Rubic DEX aggregator hack leads to $1.4m of user funds stolen
Tecnología El pirateo del agregador Rubic DEX conduce al robo de $ 1.4 millones de fondos de usuarios 12/25/2022 Noticias de Bitcoin Ethereum Cross-chain decentralized finance (DeFi) protocol Rubic was compromised, resulting in funds stored in its users addresses being siphoned out and transferred to the hackers. On Dec. 25, Rubic protocol announced that one of its routing contracts was compromised and all contracts would be stopped until the situation is fully understood. The announcement read: The protocols creators also advised their users to revoke contract authorization through the revoke.cash tool. A Twitter thread by blockchain cybersecurity firm PeckShield explains that a vulnerability in the Rubic protocol led to a loss of $1.41 million worth of funds directly from the wallets that authorized its smart contracts. The exploiter address received the funds from the Uniswap decentralized exchange (DEX) in transactions involving the USD Coin (USDC) stablecoin. PeckShied explained that the hack was made possible due to mistakenly adding USDC into supported routers. Furthermore, “a lack of validation in ruterCallNative” also allowed malicious contract use. A quick smart contract analysis with the help of chatGPT suggests that the ruterCallNative function contains numerous potential vulnerabilities, including invalidated input for the “_params” and “_data” parameters. These could allow an attacker to