« 2024 »

654 reports

2024-06-10
Rekt
#UwULend
2024-06-11 • Quill Audits

With $173 million in these pools, the attacker used a 40K ETH flash loan to exploit the system. The protocol was paused soon after the exploit and UwU Lend acknowledged the exploit through their official X handle. The exploit could have been avoided by de…

#UwULend
2024-06-11 • Slowmist

SlowMist analyzed the June 10, 2024 UwU Lend hack as a $19.3 million price oracle manipulation against the protocol's EVM lending pools. The attacker used Tornado Cash-funded flash loans and large CurveFinance swaps to suppress and then inflate sUSDE pric…

#UwULend
2024-06-11 • Ahnlab

The threat actor appears to set the attack targets in advance and distribute malware after continuously collecting relevant information. The malware that is launched through the above process is XenoRAT which can perform various malicious behaviors such a…

#LNK #XenoRAT
2024-06-10 • Rekt

UwuLend was drained of $19.4 million after an attacker manipulated fallback oracle pricing in a series of rapid transactions funded from Tornado Cash. The exploit used flash-loan-driven trades against Curve pool states, allowing borrowing at one sUSDe rat…

#UwULend