Team Finance exploited for $14.5M during protocol migration despite contract audit

Published at: Oct. 27, 2022

On Thursday, decentralized finance, or DeFi, lockup protocol Team Finance said over $14.5 million worth of tokens were exploited though the Uniswap V2 to V3 migration function on its platform. As told by blockchain security firm PeckShield, the hacker transferred liquidity from Uniswap V2 assets on Team Finance to an attacker-controlled V3 pair with skewed pricing. By locking tokens to the contract, the attacker bypassed existing validation mechanisms and pocketed the huge leftovers as refund for profit. 

Uniswap V3 was designed with better efficiency for liquidity providers (LP) than V2 on its decentralized exchange. However, V2 smart contracts are still operational, and users must interact with a migration smart contract to migrate their LP assets from V2 to V3. PeckShield estimates that the initial attack vector required for this interaction costed just 1.76 Ether (ETH).

Drained assets include USD Coin, CAW, TSUKA, and KNDA tokens, as the liquidity pools were 'moved' to Uniswap V3. On the decentralized exchange, some of the affected tokens, such as CAW, suffered steep price declines due to the exploit and subsequent liquidity crunch. 

Team Finance says that the smart contract had been previously audited and urged the hacker to "get in contact with us for a bounty payment." As a result, developers have temporarily paused all activity on the protocol and claim that all funds on the platform are not at risk of further exploit. Founded in 2020, Team Finance and its parent firm TrustSwap provides token liquidity locking and vesting services for project executives. The protocol claims to have $3 billion secured across 12 blockchains.

With vesting periods longer than Liz Truss' employment history... https://t.co/1Wo6RwqsFg can keep you safer than the British economy this winter!Lock your tokens today and keep the Truss away. pic.twitter.com/QYPhjg7HQo

— Team Finance (@TeamFinance_) October 21, 2022
Tags
Related Posts
‘DeFi done right’: Layer-one protocol launches mainnet
A decentralized finance protocol has launched its mainnet — describing it as a crucial step on the journey to a frictionless financial future. Radix, which describes itself as a platform for smart money, is also launching Instapass with its Olympia mainnet — an optional user and developer service that delivers the world’s first single sign-on solution for building compliant DeFi. The Radix mainnet is being positioned as a generational improvement in the history of decentralized ledger computing — and one that delivers 100 times more executional efficiency than the Ethereum Virtual Machine. This comes hot on the heels of the …
Decentralization / July 29, 2021
The remaining steps to mainstream institutional investment
It has been said that you only get one chance to make a first impression. Perhaps the best example of this old adage is the cryptocurrency space. From exit scams and money laundering, to unaudited code and high carbon footprints, the crypto landscape has spent the better part of the past decade scrubbing itself of its infamous past. For many, the sanitizing of the decentralized ecosystem was inevitable — simply a matter of when, not if. This mindset hindered the sense of urgency that should have been on display and may have ultimately contributed to the skepticism exhibited by mainstream …
Adoption / May 29, 2021
Supply chain tokens see triple-digit gains as the global economy recovers
Over the last few weeks, blockchain projects focused on supply chains and logistics have seen tremendous growth as the coronavirus-induced economic gridlock begins to loosen and future concerns related to the global pandemic subside. Three logistics projects that have benefited from the improving economic outlook are OriginTrail, Waltonchain and Wabi. Since early February, each has seen its token price increase by up to 300%. TRAC/USD OriginTrail is a self-described “ecosystem dedicated to making global supply chains work together by enabling a universal, collaborative and trusted data exchange.” The project was established in 2011 with the goal of providing enterprise users …
Technology / March 15, 2021
KuCoin Labs Launches $100 Million Venture Capital Fund To Empower Early-Stage Metaverse Projects
KuCoin Labs, the company behind the world's sixth-largest cryptocurrency exchange by trading volume with more than 500 crypto assets listed, announced on Wednesday that it would be launching a $100 million metaverse fund for early-stage projects. The money is also available for entities that develop blockchain-based games, nonfungible tokens, and decentralized applications. In addition, Kucoin will also provide business incubation services, branding, incentives, and business partnerships for developers selected into the fund. Johnny Lyu, CEO of Kucoin, said the following in a prepared statement obtained by Cointelegraph: "KuCoin Metaverse Fund will be launched to accelerate the evolution of the Internet …
Adoption / Nov. 17, 2021
‘We want to build Minterest as a fairer financial system,’ says CEO Josh Rogers
Decentralized finance (DeFi) protocols have gained significant traction in the cryptocurrency sector, with a total value locked surpassing $271 billion, based on data from DefiLlama. One exceptionally popular category of DeFi services is that of decentralized borrowing and lending, where users can pledge their crypto as collateral and take out stablecoin loans (or vice versa) to pay for everyday expenses while their investment continues to grow. Such protocols typically charge a spread or difference between deposit and lending rates as a service fee. But then there are protocols like Minterest that seek to distribute a vast majority, if not all, …
Decentralization / Nov. 18, 2021