DeFi yield aggregator Zunami Protocol suffers $2.1 million loss in exploit

Quick Take

  • Zunami suffered what appeared to be a price manipulation attack today that resulted in losses of over $2.1 million, security firm PeckShield said.

DeFi yield aggregator Zunami Protocol has been hit with an exploit that may have led to losses of over $2.1 million, according to security firm PeckShield.

PeckShield tweeted on Monday morning in Asia that it had detected an ongoing attack involving two key transactions. PeckShield added that the stolen funds had been washed via mixing service Tornado Cash.

“It appears that zStables have encountered an attack,” Zunami tweeted following PeckShield’s warning, adding that the collateral remained secure and the team has started to investigate.

“Please do not buy zETH and UZD at the moment. [Their] emission has been attacked,” Zunami said.

Zunami did not immediately respond to The Block’s request for comment.

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

Price manipulation attack

PeckShield said in its tweet that the hack was a price manipulation issue, which could be “exploited by donation to incorrectly calculate the price as shown in the following figures.”

Xian Yu, founder of blockchain security firm SlowMist, tweeted today that their firm had identified the vulnerability two months ago. 

“This project fell victim to price manipulation attacks, resulting in a loss of over $2.1 million. The key point is, our system detected this risk two months ago, and we informed them privately in advance,” said Yu, also known as Cos. “Unfortunately, that communication was an unpleasant experience... In hindsight, it appears that this could have been avoided.”


© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Timmy Shen is an Asia editor for The Block. Previously, he wrote about crypto and Web3 for Forkast.News from Taiwan after spending more than three years in Beijing covering finance and current affairs at Caixin Global and Chinese tech at TechNode. His China-related reporting has also appeared in The Guardian. When he's not chasing headlines, you'll find him savoring hot pot and shabu shabu in a Taipei local haunt. Timmy holds an MS degree from Columbia University Graduate School of Journalism. Send tips to [email protected] or get in touch on X/Telegram @timmyhmshen.

Editor

To contact the editor of this story:
Ryan Weeks at
[email protected]