Wise Lending Experiences DeFi Flash Loan Attack Resulting in $464k Loss
Wise Lending, a prominent Web3 lending application and yield aggregator, recently fell victim to a flash loan attack, resulting in a significant loss of approximately $464,000. This incident has quickly gained attention as one of the major crypto hacks of 2024, shedding light on the vulnerabilities within the decentralized finance (DeFi) sector.
To understand the attack strategy, blockchain security firm PeckShield has revealed that the attacker exploited a flaw in Wise Lending’s share accounting logic. By manipulating a precision issue, the attacker was able to strategically drain the platform’s funds, marking a crucial moment in the DeFi landscape as it faces its first major breach this year.
The attacker employed a flash loan attack, a tactic commonly associated with manipulating oracle prices, to target an almost empty market within Wise Lending and artificially inflate the share price. Seizing the opportunity, the attacker swiftly borrowed a substantial amount from the lending markets, taking advantage of the manipulated conditions.
The impact of the attack is staggering, as revealed by Etherscan data. The attacker managed to acquire $9,000 worth of USD Coin (USDC), $2,000 worth of Tether (USDT), $5,000 worth of Dai (DAI), 18.51 Wrapped Ether (WETH) valued at $47,694, and various tokens linked to Pendle Finance. Furthermore, the attacker utilized the flash loan to borrow 1,110 Lido Staked Ether (stETH) tokens from the Aave (AAVE) lending protocol, totaling around $2.9 million.
Initially, reports suggested that a new Pendle Finance derivative token was responsible for the attack. However, some blockchain researchers hinted at a potential connection to a 7% price swing between stETH and ETH within a specific pool, possibly triggered by an AAVE v2 stETH flash loan.
In response to the breach, Wise Lending has implemented preventive measures, prompting the wider crypto community to closely monitor further developments. This incident in early 2024 serves as a stark reminder of the challenges involved in securing DeFi platforms.
As the cryptocurrency space grapples with its most significant security breach of the year, the Wise Lending flash loan exploit serves as a wake-up call for the entire DeFi community.