Moonwell suffers governance attack, with attackers spending $1,800 to push malicious proposals, risking $1.08 million in funds.

Gate News: On March 26, the DeFi lending protocol Moonwell was subjected to a governance attack, putting over $1 million of user funds at risk. On-chain observers detected that an attacker spent approximately $1,800 to purchase about 40 million MFAM tokens and used their voting power to push a malicious governance proposal. The proposal aimed to transfer control of the protocol’s core contract to an address controlled by the attacker. The entire attack, from purchasing tokens and creating the proposal to passing the vote, took only about 11 minutes. The proposal has currently been enacted in Moonwell’s Moonriver deployment environment, involving the transfer of control over 7 lending markets, auditing firms, and oracles. If executed, the attacker could drain the protocol’s funds, risking the loss of approximately $1.08 million of user assets. Moonwell is a lending protocol based on Moonbeam and Moonriver, part of the Polkadot ecosystem. Previously, in February this year, the protocol experienced a bad debt of about $1.78 million due to an oracle configuration error.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

1inch Liquidity Provider TrustedVolumes Under Attack on Ethereum, $5.87M Stolen

According to Blockaid, the 1inch market maker and resolver TrustedVolumes is under attack on Ethereum as of May 7. The vulnerability was detected in Blockaid's security monitoring system within a custom RFQ trading agent contract controlled by TrustedVolumes. Attackers have extracted

GateNews1h ago

Project Eleven Warning: 6.90 million BTC face a quantum threat, with Q-Day earliest in 2030

In the post-quantum security space, the startup Project Eleven published a report on May 6, warning that the earliest possible arrival of the quantum computers surpassing the critical point of modern cryptography (Q-Day) may be as early as 2030, with a probability exceeding 50% for occurrence by 2033. The report also estimates that, under certain conditions, around 6.9 million bitcoins face potential quantum attack risk, and it calls on the cryptocurrency ecosystem to accelerate the anti-quantum migration process.

MarketWhisper1h ago

Project Eleven Warns Q-Day Could Arrive as Early as 2030

Project Eleven published a report on Wednesday proposing that the inflection point of quantum computers breaking modern encryption, often referred to as "Q-Day," could come as early as 2030, with a breakthrough described as "more likely than not" by 2033. The startup, focused on post-quantum securit

CryptoFrontier2h ago

NYSE Tokenization Partners Warn of Synthetic Stock Token Risks

NYSE tokenization partners have issued a warning that synthetic stock tokens could mislead retail traders through misrepresentation of underlying equities and unauthorized use of company names, according to the warning. Concerns About Offshore Synthetic Tokens The partners identified three key ri

CryptoFrontier6h ago

Project Eleven Warns Q-Day Could Hit as Early as 2030, With 6.9M Bitcoin at Risk

According to Project Eleven's Wednesday report, quantum computers could break modern encryption as early as 2030, with the startup estimating that 6.9 million bitcoins, worth more than $560 billion, could be exposed to quantum risk under certain conditions. The post-quantum security-focused startup

GateNews8h ago

Ekubo Protocol Drained of $1.4M in WBTC Through Approval-Based Exploit

According to blockchain security firm Blockaid, Ekubo Protocol lost approximately $1.4 million in wrapped bitcoin (WBTC) recently after attackers exploited an access control flaw in its EVM swap router contracts. The attackers bypassed payment verification mechanisms to drain funds from wallets

GateNews12h ago
Comment
0/400
No comments