{"id":54521,"date":"2021-12-11T20:11:52","date_gmt":"2021-12-11T18:11:52","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=54521"},"modified":"2025-09-03T20:52:07","modified_gmt":"2025-09-03T17:52:07","slug":"defi-digest-bug-found-in-the-solana-library-monox-and-badgerdao-hacked","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/defi-digest-bug-found-in-the-solana-library-monox-and-badgerdao-hacked\/","title":{"rendered":"DeFi Digest: Bug Found in the Solana Library; MonoX and BadgerDAO Hacked"},"content":{"rendered":"<p>The decentralised finance (DeFi) sector continues to attract heightened attention from crypto investors. ForkLog has compiled the most important developments and news of the past weeks in a digest.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Key metrics for the DeFi sector<\/strong><\/h2>\n<p>Against the backdrop of <a href=\"https:\/\/u1f987.com\/en\/news\/bitcoin-price-falls-below-47000-2\">market correction<\/a>, the total value locked (TVL) in DeFi protocols fell to $246.82 billion. Curve Finance remains the leader, with its TVL rising to $21.26 billion. MakerDAO ($18.16 billion) moved into second, Convex Finance ($15.85 billion) third.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"619\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/tvl-defi-1024x619.png\" alt=\"DeFi Digest: Bug Found in the Solana Library; MonoX and BadgerDAO Hacked\" class=\"wp-image-158836\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/tvl-defi-1024x619.png 1024w, https:\/\/u1f987.com\/wp-content\/uploads\/tvl-defi-300x181.png 300w, https:\/\/u1f987.com\/wp-content\/uploads\/tvl-defi-768x464.png 768w, https:\/\/u1f987.com\/wp-content\/uploads\/tvl-defi.png 1384w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Data: <a href=\"https:\/\/defillama.com\/home\">DeFi Llama<\/a>.<br \/><\/figcaption><\/figure>\n<p>Defi Llama includes in the final figure a basket of tokenised Bitcoins. WBTC, with $12.46 billion, ranked fifth. hBTC, with $1.94 billion, ranked 20th. The combined value of \u2018Bitcoin on Ethereum\u2019 amounted to $15.78 billion.<\/p>\n<p>The TVL in Ethereum applications rose to $163.08 billion. Over the last 30 days the figure is down 11% (11 November it stood at $180.65 billion).<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"263\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/tvl-eth-1024x263.png\" alt=\"DeFi Digest: Bug Found in the Solana Library; MonoX and BadgerDAO Hacked\" class=\"wp-image-158837\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/tvl-eth-1024x263.png 1024w, https:\/\/u1f987.com\/wp-content\/uploads\/tvl-eth-300x77.png 300w, https:\/\/u1f987.com\/wp-content\/uploads\/tvl-eth-768x197.png 768w, https:\/\/u1f987.com\/wp-content\/uploads\/tvl-eth.png 1384w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Data: <a href=\"https:\/\/defillama.com\/chain\/Ethereum\">DeFi Llama<\/a>.<br \/><\/figcaption><\/figure>\n<p>Trading volume on decentralised exchanges (DEX) over the past 30 days stood at $127.1 billion.<\/p>\n<p>Uniswap continues to command dominance in the non-custodial exchange market \u2014 accounting for more than 78% of total turnover. The second-largest DEX by volume is SushiSwap (8.6%), the third is Curve (5.8%).<\/p>\n<h2 class=\"wp-block-heading\"><strong>The Bank of France proposed establishing oversight of the DeFi sector<\/strong><\/h2>\n<p>European regulators <a href=\"https:\/\/u1f987.com\/en\/news\/bank-of-france-calls-for-oversight-of-the-defi-sector\">must establish oversight<\/a> of the DeFi sector. The official spoke on the topic in a speech addressing the challenges for the digital euro.<\/p>\n<p>The official touched on the topic in a speech addressing the challenges for the digital euro.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cFurther important changes are needed. In particular, oversight of the DeFi sector, where normal regulatory frameworks are limited. Issuers and service providers are not easy to identify, protocols operate automatically without intermediaries, and there is no fixed jurisdiction for the services offered,\u201d the official said.