SlowMist:Brief Analysis of Value DeFi Protocol Lightning Loan Attack
On November 15, 2020, Value DeFi’s Value DeFi MultiStables vault suffered a lightning loan attack. The SlowMist security team followed up and conducted relevant analysis as soon as possible, and presented it to everyone in a brief form for your reference.
Attack brief analysis
- The attacker fist flash loan 80,000 ETH from Aave.
- The attacker use 80,000 ETH to swap USDT from Uniswap WETH/USDT pool and flash loan a large amount of DAI from Uniswap WETH/DAI pool.
- The attacker use DAI loaned from step two to deposit in ValueMultiVaultBank, ValueMultiVaultBank will convert its asset from bCRV/cCRV to 3CRV. the convert path is bCRV/cCRV -> USDC -> 3CRV. And then mint tokens to attacker according to the amount of the deposited DAI and the total value of 3CRV.
- The attacker swap DAI and USDT to USDC in Curve DAI/USDC/USD pool, increase the price of USDC/3CRV.
- The attacker withdraw 3CRV from ValueMultiVaultBank, because in step 3, because the attacker has increased the price of USDC/3CRV, the bCRV and cCRV can be converted to more 3CRV, which means that the attacker can withdraw the same amount of tokens that minted in step 3 for more 3CRV token.
- Retrun falsh loan to Aave and Uniswap, and burn 3CRV for DAI from Curve DAI/USDC/USD pool.
Conclusion
The ValueMultiVaultBank convert its asset to 3CRV when mint CRV, which depends on the price of USDC/3CRV in DAI/USDC/USDT pool, attacker can stolen assets in ValueMultiVaultBank by controlling the USDC/3CRV price in Curve DAI/USDC/USD pool.
