<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Onyx_Protocol_Low_Liquidity_NFTLiquidation_Vulnerability</id>
	<title>Onyx Protocol Low Liquidity NFTLiquidation Vulnerability - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Onyx_Protocol_Low_Liquidity_NFTLiquidation_Vulnerability"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Onyx_Protocol_Low_Liquidity_NFTLiquidation_Vulnerability&amp;action=history"/>
	<updated>2026-05-30T06:44:17Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Onyx_Protocol_Low_Liquidity_NFTLiquidation_Vulnerability&amp;diff=6196&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/onyxprotocollowliquiditynftliquidationvulnerability.php}} {{Unattributed Sources}}  Onyx Protocol Logo/HomepageOnyx Protocol is an algorithmic money market designed to bring secure and trustless credit and lending to users on Ethereum Network. On September 26th, 2024, they were once again exploited by a low liquidity market, with an attacker walking off wi...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Onyx_Protocol_Low_Liquidity_NFTLiquidation_Vulnerability&amp;diff=6196&amp;oldid=prev"/>
		<updated>2024-09-27T20:11:00Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/onyxprotocollowliquiditynftliquidationvulnerability.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Onyxprotocol.jpg&quot; title=&quot;File:Onyxprotocol.jpg&quot;&gt;thumb|Onyx Protocol Logo/Homepage&lt;/a&gt;Onyx Protocol is an algorithmic money market designed to bring secure and trustless credit and lending to users on Ethereum Network. On September 26th, 2024, they were once again exploited by a low liquidity market, with an attacker walking off wi...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/onyxprotocollowliquiditynftliquidationvulnerability.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Onyxprotocol.jpg|thumb|Onyx Protocol Logo/Homepage]]Onyx Protocol is an algorithmic money market designed to bring secure and trustless credit and lending to users on Ethereum Network. On September 26th, 2024, they were once again exploited by a low liquidity market, with an attacker walking off with $3.8m worth of funds. At present, they have offered the attacker a 20% bounty and the final outcome is unclear.&amp;lt;ref name=&amp;quot;rekthqtwitter-15988&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;onyxdaotwitter-15989&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cyversalertstwitter-15990&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;hackenclubtwitter-15991&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-15992&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;peckshieldtwitter-15993&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;onyx-15909&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;onyxdocs-15910&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;onyxdaotwitter-15994&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;peckshieldtwitter-15995&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;peckshieldtwitter-15996&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;hackenclubtwitter-15997&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Onyx Protocol ==&lt;br /&gt;
&amp;quot;The Backbone of Decentralised Web3 Protocols&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Onyx Protocol is an algorithmic money market designed to bring secure and trustless credit and lending to users on Ethereum Network. &lt;br /&gt;
&lt;br /&gt;
Onyx enables investors to lend and/or borrow cryptocurrencies, by pledging the platform an over-collateralized amount of cryptocurrency. Onyx does this by utilizing money markets, which are pools of assets with algorithmically derived interest rates, based on the supply and demand of each asset. &lt;br /&gt;
&lt;br /&gt;
Users who choose to supply liquidity to Onyx earn compounded interest as rewards for supplying their assets to the protocol. When supplying assets, users are also given the ability to mint stable-coins, or borrow other assets against their supplied assets. Once a user has supplied assets to Onyx, the user can then borrow assets or mint stable-coins, by over-collateralizing and paying interest on the amount borrowed. &lt;br /&gt;
&lt;br /&gt;
Loans from the Onyx protocol do not have monthly payments, late fees, and can be paid off at any time. Onyx is able to do this without ever requiring a credit check, with near immediate origination, using smart contracts that provide an automated, and absolutely transparent system for investment and profit distribution.&lt;br /&gt;
&lt;br /&gt;
Onyx also provides loans for CryptoPunks and BAYC.  NFT holders can leverage their idle NFTs to obtain loans and earn extra yield.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Onyx Protocol Low Liquidity NFTLiquidation Vulnerability&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 6:01:59 AM MDT&lt;br /&gt;
|Attack Transaction&lt;br /&gt;
|The attack transaction happens on the blockchain, as later reported by Hacken.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 6:43:00 AM MDT&lt;br /&gt;
|Cyvers Report Tweet&lt;br /&gt;
|Cyvers reports suspicious activity on the blockchain regarding Onyx Protocol.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 7:15:00 AM MDT&lt;br /&gt;
|Hacken Analysis Tweet&lt;br /&gt;
|Hacken shared an analysis which includes the original blockchain transaction.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 7:30:00 AM MDT&lt;br /&gt;
|PeckShield Initial Post&lt;br /&gt;
|PeckShield posts a tweet with a screenshot of the transaction and notes that Onyx &amp;quot;may want to take a look&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 7:39:00 AM MDT&lt;br /&gt;
|Latest Whereabouts Update&lt;br /&gt;
|PeckShield provides an update with the latest whereabouts of the tokens.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 7:55:00 AM MDT&lt;br /&gt;
|PeckShield Analysis Tweet&lt;br /&gt;
