$106 000 USD

JUNE 2024

GLOBAL

STEAMSWAP

DESCRIPTION OF EVENTS

"Steam Swap is a decentralized digital asset trading platform that focuses on connecting digital asset trading markets around the world and providing users with efficient, secure and transparent trading services. We are committed to building an open, connected blockchain ecosystem that allows users to freely exchange digital assets and realize the flow and value of assets. Steam SWAP makes digital asset trading easier and more convenient! Our vision is to become a leader in the blockchain industry, lead the future development trend, and make STEAM SWAP a shining star in the blockchain world!"

 

"In order to ensure a smooth launch, we temporarily replaced the high-defense server. Considering the time difference of global members. we decided to adjust the launch time to UTC time June 6, 2024 05:00:00 Thank you"

 

"The vulnerable MineSTM contract has a sell function that uses a reserve pair for liquidity calculation. Notably, this exploited contract was deployed roughly 16 hours before the incident took place."

 

"The exploiter initially took a flash loan of 500,000 BSC-USD and used it to purchase roughly 2,740,041 STM tokens. The exploiter was able to manipulate this reserve balance by swapping a large amount of these tokens, and then ultimately called the above sell function to complete their attack."

 

"a loss of approximately $105K."

 

"The excess of the STM tokens were sold for profits worth approximately $91,670 before repaying the borrowed flash loan."

 

"Another attacker, likely a copycat of the original exploiter, executed yet another attack transaction to profit by roughly $13,892."

 

"According to monitoring by the SlowMist security team, SteamSwap(STM) on BNBChain was attacked, resulting in a loss of approximately $105K."

 

"Steam Swap was exploited across two different transactions on the $BNB chain due to the price manipulation of the underlying assets, resulting in a loss of assets worth approximately $105,000."

 

"During tonight's node LP minting and mining process, a vulnerability was discovered in the contract. To ensure the system's security and stability, we have decided to conduct a security audit of the contract. The audit report is expected to be completed within 7-10 business days."

Steam Swap is a decentralized digital asset trading platform. There smart contract was unfortunately vulnerable to reserve balance price manipulation. This allowed multiple attackers to use flash loans to manipulate the prices and drain funds. The protocol lost ~$106k worth of assets. The team has decided to audit the smart contract and relaunch. No mention of any reimbursements could be located.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.