Source: CryptoNewsNet
Original Title: Is an AI hacker targeting old DeFi projects in $5M spree?
Original Link: https://cryptonews.net/news/security/32160032/
A trio of hacks targeting old DeFi projects have stolen approximately $5 million in the past week.
The three projects targeted were all well-known names during DeFi’s 2020-2022 cycle, and the affected contracts are all from abandoned projects, immutable, or no longer maintained.
The similarities have led some to wonder if legacy contracts are being targeted in a concentrated, AI-aided hacking campaign.
Ribbon Finance flip-flops on recovery plan
Last Friday, Aevo (formerly Ribbon Finance) informed users of an oracle-manipulation hack on “legacy Ribbon DOV vaults,” resulting in a $2.7 million loss. The post reassured Aevo users that they weren’t impacted.
In a since-deleted follow-up post, the team announced a plan to reimburse those affected using $400,000 of its own funds, as well as assets from “dormant” users.
However, the Ribbon team walked back the controversial plan a few days later, clarifying that the affected users would, in fact, suffer a 100% loss.
Defunct Rari Capital hijacked
The $2 million Rari Capital hack occurred on December 10, but was not flagged for a week.
In what appears to be a “hijacking of the implementation contract,” the attacker was able to borrow assets "without posting any collateral.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Is an AI hacker targeting old DeFi projects in $5M spree?
Source: CryptoNewsNet Original Title: Is an AI hacker targeting old DeFi projects in $5M spree? Original Link: https://cryptonews.net/news/security/32160032/ A trio of hacks targeting old DeFi projects have stolen approximately $5 million in the past week.
The three projects targeted were all well-known names during DeFi’s 2020-2022 cycle, and the affected contracts are all from abandoned projects, immutable, or no longer maintained.
The similarities have led some to wonder if legacy contracts are being targeted in a concentrated, AI-aided hacking campaign.
Ribbon Finance flip-flops on recovery plan
Last Friday, Aevo (formerly Ribbon Finance) informed users of an oracle-manipulation hack on “legacy Ribbon DOV vaults,” resulting in a $2.7 million loss. The post reassured Aevo users that they weren’t impacted.
In a since-deleted follow-up post, the team announced a plan to reimburse those affected using $400,000 of its own funds, as well as assets from “dormant” users.
However, the Ribbon team walked back the controversial plan a few days later, clarifying that the affected users would, in fact, suffer a 100% loss.
Defunct Rari Capital hijacked
The $2 million Rari Capital hack occurred on December 10, but was not flagged for a week.
In what appears to be a “hijacking of the implementation contract,” the attacker was able to borrow assets "without posting any collateral.