{"id":52224,"date":"2020-11-12T09:01:40","date_gmt":"2020-11-12T09:01:40","guid":{"rendered":"https:\/\/www.cryptocabaret.com\/?p=52224"},"modified":"2020-11-12T09:01:40","modified_gmt":"2020-11-12T09:01:40","slug":"report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing","status":"publish","type":"post","link":"https:\/\/www.cryptocabaret.com\/?p=52224","title":{"rendered":"Report: Blockchain Price Oracle Manipulation Produces Millions in Losses, Shows No Signs of Slowing"},"content":{"rendered":"<p><img decoding=\"async\" width=\"696\" height=\"392\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-768x432.jpg\" class=\"attachment-medium_large size-medium_large wp-post-image\" alt=\"Report: Blockchain Price Oracle Manipulation Produces Millions in Losses, Shows No Signs of Slowing\" loading=\"lazy\" srcset=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-768x432.jpg 768w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-300x169.jpg 300w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-1024x576.jpg 1024w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-696x392.jpg 696w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-1068x601.jpg 1068w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-747x420.jpg 747w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-190x107.jpg 190w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-380x214.jpg 380w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing-760x428.jpg 760w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing.jpg 1280w\" sizes=\"auto, (max-width: 696px) 100vw, 696px\"><\/p>\n<p><strong>On November 9, a writer from the website samczsun.com published a report that shows a number of issues with price oracle manipulation stemming from a few blockchain applications. The researcher notes that price oracle manipulation has resulted in \u201cover $30 [million] in losses so far.\u201d<\/strong><\/p>\n<p>According to the researcher from <a href=\"https:\/\/samczsun.com\/\">samczsun.com<\/a> there\u2019s been a substantial amount of price oracle manipulation in 2020. On Monday, he <a href=\"https:\/\/twitter.com\/samczsun\/status\/1325890420111511553\">tweeted<\/a>: \u201cPrice oracle manipulation has resulted in over 30MM of losses so far and it shows no signs of slowing.\u201d The tweet was also retweeted by the ethereum.org Twitter handle\u2019s 500k followers. The tweet from @samczsun also leads to a blog post written on the researcher\u2019s web portal called: \u201cSo you want to use a price oracle.\u201d<\/p>\n<p>In the article, he explains that during the end of 2019 he published a post called \u201c<a href=\"https:\/\/samczsun.com\/taking-undercollateralized-loans-for-fun-and-for-profit\/\">Taking undercollateralized loans for fun and for profit<\/a>\u201d and the post explained how he could attack ETH-based decentralized applications (dapps). The dapps he wrote about specifically rely on price oracle data for a number of crypto assets.<\/p>\n<p>\u201cIt\u2019s currently late 2020 and unfortunately numerous projects have since made very similar mistakes,\u201d samczsun.com\u2019s post stresses. \u201cWith the most recent example being the Harvest Finance hack which resulted in a collective loss of 33MM USD for protocol users.\u201d<\/p>\n<p>Basically an oracle is a protocol that can record both onchain and off-chain data and submits the data into a blockchain like Ethereum. These oracles are used in smart contracts, <a href=\"https:\/\/news.bitcoin.com\/decentralized-exchanges-that-use-automated-market-makers-now-represent-93-of-the-market\/\">automated market makers<\/a> (AMM), trading platforms, and one of the popular ETH-based oracles is Chainlink. The report on vulnerabilities says that developers are aware of some of the issues tethered to oracles but \u201cprice oracle manipulation is clearly not something that is often considered.\u201d<\/p>\n<p>The blog post adds:<\/p>\n<blockquote>\n<p><em><strong>Conversely, exploits based on reentrancy have fallen over the years while exploits based on price oracle manipulation are now on the rise. <\/strong><\/em><\/p>\n<\/blockquote>\n<p>The blog post however isn\u2019t just criticisms and samczsun.com\u2019s editorial features an introduction to oracles, oracle manipulation, and how to mitigate against exploitation. Further, the post discusses six vulnerabilities that have taken place in the past.<\/p>\n<p>For example, the post mentions <a href=\"https:\/\/samczsun.com\/taking-undercollateralized-loans-for-fun-and-for-profit\/\">undercollateralized loans<\/a>, the Synthetix sKRW oracle malfunction, the yVault bug, Synthetix <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/MKR\" target=\"_blank\" rel=\"noopener noreferrer\">MKR<\/a> <a href=\"https:\/\/www.reddit.com\/r\/ethfinance\/comments\/eexbfa\/daily_general_discussion_december_24_2019\/fby3i6n\/\">manipulation<\/a>, the Harvest Finance hack, and the Bzx hack as well.<\/p>\n<figure aria-describedby=\"caption-attachment-423112\" class=\"wp-caption aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"wp-image-423112 size-full\" title=\"Report: Blockchain Price Oracle Manipulation Produces Millions in Losses, Shows No Signs of Slowing\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2020\/11\/image-29.png\" alt=\"Report: Blockchain Price Oracle Manipulation Produces Millions in Losses, Shows No Signs of Slowing\" width=\"950\" height=\"1007\" srcset=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2020\/11\/image-29.png 950w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/image-29-283x300.png 283w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/image-29-768x814.png 768w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/image-29-696x738.png 696w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2020\/11\/image-29-396x420.png 396w\" sizes=\"auto, (max-width: 950px) 100vw, 950px\"><figcaption class=\"wp-caption-text\">An illustration of the Synthetix <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/MKR\" target=\"_blank\" rel=\"noopener noreferrer\">MKR<\/a> manipulation. Photo via Samczsun.com.<\/figcaption><\/figure>\n<p>Samczsun.com\u2019s research also summarizes the Harvest Finance issues that took place on October 26, 2020.<\/p>\n<p>\u201cThe attacker deflated the price of USDC in the Curve pool by performing a trade, entered the Harvest pool at the reduced price,\u201d the findings state. \u201c[The attacker] restored the price by reversing the earlier trade, and exited the Harvest pool at a higher price. This resulted in over 33MM USD of losses.\u201d<\/p>\n<p>The report concludes that \u201cprice oracles are a critical, but often overlooked, component of defi security.\u201d The article highlights that there are plenty of ways that dapps can shoot themselves in the foot if they overlook some of these problems. \u201cReading price information during the middle of a transaction may be unsafe and could result in catastrophic financial damage,\u201d the research post says.<\/p>\n<p><em><strong>What do you think about the millions lost from blockchain-based price oracles so far? Let us know what you think in the comments section below.<\/strong><\/em><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/news.bitcoin.com\/report-blockchain-price-oracle-manipulation-produces-millions-in-losses-shows-no-signs-of-slowing\/\">Report: Blockchain Price Oracle Manipulation Produces Millions in Losses, Shows No Signs of Slowing<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/news.bitcoin.com\/\">Bitcoin News<\/a>.<\/p>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener noreferrer\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On November 9, a writer from the website samczsun.com published a report that shows a number of issues with price oracle manipulation stemming from a few blockchain applications. The researcher notes that price oracle manipulation has resulted in \u201cover $30 [million] in losses so far.\u201d According to the researcher from samczsun.com there\u2019s been a substantial [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":52225,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[309],"tags":[],"class_list":["post-52224","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/52224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=52224"}],"version-history":[{"count":0,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/52224\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/media\/52225"}],"wp:attachment":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=52224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=52224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=52224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}