Grim Finance Reentrancy Attack: Difference between revisions

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search
(Another 30 minutes complete.)
(Another 30 minutes complete.)
Line 3: Line 3:
[[File:Grimfinance.jpg|thumb|Grim Finance]]Despite an audit, Grim Finance's smart contract hot wallets suffered an exploit where they allowed an attacker to add a malicious smart contract, gaining extra shares. The attacker appears to have gotten away with roughly $30m in Fantom. Grim Finance is working on a compensation plan for affected users. Solidity Finance, who provided the audit, deflected blame to a junior developer who they hired to perform that particular audit.
[[File:Grimfinance.jpg|thumb|Grim Finance]]Despite an audit, Grim Finance's smart contract hot wallets suffered an exploit where they allowed an attacker to add a malicious smart contract, gaining extra shares. The attacker appears to have gotten away with roughly $30m in Fantom. Grim Finance is working on a compensation plan for affected users. Solidity Finance, who provided the audit, deflected blame to a junior developer who they hired to perform that particular audit.


This is a global/international case not involving a specific country.<ref name="rektnews-5141" /><ref name="grimfinance-5142" /><ref name="grimfinancedocs-5143" /><ref name="ftmscan-5144" /><ref name="financegrimtwitter-5145" /><ref name="financegrimtwitter-5146" /><ref name="financegrimtwitter-5147" /><ref name="grimfinance11medium-5148" /><ref name="googledoc-5149" /><ref name="ftmalertstwitter-5150" /><ref name="financegrimtwitter-5151" /><ref name="financegrimtwitter-5152" /><ref name="financegrimtwitter-5153" /><ref name="financegrimtwitter-5154" /><ref name="certik-5155" /><ref name="financegrimtwitter-5156" /><ref name="financegrimtwitter-5157" /><ref name="financegrimtwitter-5158" /><ref name="financegrimtwitter-5159" /><ref name="grimfinance11medium-5160" /><ref name="solidityfinance-5161" /><ref name="solidityfinancetwitter-5162" /><ref name="ftmscan-5163" /><ref name="solidityfinancetwitter-5164" /><ref name="certik-5262" /><ref name="cryptonews-9850" /><ref name="cryptonews-9854" /><ref name="unnamed-11224" /><ref name="unnamed-11225" /><ref name="unnamed-11226" /><ref name="unnamed-11227" /><ref name="unnamed-11228" />
This is a global/international case not involving a specific country.<ref name="rektnews-5141" /><ref name="grimfinance-5142" /><ref name="grimfinancedocs-5143" /><ref name="ftmscan-5144" /><ref name="financegrimtwitter-5145" /><ref name="financegrimtwitter-5146" /><ref name="financegrimtwitter-5147" /><ref name="grimfinance11medium-5148" /><ref name="googledoc-5149" /><ref name="ftmalertstwitter-5150" /><ref name="financegrimtwitter-5151" /><ref name="financegrimtwitter-5152" /><ref name="financegrimtwitter-5153" /><ref name="financegrimtwitter-5154" /><ref name="certik-5155" /><ref name="financegrimtwitter-5156" /><ref name="financegrimtwitter-5157" /><ref name="financegrimtwitter-5158" /><ref name="financegrimtwitter-5159" /><ref name="grimfinance11medium-5160" /><ref name="solidityfinance-5161" /><ref name="solidityfinancetwitter-5162" /><ref name="ftmscan-5163" /><ref name="solidityfinancetwitter-5164" /><ref name="certik-5262" /><ref name="cryptonews-9850" /><ref name="cryptonews-9854" /><ref name="unnamed-11224" /><ref name="unnamed-11225" /><ref name="unnamed-11226" /><ref name="unnamed-11227" />
 
