🔍 What The Hack Series - Part 3: The Cypher Protocol Hack (August 2023) 🔍
In August 2023, Solana-based Cypher Protocol experienced a significant exploit, resulting in an estimated $1 million loss. This vulnerability allowed an attacker to manipulate Cypher’s marginal lending and borrowing system, exploiting smart contract flaws to take unauthorized loans. Here’s a breakdown:
🚨 Inside the Attack
Cypher’s protocol uses primary and sub-accounts for lending, borrowing, and trading. Each sub-account is cross-collateralized by default, but a code error prevented the main account from recognizing changes when switching to an isolated state. Additionally, faulty margin checks and inactive oracle price feeds let the attacker borrow funds without proper backing.
⚠️ Lessons Learned
This hack exposes the critical need for security audits. Both business logic and implementation errors can leave protocols vulnerable, highlighting the importance of rigorous checks before launch. However, many times, they’re just not enough!
🛡️ Stay Protected
DeFi risks are real, which is why Amulet V3 offers smart contract covers to protect against vulnerabilities like this. Explore Amulet V3 and safeguard your assets 👉 https://t.co/1EEwZrREuN https://t.co/JsRxmufTam