Crypto security researchers have successfully thwarted a sophisticated backdoor exploit that silently threatened thousands of smart contracts for months, preventing the potential theft of over $10 million in decentralized finance (DeFi) assets. The vulnerability, discovered by Venn Network, targeted uninitialized ERC-1967 proxy contracts, allowing attackers to inject malicious code before proper setup.
Key Takeaways
-
Sophisticated Exploit: The attack vector was highly sophisticated, targeting uninitialized ERC-1967 proxy contracts across various EVM chains.
-
Hidden Backdoor: Attackers injected malicious contract implementations, creating a well-hidden and unremovable backdoor that could have been exploited at any time.
-
Collaborative Rescue: A rapid 36-hour operation involving multiple security researchers successfully secured at-risk funds.
-
Proactive Measures: Several DeFi protocols were able to secure their assets during the operation, preventing potential losses.
-
Berachain's Response: Berachain, one of the affected protocols, promptly paused its incentive claim contract and transferred funds to a new, secure contract, ensuring no user funds were lost.
DeFi Disaster Averted: How Researchers Neutralized a $10M Backdoor
On Thursday, Venn Network researcher Deeberiroz revealed on X that a critical backdoor exploit had been active for months, posing a significant threat to the DeFi ecosystem. The vulnerability allowed attackers to front-run contract deployments and inject malicious implementations, creating a hidden and persistent backdoor in thousands of contracts. This exploit could have enabled attackers to take over vulnerable contracts at any point, with malicious activity becoming nearly invisible once the contracts were initialized.
The 36-Hour Rescue Operation
Upon discovering the vulnerability on Tuesday, Venn Network initiated a rapid 36-hour rescue operation. This collaborative effort involved several prominent security researchers, including Pcaversaccio, Dedaub, and Seal 911. Their coordinated actions focused on evaluating affected contracts and securing vulnerable funds before attackers could exploit them. The success of the operation was largely due to the researchers' decision to keep the vulnerability under wraps, preventing the attackers from realizing their scheme had been uncovered.
Potential Perpetrators and Broader Implications
While there is no definitive confirmation, Venn Network security researcher David Benchimol suspects the infamous North Korean hacking group Lazarus may be involved due to the exploit's sophistication and its deployment across every EVM chain. Benchimol noted that the attacker appeared to be waiting for a larger target, suggesting an organized group was behind the operation. Or Dadosh, co-founder and president of Venn Network, emphasized the potential for a much larger catastrophe, stating that tens of millions of dollars were at risk, and the threat could have grown to impact a significant portion of the total value locked (TVL) in affected protocols.
Sources
-
Venn Network Uncovers and Shuts $10M DeFi Backdoor, Cointelegraph.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.