Moola Market Milked For $8 Million

avatar

In today's edition of YIYL, (You Invest, You Lose) we head back to the gift that keeps on giving, the DEFI market, with hacktober continuing and prices of shitcoins continuing to lose value no wonder shillfluencers like shitboy crapto are losing their minds online drama farming trying to capture the last bit of clicks to try and shill his affiliate links and paid groups.

Anyway, the butchering continues with CELO a blockchain literally no one gives a fuck about, it's like the Qtum of this cycle, but I guess some suckers are going to fall for it. Celo is just another EVM shitcoin chain that does nothing but mimic Ethereum and try to sucker people into using their bullshit chain by offering lower fees and encouraging fake DEFI projects to drive capital to their system.

Same shit just a different flavour

It's a playbook we've seen used by every layer 1 smart contract shitcoin chain, from BNB, to Solana and Avax. It's honestly just a cereal isle of shit, they all have different flavours, but they all do the same thing, drive soy and high fructose corn syrup down your throat at the cheapest price to the producer.

Then you get joe crypto or joe consumer thinking he is picking something, he is trying new things, he is diversifying, when you're really just trying seven different flavours of shit and finding some retarded justification for it.

moolamarket.png

Moola market gets milked

To illustrate that all these shitcoins, their chains, and their projets are all the same shit, let's take a look at the ghost town that is Celo. If fewer people are using your shit chain and concentrating on the others, you should be able to fly in the clear, but heres the thing, when you copy ETH you bring over its problems too and if there is enough of a kitty to crack your project you will get cracked.

This past week we saw Celo-based borrowing and lending platform, Moola Market, suffer a major exploit when a user was able to adjust collateral prices and run it in their smart contract, remember kids' code is the law. If the smart contract allows it, is it really stealing? The user was then able to access a collection of assets notionally worth around $8.4 million.

https://twitter.com/hackenclub/status/1582489974112686080

After taking a loan of $MOO tokens on the platform, the user manipulated the price of those tokens to borrow a host of other tokens available on the lending protocol.

The project dashboard currently shows 100% utilisation, because the attacker used those marked-up collateral to loan out all funds that were available:

This was a mix of $CELO, $cEUR, $MOO, and $cUSD which amounted to $8.4 million. Not a bad day at the office for that guy and I do wish him well for scoring that bug bounty.

https://twitter.com/Moola_Market/status/1582432297835368449

Same same but different

untitled.gif

This attack was executed similarly to the Mango Markets exploit a week prior and it looks like users are looking to exploit oracles or the variable that should be dictated by the oracle to try and change mark-to-market pricing for collateral.

Moola Market tweeted that they had

"contacted law enforcement and taken steps to make it difficult to liquidate the funds. We are willing to negotiate a bounty payment in exchange for returning the funds within the next 24 hours."

https://twitter.com/FrankResearcher/status/1582448720985014273

Investors are the bug bounty program

Subsequently, five hours later, Moola said that about 93.1% of the exploited funds were returned to a wallet that they own and the user was able to keep the remaining $500,000 as a bug bounty. Still not a bad return for an afternoon's work and well who the fuck is going to use Moola market anytime soon, clearly only a bunch of brain-dead morons and bots.

Sources:

Have your say

What do you good people of HIVE think?

So have at it my Jessies! If you don't have something to comment, "I am a Jessie."

Let's connect

If you liked this post, sprinkle it with an upvote or esteem and if you don't already, consider following me @chekohler and subscribe to my fanbase

Earn Free bitcoin & shopEarn Free Bitcoin & shopClaim Free Bitcoin & Shop
lightning.jpgSmiles.jpgthebitcoincompany.jpg

Posted Using LeoFinance Beta



0
0
0.000
3 comments
avatar

How come they did not audit their code when similar attach happened a few week ago in some other chain. 🤷‍♂️

0
0
0.000
avatar

I never did get on Celo. I was on Fantom and Harmony ONE and boy am I glad I pulled my funds before everything collapsed price wise

0
0
0.000