ParaSwap foils hack attempt on Augustus v6 contract

ParaSwap, a decentralized finance (DeFi) aggregator, averted a potential hack targeting its newly launched Augustus v6 contract by swiftly identifying and neutralizing a critical vulnerability.

The Augustus v6 contract, which went live on March 18, aimed to enhance swapping efficiency and reduce gas fees. However, shortly after its launch, ParaSwap discovered a flaw that could have allowed hackers to drain funds from approved transactions.

Taking prompt action on March 20, ParaSwap halted the v6 application programming interface (API) and safeguarded users’ funds through a white hat intervention, preventing any significant loss.

To mitigate further risks, ParaSwap advised all users to revoke permissions granted to the vulnerable Augustus v6 contract until the vulnerability is addressed.

Despite ParaSwap’s proactive measures, the hacker managed to exploit the vulnerability, cashing out approximately $24,000 across four different addresses. In total, 386 addresses were potentially affected, prompting ParaSwap to urge users to report any losses and deactivate support for the vulnerable v6 contract on its user interface (UI).

Source: ParaSwap Notion

ParaSwap assured affected users that funds had been successfully recovered for all addresses and shared details about the refund process.

To ensure safety, ParaSwap recommended users utilize exploit checker services like Revoke to verify the revocation of approvals and minimize the risk of further exploitation.

Rate this article
( No ratings yet )
Chainspot News