• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

Hacked Grim Finance’s Auditors Blame New Analyst For Missing the Issue

December 20, 2021
in Crypto News
Reading Time: 3min read
0 0
A A
0
Hacked Grim Finance’s Auditors Blame New Analyst For Missing the Issue
0
SHARES
6
VIEWS
ShareShareShareShareShare
Source: AdobeStock Rawpixelcom

 

Auditors of the decentralized finance (DeFi) platform Grim Finance, which was exploited for USD 30m worth of digital assets on Sunday, claim that a new analyst had conducted the protocol’s audit while their Chief Technology Officer (CTO) was on vacation.

On December 19, Grim Finance informed users that the project was exploited by an external hacker. “The attacker attacked using the function titled beforeDeposit() from our vault strategy entering a malicious token contract,” the team detailed.

Approximately four months ago, Grim Finance was audited by Solidity Finance, a smart contract auditing service. The service said that the issue slipped through their auditing process as they were overwhelmed by the number of projects and busy onboarding new analysts.

“When conducting the Grim Finance audit ~4 months ago, our firm was experiencing rapid growth and hiring. This audit was performed by an analyst who was new to the team & while our CTO was on vacation; and unfortunately this issue was not caught in our peer review process,” Solidity Finance said. 

According to Rugdoc.io, a DeFi watchdog, the Grim Finance hacker used a reentrancy attack, faking additional deposits into a vault while an initial transaction was still going. This way, they managed to withdraw more funds than they had truly deposited into the vault.

Rugdoc.io also criticized Grim Finance over its weak security measures, suggesting that the project should have used a reentrancy guard, which can prevent more than one function from being executed at a time by locking the contract.

“Hopefully all projects can draw lessons from this incident that there is much knowledge most experienced solidity devs have at hand,” Rugdoc.io tweeted. “If you haven’t acquired this yet, don’t build multi-million dollar projects. Don’t get audits from companies which everyone knows are useless.”

Following the hack, the Grim Finance team said that the vaults have been paused “to prevent any future funds from being placed at risk” and recommended users withdraw their funds as all of the vaults and deposited funds are at risk.

“We have contacted and notified Circle (USDC), DAI, and AnySwap regarding the attacker address to potentially freeze any further fund transfers,” the team said.

Meanwhile, the project’s native token GRIM plunged by 81.2% at the early hours of the hack, falling from nearly USD 0.8 to USD 0.15, according to CoinGecko. At 10:07 UTC, the coin is up 3.3% over the past 24 hours, and down 55% over the past week, trading at USD 0.25.

____

Learn more:

– Crypto Security in 2022: Prepare for More DeFi Hacks, Exchange Outages, and Noob Mistakes 
– What Did We Learn from the MonoX Hack?

– Hacked Vulcan Forged Says It Has Refunded ‘the Majority’ of Affected Users
– Hacked AscendEX to Reimburse Users, Says ‘Relatively Small Percentage’ Impacted

– Hacked Bitmart to Compensate Crypto Traders After USD 200M Loss
– Badger DAO Appears to Have Lost Over USD 120M in an Attack 


Credit: Source link

ShareTweetSendPinShare
Previous Post

Is the Narrative about Bitcoin’s 4-Year Halving Cycle Diminishing?

Next Post

Cryptocurrency Firms Starting to See Singapore as Unhospitable, Nikkei Says

Next Post
Cryptocurrency Firms Starting to See Singapore as Unhospitable, Nikkei Says

Cryptocurrency Firms Starting to See Singapore as Unhospitable, Nikkei Says

You might also like

Investors Accuse JPMorgan of Facilitating $328M Crypto Fraud

Investors Accuse JPMorgan of Facilitating $328M Crypto Fraud

March 13, 2026
$HYPE to Hit $150 By August Says Admitted “Hype Man” Arthur Hayes

$HYPE to Hit $150 By August Says Admitted “Hype Man” Arthur Hayes

March 10, 2026
Bitcoin Short Bets Surge—Will Bears Get Squeezed?

Bitcoin Short Bets Surge—Will Bears Get Squeezed?

March 10, 2026
SharpLink Gaming Stock Reports $734M Loss Tied to ETH Holdings

SharpLink Gaming Stock Reports $734M Loss Tied to ETH Holdings

March 10, 2026
Altcoins Approach Historic Stress Levels as 38% of Tokens Near All-Time Lows

Altcoins Approach Historic Stress Levels as 38% of Tokens Near All-Time Lows

March 10, 2026
Michael Saylor’s Strategy Acquires $1,280,000,000 in Bitcoin, Tom Lee’s Bitmine Buys $122,000,000 in Ethereum

Michael Saylor’s Strategy Acquires $1,280,000,000 in Bitcoin, Tom Lee’s Bitmine Buys $122,000,000 in Ethereum

March 10, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

What To Expect Before The Run-Up Above $100,000

What To Expect Before The Run-Up Above $100,000

March 14, 2026
Bitcoin Market Remains Pessimistic Despite Price Reclaiming $70k

Bitcoin Market Remains Pessimistic Despite Price Reclaiming $70k

March 14, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.