|PeckShield posts a further analysis of the attack against Onyx.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 8:12:00 AM MDT&lt;br /&gt;
|PeckShield Highlighting Issue&lt;br /&gt;
|In an update tweet, PeckShield provides details of another exploit where &amp;quot;the NFTLiquidation contract, which does not properly validate (untrusted) user input and was exploited to inflate the self-liquidation reward amount&amp;quot;. This would later be referenced in a tweet by the Onyx team.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 10:06:00 AM MDT&lt;br /&gt;
|Onyx Protocol Is Aware&lt;br /&gt;
|In a Tweet, Onyx Protocol notes that they are &amp;quot;aware of unusual activity&amp;quot; on their platform. They &amp;quot;will announce further details in due course&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 1:46:00 PM MDT&lt;br /&gt;
|Rekt News Investigation&lt;br /&gt;
|Rekt publishes their investigation of the Onxy protocol situation.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 5:17:00 PM MDT&lt;br /&gt;
|Onyx Protocol Postmortem&lt;br /&gt;
|Onyx publishes a post-mortem with more details of what happened and the path forward.&lt;br /&gt;
|-&lt;br /&gt;
|September 26th, 2024 9:50:00 PM MDT&lt;br /&gt;
|Onyx Offers 20% Bounty&lt;br /&gt;
|The Onyx team offers a 20% bounty to the hacker. If they return 80%, then the rest of the funds will be considered as a bounty for discovering the exploit.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;The vulnerability stems from a flaw in the asset’s exchange rate calculation when there’s low liquidity in a certain market. The attacker manipulated the exchange rate by minting and redeeming Onyx ETH (oETH) 56 times.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The exploit started with a 2K ETH flash loan from Balancer. The attacker deposited 1,999.5 ETH into the oEther contract (oETH market) while depositing 0.5 ETH into another malicious contract (0xAE7d68) created in the same transaction. &lt;br /&gt;
&lt;br /&gt;
This contract was used to mint and redeem very small amounts of oETH (as little as 0.00000001 oETH), manipulating the exchange rate to exploit the system.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $3,800,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;ALERT! Our system has detected suspicious transaction involving @OnyxDAO on #ETH chain!&lt;br /&gt;
&lt;br /&gt;
Total loss is around  $3.2M. Most of the loss are in $VUSD. Attacker currently holds 521 $ETH $1.36M. Rest of the digital assets are not swapped yet!&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Onyx Protocol is aware of unusual activity on our platform and is currently reviewing third party post mortem examination data while conducting our own investigation.&lt;br /&gt;
&lt;br /&gt;
We will announce further details in due course&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Another Compound v2 fork that just can't catch a break, @OnyxDAO, has been exploited again.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
This time, the damage tally stands at a cool $3.8 million, siphoned off by the same vulnerability that bit them late last year.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;The attacker has already swapped all the stolen VUSD to ETH using CoW Protocol and Uniswap. In 12 transactions, they swapped 3.8M VUSD but only received 570 ETH ($1.5M) due to high slippage in the liquidity pools.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The total amount recovered is unknown.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
&amp;quot;Onyx DAO is offering a 20% bounty for the recovery of the exploited funds. We will also consider funds returned from the hacker as a bounty and request 80% back. After 7 days, we will send the information from third parties regarding the identity  of the hackers to authorities.&amp;quot;&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rekthqtwitter-15988&amp;quot;&amp;gt;[https://twitter.com/RektHQ/status/1839391124424712596 @RektHQ Twitter] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;onyxdaotwitter-15989&amp;quot;&amp;gt;[https://twitter.com/OnyxDAO/status/1839335665768845452 @OnyxDAO Twitter] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cyversalertstwitter-15990&amp;quot;&amp;gt;[https://twitter.com/CyversAlerts/status/1839284600461303958 @CyversAlerts Twitter] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;hackenclubtwitter-15991&amp;quot;&amp;gt;[https://twitter.com/hackenclub/status/1839292759330664825 @hackenclub Twitter] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-15992&amp;quot;&amp;gt;[https://etherscan.io/tx/0x46567c731c4f4f7e27c4ce591f0aebdeb2d9ae1038237a0134de7b13e63d8729 Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;peckshieldtwitter-15993&amp;quot;&amp;gt;[https://twitter.com/peckshield/status/1839302663680438342 @peckshield Twitter] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;onyx-15909&amp;quot;&amp;gt;[https://onyx.org/ The Backbone of Decentralised Web3 Protocols] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;onyxdocs-15910&amp;quot;&amp;gt;[https://docs.onyx.org/ Onyx Documentation | Onyx Protocol] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;onyxdaotwitter-15994&amp;quot;&amp;gt;[https://twitter.com/OnyxDAO/status/1839444120060023167 @OnyxDAO Twitter] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;peckshieldtwitter-15995&amp;quot;&amp;gt;[https://twitter.com/peckshield/status/1839298850605142413 @peckshield Twitter] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;peckshieldtwitter-15996&amp;quot;&amp;gt;[https://twitter.com/peckshield/status/1839307011491770523 @peckshield Twitter] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;hackenclubtwitter-15997&amp;quot;&amp;gt;[https://twitter.com/hackenclub/status/1839312308880715797 @hackenclub Twitter] (Accessed Sep 27, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>