$100 000 USD

OCTOBER 2021

GLOBAL

WEDEX

DESCRIPTION OF EVENTS

"WeDEX is a decentralized exchange based on Ethereum. WeDEX adopts the Loopring Protocol and Zkps technology, which greatly improves transaction speed and user experience on the premise of ensuring transaction security. WeDEX does not take any custody of user assets, each trade can be verified on the chain and the data is transparent in WeDEX. With on-chain data availability, the throughput is as high as 1400 trades per second. The user experience is comparable to centralized exchanges. Enjoy your crypto trading in WeDEX."

 

"WEDEX is the leading decentralized exchange on Binance Smart Chain, we bring the freedom and privacy for the user! Why pay more? WEDEX runs on Binance Smart Chain, a blockchain with much lower transaction costs than Ethereum or Bitcoin. Trading fees are lower than other top decentralized exchanges too, so that's a double win for you! Trade directly from your wallet app. Unlike centralized exchanges like Binance or Coinbase, WEDEX doesn’t hold your funds when you trade: you have 100% ownership of your own crypto."

 

"On October 18, 2021" "#WEDEX suffered a flash loan assisted attack. The attacker was able to gain profit from deposit and emergencyWithdraw operation."

 

"WeDEX lost $100K after an attacker was able to continuously call emergencyWithdraw() function due to a misconfiguration." "The incident caused by the #WEDEX unique feature, users can receive commissions ($DEX) when deposit LP tokens to WedexChef if the pool’s locking period not 0."

 

"When the variable emergencyLockingWithdrawEnable is "TRUE", the attacker can trigger the function emergencyWithdraw() to withdraw tokens without any explicit restrictions."

 

"The attacker repeated the steps “deposit-emergencyWithdraw” to generate more commissions. Lastly, the attacker amplified the profit by borrowing flash loans to manipulate the DEX price."

 

"Hey there dear community members! WEDEX contract is audited and listed, check the report by link below and stay safe."

The WeDEX smart contract hot wallet was reportedly exploited for $100k. Shortly afterward, the team optained an audit. It's unclear if the team has done anything to compensate affected users.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.