Algorand-Based Tinyman AMM Exploited for $3.5Mđź’°

QuillAudits - Web3 Security 🛡️
QuillHash
Published in
3 min readJan 8, 2022

Events Under the Spotlight

Stobox TOKEN Hacked

  • Stobox, a technology and consulting company’s $STOX token’s deployer address, which was the same for Ethereum and Binance Smart Chain, was compromised resulting in stolen and liquidated funds.

MetalandDAO Rugged Investors

  • MetalandDAO, a project listed on PancakeSwap on BSC, rugged investors for more than 40 wBNB. Stolen funds were swapped for ETH.

NFT project Bored Bunny Rug Pulled Investors

  • Bored Bunny, an NFT project that’s collection of 4,999 unique NFTs on OpenSea, rug pulled investors for 2,000 ETH within hours of launch.
  • Later, about 800 ETH were transferred to Binance exchange.

Arbix Finance Rug Pulled investors

  • Arbix Finance rug pulled investors for more than $10 Million in BUSD, BNB, BTCB, CAKE, USDC, anyUSDT and anyETH.
  • The stolen funds were sent to Ethereum using AnySwap.

Algorand’s DeFi platform Tinyman exploited for $3.5M

  • Tinyman, an Algorand blockchain based trading platform was attacked, that cost the DeFi platform $3.5 Million.
  • The attacker exploited unknown vulnerabilities, also known as 0 dayvulnerabilities in the Tinyman smart contracts.
  • This provided unauthorised access to the platform’s liquidity pools to withdraw tokens which resulted in an increased volatile market aftermath the attack.
  • The hacker burned and swapped Pool Tokens multiple times to steal locked funds off the platform.
  • The Tinyman team later disclosed some information about the hack.

Vesper Finance exploited for $1M

  • Vesper Finance was exploited during beta testing of its new beta Vesper Rari Fuse liquidity pool.
  • The attacker manipulated an oracle to drain $1 Million DAI, ETH, wBTC and USDC from the beta lending pool by using an out-of-market pair of VUSD/USDC.

To the Numerophiles out there 🔢

Crypto scammers took a record $14 billion in 2021. — Source

Interest in Bitcoin and Ethereum Slides According to Google Trends Data, NFT Queries Skyrocket. — Source

Google Trends scores for the terms “bitcoin,” “ethereum,” and “cryptocurrency.” Screenshot taken on January 7, 2022.

More From the Editor’s Desk

Owing to the large client base and their influence in different industries, the big four, namely — Deloitte, Ernst & Young (EY), Price Waterhouse Cooper LLP (PwC) and KPMG have become among the most active members of the blockchain revolution over the last couple of years.

Checkout how the inclination of Big Four towards auditing is highlighting the importance of auditing in blockchain projects.

Read Here

Word on the Block

Versus Series

Fungible Tokens 🆚 Non-Fungible Tokens..!

Catch out the Key differences between various significant terminologies in the Blockchain.

--

--

QuillAudits - Web3 Security 🛡️
QuillHash
Writer for

6+ Years Securing #Web3: 1M+ Lines Audited. Trusted by 1K+ Clients including StarkWare, Taiko, ZetaChain & Metis. Next-gen audits, KYC & on-chain monitoring.