Friday, November 22

This month, DeFi witnessed its biggest hack in 2023, as Euler Finance became the victim of a major exploit which resulted in a total loss of approximately $197 million across multiple currencies. Currently, it appears almost 100% of user deposits are now under the attacker’s control and, at the time of writing, the hacker is not communicating with the Euler team and none of the funds seems likely to be returned.

Projects relying more heavily on Euler were severely affected:

What happened?

Following an incident post-mortem by Omniscia, an auditor used by Euler, it appears a single function enabled the attack. This “donateToReserves” function was added as part of eIP-14 in July 2022 and sat within the system for 8 months despite active bug bounties through both Euler and their auditor.

As a result of flawed logic within this update, the attacker was able to artificially create an unbacked debt token within Euler that would never be liquidated.

This code was audited by Sherlock DeFi prior to launch, who also provided a coverage policy in case of this incident. Sherlock has passed a vote on a $4.5 million payout, $3.3 of which has been paid so far, the first time an audit team has paid this amount for a missed vulnerability.

Once they stopped the direct attack, Euler engaged various crypto-native teams for investigation, as well as UK and US law enforcement, and are continuing to investigate.

While Euler did appear to follow the correct process, offering both bug bounties and having the new code fully audited with cover in place, as we discussed in our risk whitepaper “DeFi Risks – A Primer”, nothing can ever be 100% certain. 

Spool severely reduces such impacts with an effective risk management strategy

Spool was developed specifically to reduce the impact of this kind of “black swan” event on any investor managing their funds within DeFi. While they should be rare, we do see them occur and can be catastrophic for investors who invest 100% via a single protocol.

In this incident, we can see that Spool performed as expected and severely reduced the impact on investors. Spool allows for easy distribution of funds between multiple yield sources, an essential part of an effective risk management strategy. By giving users an easy tool to access multiple yield strategies, Smart Vaults removed the onus on the users to fully study and manually invest in multiple protocols.

As a result, Spool has never exposed itself 100% to a single yield strategy. In this incident, the worst affected Smart Vaults, those designed by users to seek higher (and riskier) yields, were only affected for up to 35%. The lowest affected vault with exposure to Euler strategies (via Harvest or Idle), in comparison, was only affected by 6%. Some vaults had zero exposure and were thus not impacted.

We can see that Spool Smart Vaults performed exactly as expected during the incident. Despite the severity of the attack, and the wide range of protocols affected, the Smart Vault system massively reduced the impact on investors using the platform.

While this is not ideal, it clearly demonstrates the ability of the Smart Vaults to provide tailored risk models and to distribute users’ funds among multiple yield sources. 

Read Also: The Crypto Industry Lost $4B In 2022, Mostly Through Hacks

Share.

Arun Shakyawar is a Tech writer based out of Los Angeles. He holds an Engineering degree in Electronics and communications, and an MBA in marketing. He specializes in TMT. Before writing full-time, Arun worked as a management consultant with leading consulting firms. As a consultant he developed interest in blockchain technology, and now actively tracks blockchain and digital asset markets. Arun can be reached at arun@alexablockchain.com.

Comments are closed.

Exit mobile version