<\/p>\n<\/blockquote>\n<h2 class=\"wp-block-heading\"><strong>Omicron token rises more than 900% after new COVID-19 variant emerges<\/strong><\/h2>\n<p>The Omicron (OMIC) token <a href=\"https:\/\/u1f987.com\/en\/news\/omicron-token-surges-tenfold-after-the-emergence-of-a-new-covid-19-variant\">rose more than 900%<\/a> after the emergence of a new COVID-19 variant. On 26 November the WHO named it \u201cOmicron.\u201d<\/p>\n<p>The DeFi project Omicron DAO\u2019s token was issued on the Arbitrum One layer-2 protocol and trades on SushiSwap. According to Twitter, the asset launched on 2 November.<\/p>\n<p>On 27 November OMIC traded around $65, and two days later it reached an all-time high above $689. By 11 December the price had fallen to $63.<\/p>\n<h2 class=\"wp-block-heading\"><strong>LUNA price hits new high as Terra DeFi inflows surge<\/strong><\/h2>\n<p>On 5 December the native token of the Terra protocol (LUNA) <a href=\"https:\/\/u1f987.com\/en\/news\/luna-hits-new-high-as-terra-defi-inflows-surge\">hit a price high<\/a> above $78 (on Binance). The quotes peaked amid substantial inflows into the project\u2019s ecosystem \u2014 TVL in DeFi apps exceeded $14 billion.<\/p>\n<p>At the time of writing LUNA trades near $63. The ecosystem TVL stood at $12.86 billion. <\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"490\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/LUNAUSDT_2021-12-11_19-25-13-1024x490.png\" alt=\"DeFi Digest: Bug Found in the Solana Library; MonoX and BadgerDAO Hacked\" class=\"wp-image-158838\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/LUNAUSDT_2021-12-11_19-25-13-1024x490.png 1024w, https:\/\/u1f987.com\/wp-content\/uploads\/LUNAUSDT_2021-12-11_19-25-13-300x144.png 300w, https:\/\/u1f987.com\/wp-content\/uploads\/LUNAUSDT_2021-12-11_19-25-13-768x368.png 768w, https:\/\/u1f987.com\/wp-content\/uploads\/LUNAUSDT_2021-12-11_19-25-13-1536x735.png 1536w, https:\/\/u1f987.com\/wp-content\/uploads\/LUNAUSDT_2021-12-11_19-25-13.png 1834w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Hourly chart of LUNA\/USDT on Binance. Data: <a href=\"https:\/\/ru.tradingview.com\/symbols\/LUNAUSDT\/\">TradingView<\/a>.<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\"><strong>Bug in Solana library allowed theft of up to $27 million per hour<\/strong><\/h2>\n<p>The error in the Solana SPL protocol library could have allowed funds to be stolen from several major DeFi projects at a rate of roughly $27 million per hour, according to researchers from Neodyme.<\/p>\n<p>The Tulip Protocol yield aggregator, along with the Solend and Larix lending protocols, were at risk. At the peak, the combined TVL of these projects reached $2.6 billion.<\/p>\n<p>Experts noted that the bug was publicly disclosed by one of the auditors of the group, who uses the nickname Simon, back in June. On 1 December he found that the vulnerability had not been fixed. Neodyme suspects that perhaps it was considered harmless.<\/p>\n<p>However, researchers found that the bug allows the theft of \u201chundreds of millions of dollars\u201d via small sums quickly.<\/p>\n<p>Experts contacted the Solana Foundation and eight projects affected. In some cases the suspicions proved incorrect, and Port Finance had fixed the issue months earlier. In Tulip, Solend and Larix they fixed the issue after the outreach, and the Solana team also updated the documentation.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Investments in DeFi<\/strong><\/h2>\n<p>The Panther Protocol, a developer of a privacy-preserving DeFi protocol, <a href=\"https:\/\/u1f987.com\/en\/news\/panther-protocol-raises-more-than-22-million-in-public-token-sale\">raised more than $22 million<\/a> in a public token sale.<\/p>\n<p>The token sale ended in 90 minutes, and the total funding raised by the project reached $32 million.<\/p>\n<p>The Panther Protocol solution uses the <a href=\"https:\/\/u1f987.com\/en\/news\/what-is-a-zero-knowledge-proof\">zk-SNARK<\/a> technology and runs on Ethereum, Polygon, Flare, Songbird, NEAR and Elrond.