{"id":58791,"date":"2022-03-15T16:37:47","date_gmt":"2022-03-15T14:37:47","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=58791"},"modified":"2025-09-04T18:36:14","modified_gmt":"2025-09-04T15:36:14","slug":"hacker-exploits-deus-finance-dao-nets-about-3-million","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/hacker-exploits-deus-finance-dao-nets-about-3-million\/","title":{"rendered":"Hacker exploits Deus Finance DAO, nets about $3 million"},"content":{"rendered":"<p>The DeFi protocol Deus Finance DAO was hacked. The hacker&#8217;s profit totaled about $3 million, including 200,000 DAI and 1,101.8 ETH.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">1\/ <a href=\"https:\/\/twitter.com\/DeusDao?ref_src=twsrc%5Etfw\">@deusdao<\/a> Deus Finance was exploited in <a href=\"https:\/\/t.co\/bfYCQcz5rZ\">https:\/\/t.co\/bfYCQcz5rZ<\/a>, leading to the gain of ~$3M for the hacker (The protocol loss may be larger), including 200,000 DAI and 1101.8 ETH<\/p>\n<p>\u2014 PeckShield Inc. (@peckshield) <a href=\"https:\/\/twitter.com\/peckshield\/status\/1503632734299701250?ref_src=twsrc%5Etfw\">March 15, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>PeckShield reported that losses for the project could be higher. The Deus Finance team confirmed the hack but said that the funds were safe and promised to disclose details of the incident later.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">We are aware of the recent exploit reports regarding the <a href=\"https:\/\/twitter.com\/search?q=%24DEI&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$DEI<\/a> lending contract.<\/p>\n<p>Contract has been closed, both <a href=\"https:\/\/twitter.com\/search?q=%24DEUS&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$DEUS<\/a> &amp; <a href=\"https:\/\/twitter.com\/search?q=%24DEI&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$DEI<\/a> are unaffected. Devs are working on a summary of the events, all information will be communicated once we have assessed the full situation.<\/p>\n<p>\u2014 DEUS Finance DAO (@DeusDao) <a href=\"https:\/\/twitter.com\/DeusDao\/status\/1503652836978143242?ref_src=twsrc%5Etfw\">March 15, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>According to PeckShield researchers, the attacker used for the attack <a href=\"https:\/\/u1f987.com\/en\/news\/what-are-flash-loans\">instant loans<\/a>. The breach became possible due to manipulation of the oracle that sets the price in the USDC\/DEI pair, they found.<\/p>\n<p>After the attack, the hacker sent the funds in ETH to the Tornado Cash mixing service.<\/p>\n<p>In the wake of the breach, the protocol&#8217;s native token DEUS fell from above $400 to around $330. By the time of writing, the coin was trading near $330.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh4.googleusercontent.com\/mhkR30K_pmwlOtWC6R0SezTivpcEuLCnEh5vyuPjyzi-P7L5wYCjBKsNExKTKDjW5bPtVVSNsWWALVRLulE2N8pRo6PRfgnAmVpPBqNP1D8Izw_7hR3Cw0UnuqJ5ipXQsPE5-hZ_\" alt=\"\u0417\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u043b Deus Finance DAO \u0438 \u0437\u0430\u0440\u0430\u0431\u043e\u0442\u0430\u043b \u043e\u043a\u043e\u043b\u043e $3 \u043c\u043b\u043d\"\/><figcaption>Source: <a href=\"https:\/\/dexscreener.com\/fantom\/0x2599eba5fd1e49f294c76d034557948034d6c96e\">DEX Screener<\/a>.<\/figcaption><\/figure>\n<p>The DEI token is an <a href=\"https:\/\/u1f987.com\/en\/news\/algorithmic-stablecoins-how-alternatives-to-usdt-and-usdc-are-evolving\">algorithmic stablecoin<\/a> in the Deus Finance ecosystem. The RugDoc team believes that the DeFi protocol&#8217;s losses in this coin amounted to $35 million, but the hacker earned only about $3 million.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">\ud83d\udea8\ud83d\udea8<a href=\"https:\/\/twitter.com\/DeusDao?ref_src=twsrc%5Etfw\">@DeusDao<\/a> was exploited in a flashloan for $2.8m <a href=\"https:\/\/twitter.com\/search?q=%24ETH&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$ETH<\/a>, $200k <a href=\"https:\/\/twitter.com\/search?q=%24DAI&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$DAI<\/a>, and at least $35m of <a href=\"https:\/\/twitter.com\/search?q=%24DEI&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$DEI<\/a><\/p>\n<p>The Rugger himself only got off with ~$3m profit<a href=\"https:\/\/t.co\/KUHCf6lw3s\">https:\/\/t.co\/KUHCf6lw3s<\/a> <a href=\"https:\/\/t.co\/WKTDixWuPU\">pic.twitter.com\/WKTDixWuPU<\/a><\/p>\n<p>\u2014 Rugdoc.io (@RugDocIO) <a href=\"https:\/\/twitter.com\/RugDocIO\/status\/1503640353999491076?ref_src=twsrc%5Etfw\">March 15, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>In February, DeFi projects <a href=\"https:\/\/u1f987.com\/en\/news\/qidao-defi-protocol-loses-13-million-in-hack\">QiDAO<\/a>, <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-attacked-the-defi-protocol-dego-finance\">Dego Finance<\/a> and <a href=\"https:\/\/u1f987.com\/en\/news\/defi-project-titano-finance-on-bsc-lost-1-9-million-in-a-hack\">Titano Finance<\/a> were among the victims of hacker attacks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The DeFi protocol Deus Finance DAO was hacked, with profits of about $3 million, including 200,000 DAI and 1,101.8 ETH.<\/p>\n","protected":false},"author":1,"featured_media":58792,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,1093],"class_list":["post-58791","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-defi"],"aioseo_notices":[],"amp_enabled":true,"views":"14","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/58791","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=58791"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/58791\/revisions"}],"predecessor-version":[{"id":58793,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/58791\/revisions\/58793"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/58792"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=58791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=58791"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=58791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}