QUADRIGA INITIATIVE
CRYPTO WATCHDOG & FRAUD RECOVERY PLATFORM
A COMMUNITY-BASED, NOT-FOR-PROFIT
$500 000 USD
JULY 2024
GLOBAL
ANZEN FINANCE
DESCRIPTION OF EVENTS
"USDz: RWA-backed Stablecoin Backed by institutional grade real world assets"
"USDz is backed by a diversified portfolio of private credit assets. These assets have special traits that protect the investor, like collateral (real assets that can be sold to cover investors' funds) and covenants (rules that tell the borrower what they can or can't do)."
"USDz is fully composable, ensuring seamless integration and functionality across the entire crypto ecosystem. Easily participate in DeFi protocols, trade on decentralized exchanges, and use it for payments, benefiting from its stability and widespread acceptance."
"Staking is available across the largest DeFi platforms, offering attractive opportunities to earn rewards. This allows holders to optimize their portfolio and benefit from the security of a stablecoin with less volatility than speculative tokens."
"Anzen is a decentralized platform providing access to USDz, which is a digital token backed by a diversified portfolio of private credit assets.
Anzen carefully secures these cash-flowing assets alongside qualified KYC-compliant investors through rigorous underwriting. These assets are typically associated with reliable revenue streams and are expected to maintain their value even during periods of cryptocurrency market volatility.
By staking USDz tokens to obtain sUSDz, DeFi users have the chance to earn sustainable rewards and diversify their portfolios. This allows USDz holders to shield themselves from the price fluctuations and volatility of unbacked crypto tokens."
"Operations related to the issuance and redemption of USDz are recorded transparently on the blockchain. This allows users to verify the solvency of USDz at any time, providing clear visibility into the health of its reserves."
The issue was related to decimals and only affected the Blast chain. Details have not been provided.
$500k USD was lost.
"Anzen Finance, the issuer of RWA stablecoins, announced on the X platform that on July 30, due to an error in the Blast vault contract, a white hat hacker exploited the vault to steal 500,000 USDz. The white hat returned $450,000 in a timely manner and received a $50,000 bounty as a reward."
"At Jul-30-2024 03:44:27 PM +UTC the Blast vault was exploited by a whitehat hacker for 500k USDz due to an error in our Blast vault contract. The funds have been returned. The contract error will be corrected prior to refreshing the vault limit on Blast. All other vaults are safe to use.
Upon seeing the transactions on Blast, Anzen immediately purchased 500k USDz to mitigate any sell pressure. The price impact was negligble.
Thanks to the community, we contacted the whitehat hacker who returned the funds promptly. They received a 50k bounty for spotting the error in our Blast vault contract. This is the transaction in which they sent 450k USDC back into the treasury.
We are undergoing a rapid period of growth and would like to thank you for your patience and understanding. If there are any concerns, please reach out to the team through our support channels."
The protocol immediately supplied liquidity to resolve the price discrepancy.
$450k was recovered from the exploiter.
Anzen Finance offers a stablecoin which is backed by real-world assets. The protocol was launched on Ethereum, Base, and Blast. A decimal issue in the Blast version of the smart contract was able to be exploited and the exploiter profited 500k USDC through the exploit. An agreement was reached where 450k was returned in exchange for the remaining 50k being treated as a bug bounty. The protocol continued operating with minimal disruption to the price and without releasing a full post-mortem explaining the exact issue which occurred.
@AnzenFinance Twitter (Aug 13)
Base Transaction Hash (Txhash) Details | BaseScan
(Aug 13)
Base Transaction Hash (Txhash) Details | BaseScan
(Aug 13)
@yieldsandmore Twitter (Aug 13)
Anzen (Aug 13)
Introduction | Anzen Finance (Aug 13)
Anzen Finance was hit by a $500,000 attack and the attacker has returned the funds after deducting the bounty_Hawk Insight (Aug 13)
@yieldsandmore Twitter (Aug 13)