Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    May 28, 2025

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    May 28, 2025

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    May 28, 2025
    Facebook X (Twitter) Instagram
    Cryptify Now
    • Home
    • Features
      • Typography
      • Contact
      • View All On Demos
    • Typography
    • Buy Now
    X (Twitter) Instagram YouTube LinkedIn
    Cryptify Now
    You are at:Home » DeFi protocol SIR.trading loses entire $355K TVL in exploit 
    Crypto

    DeFi protocol SIR.trading loses entire $355K TVL in exploit 

    James WilsonBy James WilsonMarch 31, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Ethereum-based DeFi protocol SIR.trading, also known as Synthetics Implemented Right, was completely drained in an exploit on Mar. 30, losing all $355,000 of its total value locked.

    TenArmor, a blockchain security firm, was the first to report the attack on a Mar. 30 post o. X. TenArmor flagged several suspicious transactions and pointed out that the stolen funds had been transferred to RailGun, a privacy platform that helps hide transactions.

    Later, security platform Decurity, revealed that the hacker took advantage of a flaw in SIR.trading’s Vault contract, specifically in a function called “uniswapV3SwapCallback.” Decurity referred to the hack as a “clever attack.”

    In another X post, blockchain researcher Yi explained that the vulnerability was due to how the contract verified transactions. Typically, it should only permit transactions from a Uniswap (UNI) pool or other reliable source.

    However, the contract relied on transient storage, a temporary storage technique that was introduced in Ethereum’s (ETH) EIP-1153 upgrade, also known as the Dencun hard fork.

    The problem? Transient storage resets only after a transaction ends, but the contract was manipulated by the hacker overwrite important security data while it was still running. The hacker proceeded to trick the contract into trusting their fake address.

    .@leveragesir got hacked just now for $354k due a clever exploit targeting transient storage in a Vault contract’s uniswapV3SwapCallback. I think this is a groundbreaking case—How did it happen? What was the root cause? Now disappear into the darkness. 🧵👇 https://t.co/WBQDRHGzWl

    — Yi (@SuplabsYi) March 30, 2025

    They did this by brute-forcing a unique vanity address, enabling the contract to register their fake address as a legitimate one. The hacker then utilized a custom contract to drain all the funds from SIR.trading’s vault.

    The anonymous creator of SIR.trading, Xatarrer, acknowledged the attack after it happened, calling it “the worst news a protocol could receive.” They asked for community feedback on what to do next and expressed interest in rebuilding despite the loss.

    Since this attack may be among the first instances of hackers exploiting this new Ethereum feature in the real world, it raises questions regarding the security of transient storage. Security experts caution that unless developers build stronger safeguards into their smart contracts, similar attacks may occur.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMetaplanet issues $13.33M bonds to buy more Bitcoin
    Next Article 50+  ChatGPT Prompts for College Projects | SOLVE NOW! 2025
    James Wilson

    Related Posts

    Dow drops 245 points as Fed minutes spooks Wall Street

    May 28, 2025

    XRP forecast indicates $3.50 next, Unilabs leads Q2 gains

    May 28, 2025

    Bitcoin needs political support to stay protected

    May 28, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Remittix (RTX) hits $4m presale as XRP holders take notice

    February 4, 2025

    Here’s why OKB price spiked 20% today

    February 4, 2025

    iDEGEN price prediction: Is this the AI agent token to buy?

    February 4, 2025

    Gate.io to list CYBRO token on Dec 14 after $7M presale success

    February 4, 2025
    Don't Miss

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    By William GarciaMay 28, 2025

    … ). “The Africa Inexperienced Funding Initiative (AGII) led by the UAE and … 50;…

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    May 28, 2025

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    May 28, 2025

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    May 28, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    About Us
    About Us

    CryptifyNow: Your daily source for the latest insights, news, and analysis in the ever-evolving world of cryptocurrency.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    May 28, 2025

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    May 28, 2025

    Etihad Credit Insurance achieves $4.41bln in insured turnover with 15.7% growth

    May 28, 2025
    Lithosphere News Releases

    Colle AI’s iOS App Launch Brings Multichain NFT Creation to Mobile

    February 4, 2025

    AGII Transforms Web3 Infrastructure with AI-Optimized Smart Contracts

    February 4, 2025

    Colle AI (COLLE) Allocates $250M for AI Tool Development and Liquidity Growth on Solana

    February 4, 2025
    Copyright © 2025

    Type above and press Enter to search. Press Esc to cancel.