{"id":15963,"date":"2022-07-28T14:23:31","date_gmt":"2022-07-28T14:23:31","guid":{"rendered":"https:\/\/bitcoinwisdom.com\/?p=15963"},"modified":"2022-07-28T14:23:37","modified_gmt":"2022-07-28T14:23:37","slug":"solana-based-yield-protocol-nirvana-finance-suffered-a-3-5-million-exploit-through-flash-loans","status":"publish","type":"post","link":"https:\/\/bitcoinwisdom.com\/sv\/solana-based-yield-protocol-nirvana-finance-suffered-a-3-5-million-exploit-through-flash-loans\/","title":{"rendered":"Solana-baserat avkastningsprotokoll, Nirvana Finance, drabbades av en exploatering p\u00e5 $3,5 miljoner genom flashl\u00e5n"},"content":{"rendered":"<ul class=\"wp-block-list\"><li><strong>Nirvana-investerare fick \u00e5rliga procentuella avkastningar (APY) p\u00e5 mer \u00e4n 100 procent p\u00e5 sina l\u00e5sta tokens.<\/strong>&nbsp;<\/li><\/ul>\n<hr>\n\n\n\n<p>Data fr\u00e5n blockchain-s\u00e4kerhetsf\u00f6retaget PeckShield avsl\u00f6jar att hackare utnyttjade en <a href=\"https:\/\/bitcoinwisdom.com\/sv\/solana-sol-price-prediction\/\">Solana<\/a>-baserat DeFi (Decentralized Finance) protokoll, Nirvana, genom flashl\u00e5n och sifonerade ANA-tokens v\u00e4rda $3,5 miljoner. Under de senaste timmarna efter attacken har priset p\u00e5 protokollets governance token (ANA) sjunkit med mer \u00e4n 80 procent.<\/p>\n\n\n\n<p>Enligt v\u00e5r data har Nirvanas stablecoin (NIRV) f\u00f6rlorat sitt status quo och handlas f\u00f6r n\u00e4rvarande till $0.08.<\/p>\n\n\n\n<p>V\u00e4rt att notera, Nirvana-investerare fick \u00e5rliga procentuella avkastningar (APY) p\u00e5 mer \u00e4n 100 procent p\u00e5 sina l\u00e5sta tokens. Detta var m\u00f6jligt eftersom protokollet pr\u00e4glade och f\u00f6rst\u00f6rde ANA-tokens baserat p\u00e5 volymen av tokens transaktioner p\u00e5 protokollet. Innan exploateringen hade anv\u00e4ndare l\u00e5st mer \u00e4n $3,5 miljoner och tokens p\u00e5 protokollet.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/PeckShieldAlert?src=hash&amp;ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">#PeckShieldAlert<\/a> Ser ut som <a href=\"https:\/\/twitter.com\/nirvana_fi?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">@nirvana_fi<\/a> utnyttjas <a href=\"https:\/\/twitter.com\/peckshield?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">@peckshield<\/a>  <br>Exploat\u00f6rer har redan \u00f6verbryggt stulna pengar till Ethereum 0xB9AE2624Ab08661F010185d72Dd506E199E67C09 <a href=\"https:\/\/t.co\/xsByVkbWKi\" rel=\"nofollow\">https:\/\/t.co\/xsByVkbWKi<\/a> <a href=\"https:\/\/t.co\/hXWuLgnViZ\" rel=\"nofollow\">pic.twitter.com\/hXWuLgnViZ<\/a><\/p>\u2014 PeckShieldAlert (@PeckShieldAlert) <a href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1552589510986215425?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">28 juli 2022<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Nirvana; ett offer f\u00f6r dess framg\u00e5ng&nbsp;<\/h2>\n\n\n\n<p>De flesta av bedrifterna p\u00e5 <a href=\"https:\/\/bitcoinwisdom.com\/sv\/hackers-exploit-nft-platform-omni\/\">DeFi-protokoll<\/a> har varit med om snabbl\u00e5n. Det \u00e4r den mest popul\u00e4ra metoden hackare anv\u00e4nder f\u00f6r att komma \u00e5t pengar p\u00e5 de flesta DeFi-system. I juni f\u00f6rlorade Inverse Finance $1,2 miljoner i digitala tillg\u00e5ngar genom ett snabbl\u00e5nshack. Genom samma metod f\u00f6rlorade Beanstalk stablecoin-protokollet $182 miljoner till hackare i april.<\/p>\n\n\n\n<p>Genom detta l\u00e5nesystem kan handlare anv\u00e4nda smarta kontrakt f\u00f6r att f\u00e5 tillg\u00e5ng till os\u00e4krade medel fr\u00e5n l\u00e5ngivare. Detta g\u00f6r det m\u00f6jligt f\u00f6r dem att kringg\u00e5 tredje part innan de kan f\u00e5 tillg\u00e5ng till l\u00e5n. S\u00e4kerhet eller tredje part \u00e4r inte n\u00f6dv\u00e4ndig f\u00f6r s\u00e5dana l\u00e5n. Kontraktet kommer bara att markera transaktionen som slutf\u00f6rd n\u00e4r l\u00e5ntagaren slutf\u00f6r \u00e5terbetalningen till l\u00e5ngivaren.<\/p>\n\n\n\n<p>S\u00e5ledes, om en l\u00e5ntagare misslyckas med ett flashl\u00e5n, kommer det smarta kontraktet att avbryta transaktionen automatiskt och \u00e5terbetala l\u00e5ngivaren. Blockchain explorer-data visar att hackare k\u00f6pte 10 miljoner <a href=\"https:\/\/bitcoinwisdom.com\/sv\/circles-transparency-report-offers-full-glimpse\/\">USDC<\/a> flashl\u00e5n fr\u00e5n Solend (ett utl\u00e5ningsverktyg fr\u00e5n Solana).