 
The Grim Finance platform, associated with the self.FantomFoundation, was hacked by an unknown individual or group. The hacker's account was identified as 0xdefc385d7038f391eb0063c2f7c238cfb55b206c. The stolen amount at the time was reported to be €24,583,420.676 €29,080,834.875. Users who had invested in Grim Finance expressed their disappointment and shared their experiences. Some users mentioned losing their LP (liquidity provider) tokens, while others mentioned being affected by the hack. There were discussions about the risks involved in decentralized finance (DeFi) and the need to diversify investments across multiple platforms. Some users shared their strategies for reducing risk, such as manually compounding earnings on Tomb Finance or reducing their exposure to specific platforms. There were also mentions of other projects affected by the hack, such as Boo Vaults, Pod Town, Spirit, and gSpirit. Some users expressed their intent to buy TOMB and other assets during the dip caused by the hack. The hack itself was discussed in a Twitter thread, where it was explained that the hacker exploited a vulnerability in the vault by making multiple deposits simultaneously. Concerns were raised about the effectiveness of audits and the possibility of insider involvement in the hack. Overall, the hack of Grim Finance had a significant impact on users and raised questions about the security and reliability of DeFi platforms.


== About Grim Finance ==
== About Grim Finance ==
"Compounding Yield Optimizer Built on Fantom Opera. Allowing users to reap more crypto with crypto."
"Compounding Yield Optimizer Built on Fantom Opera. Allowing users to reap more crypto with crypto."


Line 28: Line 33:
|December 18th, 2021 12:45:19 PM MST
|December 18th, 2021 12:45:19 PM MST
|Hack Shared To Reddit
|Hack Shared To Reddit
|The hacking event is shared to Reddit by ...
|The hacking event is shared to Reddit by ricardo_mribeiro<ref name="unnamed-11225" /> on the FantomFoundation subreddit. The hacker's account was identified as 0xdefc385d7038f391eb0063c2f7c238cfb55b206c. The stolen amount at the time was reported to be €24,583,420.676, revised to €29,080,834.875. Users who had invested in Grim Finance expressed their disappointment and shared their experiences. Some users mentioned losing their LP (liquidity provider) tokens, while others mentioned being affected by the hack. There were discussions about the risks involved in decentralized finance (DeFi) and the need to diversify investments across multiple platforms. Some users shared their strategies for reducing risk, such as manually compounding earnings on Tomb Finance or reducing their exposure to specific platforms. There were also mentions of other projects affected by the hack, such as Boo Vaults, Pod Town, Spirit, and gSpirit. Some users expressed their intent to buy TOMB and other assets during the dip caused by the hack. The hack itself was discussed in a Twitter thread, where it was explained that the hacker exploited a vulnerability in the vault by making multiple deposits simultaneously. Concerns were raised about the effectiveness of audits and the possibility of insider involvement in the hack<ref name="unnamed-11225" />.
|-
|December 18th, 2021 6:06:09 PM MST
|Revoke Permissions Reference
|A Reddit thread references the recent hack of Grim Finance, where the hacker's account holds around $3 million, as a devastating blow to both the platform's users and the wider crypto community. To protect ourselves from such hacks, it states the importance of revoking the authorization of smart contracts. This can be done through the Token Approval option on blockchain trackers, typically found under the three-dot overflow menu. By doing this, we can prevent smart contracts from having unlimited access to the tokens they interacted with in our wallets. Although revoking authorization may involve gas fees, it is a simple step we can take to ensure our safety in the world of DeFi. Additionally, tools like allowance.beefy.finance can help purge contracts and allowances, offering further protection against potential exploits<ref name="unnamed-11228" />.
|-
|-
|December 20th, 2021
|December 20th, 2021
|Main Event
|Incident Shared To Rekt
|Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here.
|The Grim Finance hack is shared to Rekt<ref name="rektnews-5141" />. Grim Finance, a fork of Beefy Finance, has suffered a devastating attack resulting in an 80% drop in the price of its native token, $GRIM. The attack exploited a vulnerability related to reentrancy in the depositFor() function. By looping false deposits within the initial call, the hacker was able to increase their share of the vault significantly. The attacker's address has been identified as 0xdefc385d7038f391eb0063c2f7c238cfb55b206c, and the Grim Finance team is conducting an investigation to trace the movement of funds and has found connections to various centralized exchanges (CEXs). Charge DeFi, another project, also fell victim to a similar attack just hours before. While Charge DeFi claims to have warned other projects about the vulnerability, it appears that the warnings may not have had the desired effect. There are claims from a Discord user that some of the stolen funds will be donated to charity, but the incident remains a grim Christmas for the unwilling donors.
|-
|-
|
|
Line 50: Line 59:


"On the unwinding of the 5 rentrancies, each loop will see that the _amount is not 0, and mint the corresponding shares, mint the same share count 5x (the number of rentrancy loops)." "The code which was exploited was present in multiple vaults, resulting in a loss of funds across the platform's vaults."
"On the unwinding of the 5 rentrancies, each loop will see that the _amount is not 0, and mint the corresponding shares, mint the same share count 5x (the number of rentrancy loops)." "The code which was exploited was present in multiple vaults, resulting in a loss of funds across the platform's vaults."
The hacker's account was identified as 0xdefc385d7038f391eb0063c2f7c238cfb55b206c<ref name="unnamed-11225" />.




