BSC Based ValueDefi Exploited For $11M by Scammers

ValueDefi, a Binance Smart Chain based Defi protocol has become the latest protocol on BSC to face exploit as scammers managed to exploit its automated market maker (AMM) known as vSwap to steal $11 million worth of crypto assets from non 50/50 pools. This is the second exploit on the ValueDefi within a week as another $6 million were lost due to contract reinitialization.
1/8
Another weekend with a DeFi exploit on BSC, and this time the AMM called vSwap from @value_defi is in trouble.
About $11M was stolen today from non 50/50 pools, in addition to $6M already lost this week as a result of contract reinitialization.
Let’s see what happened👇 pic.twitter.com/Db2mnfCxVn
— Igor Igamberdiev (@FrankResearcher) May 8, 2021
A total of 9 out of the 16 pools were exploited by the scammers and stole the following amounts of different digital assets in the exploited pools,
- 15k BNB – 2.7k
- FARM – 1.7k
- BASv2 – 8.5M
- BDO – 68.3k
- BUSD – 41.4k
- MDG – 945k
- VBOND – 1.2M
- BAC – 11k FIRO
The attackers managed to exploit the Bancor formula where they sent a small amount of a second token to pair addresses and then swapped it for the digital asset in which they wanted to withdraw a small amount of the first token and a lot of the second token. Since Uniswap doesn’t accept pools with a non 50/50 asset ratio, ValueDefi was making use of the Bancor formula.
Due to incorrect use of the Bancor formula, pair contracts consider a swap to be successful The attacker swaps the first tokens for the second in the same pool and repeats this operation until the exploit allows it.
BSC Based Defi Protocol Exploitation on the Rise Amid Surging Popularity
Binance Smart Chain (BSC) has grown in leap and bounds this bull season with hundreds of new Defi projects choosing BSC over ETH, and even the older ones have created cross-chain support. The growing popularity can be understood from the fact that the total value locked in Defi on BSC has crossed the $45 billion mark in comparison to the TVL of Defi on ETH is just over $60 billion. However, the centralized nature of the chain makes it a primary target for scammers and multiple protocols have faced some form of exploitation over the past couple of months.
Many have also accused the Binance team responsible for approving project listing of not doing a thorough analysis of the projects and giving an easy pass for BSC-based listings.
- VanEck Registers Lido Staked Ethereum Trust in Delaware, LDO Up 7%
- Fed’s Lorie Logan Urges Caution on Further Rate Cuts Citing Inflation Risks
- Nasdaq-Listed Fitell Adds Pump.fun’s PUMP To Supplement Solana Treasury
- FG Nexus to Tokenize Stock on Ethereum as SEC Weighs 24/7 Onchain Stock Trading
- Bitcoin Still Undervalued, JPMorgan Forecasts Rally to $165,000
- Pi Network Price at Risk of Another Crash as Mysterious Whale Stops Buying
- Solana Price Eyes $360 After Bullish Retest As VisionSys AI Deploys $2B Treasury Strategy
- Cardano Price Forecast As Hashdex Listing Fuels Optimism For $1.27 Breakout
- BONK Price Rally Ahead? Open Interest Jumps as TD Buy Signal Flashes
- Shiba Inu Price to Surge as Whales Buy and Team Commits to Shibarium Growth
- XRP Price Prediction After Ripple CTO David Schwartz Resigns