<\/p>\n\n\n\n<p>De anv\u00e4nde alla l\u00e5n f\u00f6r att pr\u00e4gla eller skapa ANA-tokens. Sedan anv\u00e4nde de Nirvanas treasury-pl\u00e5nbok f\u00f6r att byta ut ANA-tokensen mot $3,5 miljoner USDT. Ok\u00e4nd f\u00f6r statskassan var USDC-depositionen p\u00e5 10 miljoner inte \u00e4kta. D\u00e4rf\u00f6r f\u00f6ll det f\u00f6r tricket och frigjorde likviditet fr\u00e5n sin statskassan.<\/p>\n\n\n\n<p><a href=\"https:\/\/defillama.com\/\" rel=\"nofollow noopener\" target=\"_blank\">DeFi Lama<\/a> data visade att hackarna dr\u00e4nerade hela Nirvanas likviditetspool. S\u00e5ledes sj\u00f6nk dess totala v\u00e4rde till $0.0069 under morgonens europeiska handelssession. Efter exploateringen \u00e5terbetalade hackarna 10 miljoner USDC till Solend. De anv\u00e4nde Wormhole bridge f\u00f6r att \u00f6verf\u00f6ra de stulna medlen till Ethereum-n\u00e4tverket.<\/p>\n\n\n\n<p>Sedan bytte de de stulna medlen till det Ethereum-byggda stablecoin, DAI. Den ber\u00f6mda Wormhole-bron \u00e4r l\u00e4nken mellan Solana och andra n\u00e4tverk f\u00f6r fondsbyte. Blockchain-data visar att hackaren fortfarande beh\u00e5ller DAI v\u00e4rda $3,5 miljoner i sin pl\u00e5nboksadress.<\/p>\n\n\n\n<p>Meddelanden p\u00e5 Nirvanas telegramkanal fr\u00e5n dess administrat\u00f6rer visar att kryptof\u00f6retag har pausat protokollets handelsfunktioner p\u00e5 sina plattformar. Nirvana har inte utf\u00e4rdat n\u00e5got officiellt uttalande ang\u00e5ende exploateringen. Dessutom har den inte svarat p\u00e5 n\u00e5gra mediaf\u00f6rfr\u00e5gningar om h\u00e4ndelsen.<\/p>","protected":false},"excerpt":{"rendered":"<p>Nirvana-investerare fick \u00e5rliga procentuella avkastningar (APY) p\u00e5 mer \u00e4n 100 procent p\u00e5 sina l\u00e5sta tokens.\u00a0<\/p>","protected":false},"author":18,"featured_media":15989,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_editorskit_title_hidden":false,"_editorskit_reading_time":1,"_editorskit_is_block_options_detached":false,"_editorskit_block_options_position":"{}","_uag_custom_page_level_css":"","footnotes":""},"categories":[12],"tags":[1218,306],"class_list":["post-15963","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-nirvana-finance","tag-solana"],"acf":[],"uagb_featured_image_src":{"full":["https:\/\/bitcoinwisdom.com\/wp-content\/uploads\/2022\/07\/3327240.jpg",1280,853,false],"thumbnail":["https:\/\/bitcoinwisdom.com\/wp-content\/uploads\/2022\/07\/3327240-500x330.jpg",500,330,true],"medium":["https:\/\/bitcoinwisdom.com\/wp-content\/uploads\/2022\/07\/3327240-300x200.jpg",300,200,true],"medium_large":["https:\/\/bitcoinwisdom.com\/wp-content\/uploads\/2022\/07\/3327240-768x512.jpg",640,427,true],"large":["https:\/\/bitcoinwisdom.com\/wp-content\/uploads\/2022\/07\/3327240-1024x682.jpg",640,426,true],"1536x1536":["https:\/\/bitcoinwisdom.com\/wp-content\/uploads\/2022\/07\/3327240.jpg",1280,853,false],"2048x2048":["https:\/\/bitcoinwisdom.com\/wp-content\/uploads\/2022\/07\/3327240.jpg",1280,853,false],"trp-custom-language-flag":["https:\/\/bitcoinwisdom.com\/wp-content\/uploads\/2022\/07\/3327240-18x12.jpg",18,12,true]},"uagb_author_info":{"display_name":"Rebecca Davidson","author_link":"https:\/\/bitcoinwisdom.com\/sv\/author\/rebeccad\/"},"uagb_comment_info":0,"uagb_excerpt":"Nirvana investors enjoyed annual percentage yields (APY) of more than 100 percent on their locked tokens.\u00a0","_links":{"self":[{"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/posts\/15963","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/comments?post=15963"}],"version-history":[{"count":0,"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/posts\/15963\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/media\/15989"}],"wp:attachment":[{"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/media?parent=15963"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/categories?post=15963"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitcoinwisdom.com\/sv\/wp-json\/wp\/v2\/tags?post=15963"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}