Ethereum DeFi Protocol SIR.trading Loses $355k TVL to Smart Contract Hack

SIR.trading DeFi Protocol Loses Entire $355K TVL in Hack Exploiting Ethereum's Transient Storage Feature

  • Ethereum DeFi protocol SIR.trading lost its entire $355,000 TVL in a March 30 hack targeting a vulnerability in its contract vault.
  • Security firms identified the attack as exploiting Ethereum’s transient storage feature, a relatively new function introduced in the Dencun upgrade.
  • Despite the complete loss of funds, the protocol’s founder indicated plans to continue operations, while the stolen assets were moved through privacy solution Railgun.

Ethereum-based DeFi protocol SIR.trading has suffered a complete loss of funds after Hackers exploited a vulnerability in its smart contract vault. The March 30 attack drained the protocol’s entire total value locked (TVL) of approximately $355,000, leaving the self-described "safer leveraging" platform with zero remaining assets.

- Advertisement -

Security firms TenArmorAlert and Decurity first detected and reported the breach on social media platform X, warning users about the ongoing attack. The protocol’s founder, known as Xatarrer, acknowledged the devastating impact, describing it as "the worst news a protocol could received [sic]" while suggesting the team would attempt to maintain operations despite the setback.

According to Decurity’s analysis, the attack targeted a callback function within the protocol’s vulnerable contract vault. The security firm characterized it as a "clever attack" that exploited Ethereum’s transient storage feature to manipulate the system. The Hacker successfully replaced legitimate Uniswap pool addresses with controlled addresses, effectively redirecting funds to their own wallet.

TenArmorAlert explained that the attacker methodically drained the protocol by repeatedly calling the compromised callback function until the entire TVL was emptied. The security firm later reported that the stolen assets were deposited into an address funded through Railgun, an Ethereum privacy solution, with SIR.trading’s founder reportedly reaching out to Railgun for assistance.

The exploit may indicate broader security concerns with Ethereum’s transient storage functionality. SupLabsYi from security firm Supremacy provided additional technical details, suggesting the hack might demonstrate vulnerabilities in this relatively new Ethereum feature introduced during the Dencun upgrade in 2023. Transient storage was designed to enable temporary data storage with lower gas fees than regular storage options.

- Advertisement -

"This isn’t merely a threat aimed at a single instance of uniswapV3SwapCallback," SupLabsYi noted, implying potential wider implications.

Ironically, SIR.trading’s documentation marketed the protocol as "a new DeFi protocol for safer leverage," specifically designed to address challenges in leveraged trading such as volatility decay and liquidation risks. However, the protocol’s documentation did acknowledge potential smart contract vulnerabilities, specifically warning that its vaults could contain undiscovered bugs leading to financial losses, despite having undergone security audits.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Solana Mobile to Launch SKR Token Jan. 21st with 30% Airdrop

SKR, a new token from Solana Mobile, will launch on January 21.The token supply...

Solana Mobile to airdrop 2B SKR to Seeker users Jan 20 9pmET

Solana Mobile will airdrop its new SKR token on January 20, with a claim...

OpenAI’s ChatGPT Health links records and wellness apps now!

OpenAI launched ChatGPT Health on Wednesday to let users link medical records and wellness...

Strategy’s mNAV Hits 1x as Market Value Matches BTC At risk!

Strategy disclosed on its homepage that its enterprise multiple-to-Net Asset Value (mNAV) has fallen...

a16z Crypto buys BABY in $15M deal to boost Bitcoin DeFi Now

Babylon raised $15 million via a token sale to the digital asset arm of...
- Advertisement -

Must Read

A Beginner’s Guide To Cryptocurrency Mining

Cryptocurrency is considered one of the most popular forms of financial assets today. Many of these digital assets operate within blockchain technology which works...
Bitcoin (BTC) $ 91,285.00 1.84%
Ethereum (ETH) $ 3,170.09 3.01%
XRP (XRP) $ 2.16 6.10%
Bittensor (TAO) $ 271.56 5.76%
Polkadot (DOT) $ 2.14 2.73%
Cardano (ADA) $ 0.401188 3.37%
Chainlink (LINK) $ 13.44 3.04%
Hyperliquid (HYPE) $ 26.87 3.79%
Monero (XMR) $ 433.55 2.12%
Hedera (HBAR) $ 0.123341 3.14%
Toncoin (TON) $ 1.88 0.41%