Close Menu
    X (Twitter)
    Blockchain Journal
    • News
      • Blockchain News
      • Bitcoin News
      • Ethereum News
      • NFT
      • DeFi News
      • Polkadot News
      • Chainlink News
      • Ripple News
      • Cardano News
      • EOS News
      • Litecoin News
      • Monero News
      • Stellar News
      • Tron News
      • Press Releases
      • Opinion
      • Sponsored
    • Price Analisys
    • Learn Crypto
    • Contact
    • bandera
    Facebook X (Twitter) Instagram
    Blockchain Journal
    Home » Grim Finance hacked; loses $30 million

    Grim Finance hacked; loses $30 million

    0
    By subhasish on December 20, 2021 DeFi News, News
    Tornado Cash Attacker Submits Proposal to Undo the Attack; Community Remains Skeptical
    Share
    Facebook Twitter LinkedIn Pinterest Email

    DeFi project protocol Grim Finance faced a security breach that resulted in net losses of over $30 million. The attack is believed to be one of the largest in the Fantom Blockchain. 

    On December 19, Grim Finance, which is a Smart Yield Optimizer Platform, built on the Fantom Opera, lost $30 million worth of tokens after it was hacked by what the DeFi protocol network stated as an “external attack.” The strike has been deemed as an advanced attack in which the hacker exploited the protocol’s vault contract.

    Grim Finance hacked; loses $30 million

    Re-entrancy attacks

    The perpetrators of the attack hit the protocol’s vault contract through five reentrancy loops, which allowed them to fake five additional deposits into a vault while the platform is processing the first deposit. They used a reentrancy loophole which alternatively gave access to add some of the fake deposits into a vault while the initial transaction was processed, deceiving the protocol. The attacker had funded both Ethereum and Binance Smart Chain wallets from Tornado cash by creating a malicious token just an hour before hacking into Grim Finance.  After which the miscreant laundered the funds through stablecoin transfers by bridging the stolen digital asset funds from the Fantom mainnet to the ETH mainnet for USD Coin (USDC) and DAI.

    In a measure to curb future attacks, the DeFi protocol platform has adjourned access to all vaults and recommended users withdraw their funds. The Grim Finance team stated in a tweet that as the exploit happened in the vault contract, all of the vaults and deposited funds were at risk. They further added,

    “We have contacted and notified Circle (USDC), DAI, and AnySwap regarding the attacker address to potentially freeze any further fund transfers,”

    It seems that the swindled tokens have already been routed to other Fantom-based decentralized exchanges such as AnySwap and SpookySwap and exchanged for other tokens such as USD Coin [USDC].

    Reentrancy- a necessity for DeFi

    Grim Finance hacked; loses $30 million

    Rugdoc.io, a decentralized finance security platform, was noted saying that the basic mistake of Grim Finance was not to have a reentrancy guard and provide the user with unwanted entitlements such as to be able to choose their own deposit token. They stated in a tweet to not build multi-billion dollar projects unless they acquired a reentrancy guard. The security platform went on to add,

    “Hopefully all projects can draw lessons from this incident that there is much knowledge most experienced solidity devs have at hand,”

    DeFi Featured Grim Finance
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    subhasish
    • X (Twitter)
    • LinkedIn

    Subhasish Barua is a full-time writer at Blockchain Journal. A post-graduate in Marketing and HR, he joined the cryptocurrency space in 2018 and is an fervent believer of financial freedom.

    Related Posts

    ARK Invest Unloads Coinbase and GBTC Shares by Millions Amid Market Boom

    December 6, 20232 Mins Read

    GBTC Discount Shrinks as Bitcoin Price Surges

    December 6, 20232 Mins Read

    IBM Introduces OSO, Designed for Cold Storage of Digital Assets

    December 6, 20232 Mins Read

    Marathon Digital Produced 1,187 Bitcoins in November and Held 14,025 Unrestricted BTC

    December 5, 20232 Mins Read

    Volume Counterfeiting Allegations Rock RATS Token on Gate Exchange

    December 5, 20232 Mins Read

    A New Era for Cryptocurrency: Zodia Custody’s Integration with Harmonize

    December 4, 20232 Mins Read

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 Blockchain Journal

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.