Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
DeFi protocol Onyx hit with a $3.2 million exploit, marking second attack within a year

DeFi protocol Onyx hit with a $3.2 million exploit, marking second attack within a year

The Block2024/09/26 16:00
By: The Block
COMP-0.04%ETH-0.19%XOLDTOKEN0.00%
Quick Take DeFi protocol Onyx was hit with a $3.2 million attack on Thursday, according to several security firms. Last October, Onyx suffered a $2.1 million attack exploiting an integer rounding vulnerability and a flash loan attack.

Onyx, a fork of DeFi lending protocol Compound Finance, was hit with a $3.2 million on Thursday, marking the second time the protocol’s smart contract was exploited over the past year. 

According to security firm Fuzzland, a malicious contract was deployed to Onyx at 11:57 a.m., approximately five minutes before the attack occurred. Rival security firms PeckShield and Cyvers also noticed suspicious transactions on OnyxDAO, prior to the hack. 

Cyvers noted most of the losses were in VUSD, a U.S. dollar-denominated stablecoin. The suspected attacker also holds 521 ETH worth about $1.36 million and, according to Cyvers , has hesitated to swap the stolen assets. 

According to PeckShield, which pins the loss at closer to $3.8 million , the attacker attacked a known bug in the forked Compound V2 code base and was able to siphon VUSD, DAI and tether stablecoins, among other cryptocurrencies. 

“Another issue that facilitates the hack is related to the NFTLiquidation contract, which does not properly validate (untrusted) user input and was exploited to inflate the self-liquidation reward amount,” Peckshield wrote on X.

Last October, Onyx suffered a $2.1 million attack exploiting an integer rounding vulnerability and a flash loan attack. 

"Last year was due to a vulnerability introduced when they forked compromised Compound code. This time they introduced a vulnerability themselves via errors in their logic," Fuzzland founder Chaofan Shou told The Block in a message.


Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

PoolX x Bitget Earn SWTCH promotion
Bitget Announcement2025/09/15 16:00
New spot margin trading pair — AVNT/USDT!
Bitget Announcement2025/09/15 09:50

Trending news

More
1
PoolX x Bitget Earn SWTCH promotion
2
New spot margin trading pair — AVNT/USDT!

Crypto prices

More
Bitcoin
Bitcoin
BTC
$115,262.02
+0.11%
Ethereum
Ethereum
ETH
$4,518.08
-1.78%
XRP
XRP
XRP
$2.99
-1.47%
Tether USDt
Tether USDt
USDT
$1
-0.03%
BNB
BNB
BNB
$918.98
-0.82%
Solana
Solana
SOL
$234.25
-2.77%
USDC
USDC
USDC
$0.9998
-0.01%
Dogecoin
Dogecoin
DOGE
$0.2676
-4.14%
TRON
TRON
TRX
$0.3447
-1.18%
Cardano
Cardano
ADA
$0.8623
-3.03%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter