U.S. Markets closed
  • S&P Futures

    3,826.50
    +1.00 (+0.03%)
     
  • Dow Futures

    30,947.00
    +14.00 (+0.05%)
     
  • Nasdaq Futures

    11,677.50
    +3.25 (+0.03%)
     
  • Russell 2000 Futures

    1,738.60
    +0.30 (+0.02%)
     
  • Crude Oil

    111.12
    -0.64 (-0.57%)
     
  • Gold

    1,823.10
    +1.90 (+0.10%)
     
  • Silver

    20.78
    -0.03 (-0.12%)
     
  • EUR/USD

    1.0533
    +0.0008 (+0.0737%)
     
  • 10-Yr Bond

    3.2060
    +0.0120 (+0.38%)
     
  • Vix

    28.36
    +1.41 (+5.23%)
     
  • GBP/USD

    1.2203
    +0.0019 (+0.1550%)
     
  • USD/JPY

    136.0430
    -0.0850 (-0.0624%)
     
  • BTC-USD

    20,352.16
    -232.12 (-1.13%)
     
  • CMC Crypto 200

    441.22
    -8.85 (-1.97%)
     
  • FTSE 100

    7,323.41
    +65.09 (+0.90%)
     
  • Nikkei 225

    26,760.55
    -288.92 (-1.07%)
     

Impossible Finance Loses $500,000 in Latest DeFi Flash Loan Attack

·2 min read

The latest decentralized finance (DeFi) protocol to join the long list of exploited Binance Smart Chain projects is Impossible Finance.

Another day, another DeFi flash loan exploit on Binance Smart Chain. This time around, the victim is the multi-chain incubator project Impossible Finance.

According to a post on the project’s Twitter and Telegram feeds on June 21, there was a flash loan attack on Impossible Finance’s liquidity pool that resulted in a loss of around 230 ETH.

“Earlier today there was a flash loan attack on our IF token. We are working with PeckShield, Watchpug, and other community whitehats to investigate the situation and will have a detailed event report.”

Copycat DeFi Attacker

SushiSwap core developer Mudit Gupta noted that it was a similar attack to the one that exploited the BurgerSwap protocol in late May. Back then, the attacker managed to drain over $7 million from the protocol executing flash loans with a fake token.

Security firm WatchPug explained that the hacker made multiple swaps in a row at about the same price and drained the liquidity pool, adding “which is usually impossible” due to slippage.

A vulnerability in the pool’s smart contract enabled the attacker to perform multiple swaps of the protocols native token IF to BUSD and then to BNB to repay the flash loan.

The Impossible Finance team confirmed on Telegram that it had allocated an insurance fund to compensate liquidity providers,

“We have also prepared an insurance fund to ensure that your funds are safe and remain our number one priority. All users funds who deposited into liquidity pools (“LPs”) PRIOR to the attack will be 100% compensated.”

Impossible Finance raised $7 million from an extensive list of venture capital and angel investors in early June in order to build a BSC incubator platform for multi-chain DeFi startups.

It joins the long list of BSC-based DeFi protocols that have been exploited this year which includes PancakeBunny, Cream Finance, bEarnBogged Finance, Uranium Finance, Meerkat Finance, SafeMoon, Spartan Protocol, and Belt Finance.

BSC itself claimed that the wave of attacks was organized and targeted.

IF token price tanks

The IF token has predictably collapsed today, tanking over 60% from a high of $2.80 this time on June 21 to as low as $0.14 before recovering to just over $1 at the time of press.

According to CoinGecko, IF is currently trading 86% lower than its June 19 all-time high of $7.61.