lazarusholic

Everyday is lazarus.dayβ

Steadefi

2023-08-08, Rekt
https://rekt.news/steadefi-rekt/
#Steadefi

Contents

Steadefi - REKT
Steady lads.
Steadefi lost $1.14M to a compromised deployer address on Monday.
Phishing or an inside job?
The yield farm on Arbitrum and Avalanche announced the exploit:
NOTICE: Steadefi has been exploited and all funds are currently at risk.
The warning came with an on-chain bounty plea to the attacker (though a second message followed, due to a typo in the email provided for negotiation…).
Taking inspiration from the bounty offered following the recent hack of Curve pools, the exploiter has a deadline to return 90% of the funds, keeping the rest as a bounty.
After the deadline, the 10% bounty will be offered to the public as a reward for information leading to a conviction.
Could this a new industry standard for bounty payments?
And will it work?
Credit: Steadefi
According to Steadefi’s own announcement, the deployer address of the protocol was compromised.
As the deployer was the owner of all of the platform’s vault contracts, the attacker was …

IoC

3C5c2F4bCeC51a36494682f91Dbc6cA7c63B514C
9cf71F2ff126B9743319B60d2D873F0E508810dc
C6a194f5F08352C6aD0B9Dcff1C7A5Ef9f8A7802