<\/p>\n<p>The DeFi platform <strong>Earnity<\/strong> <a href=\"https:\/\/u1f987.com\/en\/news\/bitnile-leads-15-million-series-a-for-earnity-defi-platform\">raised $15 million<\/a> in a Series A round. It was led by the BitNile mining company, a subsidiary of Ault Global Holdings.<\/p>\n<p>The round also included the Australia-listed Thorney and the NGC Ventures fund.<\/p>\n<p>Behind Earnity is Domenic Karosa, founder of Banxa Holdings and cofounder of Apollo Capital. The platform, aimed at \u201cdemocratising access\u201d to digital assets, is planned to launch in early 2022.<\/p>\n<h2 class=\"wp-block-heading\"><strong>DeFi hacks and scams<\/strong><\/h2>\n<p>On 30 November a hacker <a href=\"https:\/\/u1f987.com\/en\/news\/defi-platform-monox-loses-31-million-in-hack\">exfiltrated $31 million worth of crypto assets<\/a> from the Polygon-based MonoX platform. The attacker used a swap contract to push the MONO price \u201cto the moon,\u201d and then buy up all the other assets in the pool.<\/p>\n<p>On 2 December the BadgerDAO project <a href=\"https:\/\/u1f987.com\/en\/news\/badger-dao-defi-protocol-hacked-token-falls-about-20\">was hacked<\/a> \u2014 the damage exceeded $120 million. PeckShield experts noted that one of the affected addresses lost roughly 900 BTC (about $50 million at the time). A community member on Twitter <a href=\"https:\/\/u1f987.com\/en\/news\/community-ties-celsius-network-to-the-address-that-lost-900-btc-in-the-badger-dao-hack\">suggested<\/a> the address was linked to Celsius Network.<\/p>\n<p>On 10 December the project team <a href=\"https:\/\/u1f987.com\/en\/news\/badgerdao-team-reveals-details-of-121-million-hack\">announced<\/a> that during the attack hackers used Cloudflare Workers, a service that enables deploying scripts in Cloudflare\u2019s cloud network.<\/p>\n<p>Hackers gained access to the <span data-descr=\"\u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\" class=\"old_tooltip\">API<\/span>, which \u201cwas used for legitimate Cloudflare-managed operations.\u201d They then used the interface to inject malicious scripts via Cloudflare Workers into the HTML file of the app.badger.com site.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/u1f987.com\/en\/news\/defi-2-0-how-next-generation-decentralized-protocols-are-evolving\">DeFi 2.0<\/a>: how the next-generation decentralized protocols are evolving.<\/li>\n<li><a href=\"https:\/\/u1f987.com\/en\/news\/crypto-indices-how-to-invest-in-defi-analogues-of-the-sp-500\">Cryptocurrency indices<\/a>: how to invest in DeFi equivalents of the S&#038;P 500.<\/li>\n<li><a href=\"https:\/\/u1f987.com\/en\/news\/yield-farming-theory-and-practice\">Yield farming<\/a>: theory and practice.<\/li>\n<\/ul>\n<p>Read ForkLog\u2019s Bitcoin news in our Telegram \u2014 crypto news, prices and analytics.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The decentralised finance (DeFi) sector continues to attract heightened attention from crypto investors. ForkLog has compiled the most important developments and news of the past weeks in a digest.<\/p>\n","protected":false},"author":1,"featured_media":54522,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1299,1233],"class_list":["post-54521","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-defi-bulletin","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"22","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/54521","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=54521"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/54521\/revisions"}],"predecessor-version":[{"id":54523,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/54521\/revisions\/54523"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/54522"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=54521"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=54521"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=54521"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}