helio Protocol. The platform did not have up-to-date pricing on aBNBc after the Ankr exploit, which allowed the individual to borrow $16 million worth of the HAY stablecoin, which was then swapped for 15.5 million BUSD.

Discussion
Related Coverage
Unibot to Compensate Users Affected by Exploit
  • Popular Telegram bot Unibot, which is used to snipe trades on Uniswap, became a victim of a token approval exploit earlier today, when it was switching to a new router.
  • After confirming the exploit, Unibot assured users that their keys and wallets were safe, and that the project will compensate all affected users.
October 31, 2023, 3:01 PM
unlock

Shutterstock

Balancer Exploited After Giving Warning
  • DeFi protocol Balancer confirmed it was exploited almost a week after disclosing a critical vulnerability affecting several of its boosted pools.
  • The platform did its best to mitigate some of the risks but was unable to pause the affected pools, and an estimated $980,000 in DAI were stolen in an attack.
Kroll Data Breach Compromises FTX, BlockFi Customer Information
  • A cyber security incident at bankruptcy service provider Kroll has resulted in the exposure of “non-sensitive” customer data for claimants involved in the FTX and BlockFi cases.
  • Both companies confirmed that account passwords, systems, and funds remained safe, but warned customers to be on the lookout for phishing scams.