Introduction
A hacker has successfully drained approximately $455,000 from noncustodial decentralized finance (DeFi) protocol Arcadia Finance by exploiting a code vulnerability.
The Hack and Cause
Blockchain investigator PeckShield alerted about the hack on Arcadia Finance, highlighting the cause as “the lack of untrusted input validation.” The code supposedly lacked a validation mechanism to cross-check unverified inputs. This loophole allowed the hacker to drain funds worth roughly $455,000 from Ethereum (darcWETH) and Optimism (darcUSDC) vaults.
Arcadia Finance’s Response
Arcadia Finance has not yet responded to Cointelegraph’s request for comment about the hack. However, the team told Cointelegraph that the root cause pointed out by PeckShield is wrong.
Arcadia Finance confirmed the hack two hours after PeckShield’s intimation and subsequently paused the contracts to prevent further bleeding of funds.
Ongoing Investigations and Additional Vulnerability
While the investigations are underway, Arcadia’s code houses another vulnerability, which could prove catastrophic for the protocol if exploited. According to PeckShield:
- In addition, there is a lack of reentrancy protection, which allows for the instant liquidation to bypass the internal vault health check.
Most of the stolen funds were from Optimism — approximately 180 Ether (ETH) worth $1,862 — and have been washed via Tornado Cash. However, the stolen tokens on Ethereum — worth over $103,000 at the time of writing — remain parked at the suspected wallet address.
Hacks and Exploits in the Crypto Space
In the second quarter of 2023, hacks and exploits in the crypto space resulted in a cumulative loss of over $300 million.
A report by blockchain security company CertiK showed that a total of 212 security incidents were recorded in the quarter, resulting in a loss of $313,566,528 from Web3 protocols.
Compared with the previous year’s Q2 data, CertiK found that the crypto hacks declined by 58%. Out of the lot, the BNB Smart Chain recorded the most incidents, with 119 incidents leading to $70,711,385 in losses.