$1 900 000 USD

OCTOBER 2024

GLOBAL

AARK DIGITAL

DESCRIPTION OF EVENTS

"Leverage-Everything Perpetual DEX. Safe and Easy, Powered by Blockchain. Start Trading"

 

"Launched in June 2024. AARK grants holders governance rights and staking benefits including rewards, fee discounts, and Multiplier Points."

 

"During a routine GM token burn, Aark Digital encountered a callback error due to a third-party contract modification. To resolve this, Aark Digital initiated a contract upgrade and GM delisting to adjust affected user balances. Users holding GM were required to convert GM to USDC. Aark Digital ran a script to process these conversions, receiving inputs like target user, amount, token address, and decimals from event data. While executing, a single user’s USD Value shifted erroneously from 0.498942 to 498,942 * (10 ^ 12), due to an incorrect balance update (not from a deployed contract error). Exploiting this security vulnerability, the attacker caused Aark Digital a loss of 1,499,841 USDC and 159.09 ETH."

 

"Initially, we reported a total loss of 1,386,085.5 USDC and 24.143 ETH due to the exploit. However, further investigation has revealed that the actual amount stolen was higher, totaling 1,499,841 USDC and 159.09 ETH. This revised amount provides us with a more accurate scope of the breach, which is essential for our recovery strategy."

 

"The stolen funds represent approximately 67% of the total deposits, including collateral for Futures and LPs. Given the scale of the impact, we are currently able to refund 33% of the original deposit amount to affected users."

Aark Digital is a decentralized exchange which allows users to gain extra rewards and staking benefits. On October 25th, 2024, the platform experience an exploit due to an incorrect balance update in a transfer function, which caused a large loss. Aark Digital has been working to recover the funds over time with the community.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.