Line 74: Line 85:


=== Community Reactions on Reddit ===
=== Community Reactions on Reddit ===
<ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp3lesl/ carlit0s_w4y - "Absolutely gutted. At least I was able to get something back. I actually got done twice today as I'm also in charge which also got hacked, 2 in one day seriously hurts, although Charge defi have said they will compensate everyone, its been silence from Grim so far." - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp3iq64/ shiningbird1 - "I've been manually compounding on Tomb once a day. Was tempted to use an autocompounder but didn't want to take on the extra layer of risk just to save a minute of time each day. Really glad I stuck to the manual approach!" - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp4xpmt/ GoldenKnights1023 - "I lost my entire tomb-ftm lp it was substantial. There was also the boo vaults got rekt. So when they dump that boo price will tank. Pod town was using the reaper logic for their pools…rekt. Spirit and gspirit rekt. It’s an awful awful ripple. I’m gutted drunk and sad. I was Christmas shopping with my wife and kid. I saw my chat going bananas. Life is pain and that’s it." - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp4nvya/ TechnicalProposal - "Honestly speaking, all the audits are paid services and I am not even sure they do a good job. For grim it is a simple lack of guard in smart contract. How the heck these audits miss this simple fact. I guess, not all bugs are simple even though they are simple in retrospect. But these audit cost from 20k to 50k and they don’t do shit? I think this is an inside job." - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp4aiwf/ BidProud3017 - "Thats absolutely crazy. I had about 40% of my net worth in there. I am in the navy, currently out sailing, and I deleted my metamask browser extension before I left home, for security reasons lol. Now I cant even check my wallet. Hope they will get returned somehow, or magically still be in my wallet. Was all tomb-ftm lps emptied out? Insane if its lost, half a year work out the window." - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp5we77/ BidProud3017 - Defi is a dangerous place to be, especially as a soft brained monkey. Fantom defi was my dream of financial freedom. APY off more than 1k was too good to be true after all. I think I am done with Defi now. I had all my ftm in grim, half of my life savings gone in 2 seconds. - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp3an82/ DrChew1 - "Holy shit, this sucks. I'm currently at work and dont have my hardware wallet with me, what should i do when i get home? Check the vault? Revoke permissions to grim on debank? Withdraw funds if they are available? This is such a bad situation, have no idea what i should do" - Reddit] (Jul 2, 2023)</ref><blockquote>Lost my TOMB-FTM LP, but managed to pullout my WMemo. Absolutely gutted. At least I was able to get something back. I actually got done twice today as I'm also in charge which also got hacked, 2 in one day seriously hurts, although Charge defi have said they will compensate everyone, its been silence from Grim so far. Its a stark reminder about the risks involved, my first time experiencing the dark side of defi. To anyone reading this please please ensure you spread your risk across multiple platforms if you're not already. Grim has multiple audits from respected auditors, can happen to any protocol, I'm certainly going to be treading very cautiously moving forward. I have been doing my due diligence yet I still got burnt (luckily not totally rekt), although I'll be spreading my portfolio more thinly in the future, makes it harder to manage, however, will be worth it.</blockquote><blockquote>I've been manually compounding on Tomb once a day. Was tempted to use an autocompounder but didn't want to take on the extra layer of risk just to save a minute of time each day. Really glad I stuck to the manual approach!</blockquote><blockquote>I lost my entire tomb-ftm lp it was substantial. There was also the boo vaults got rekt. So when they dump that boo price will tank. Pod town was using the reaper logic for their pools…rekt. Spirit and gspirit rekt. It’s an awful awful ripple. I’m gutted drunk and sad. I was Christmas shopping with my wife and kid. I saw my chat going bananas. Life is pain and that’s it.</blockquote><blockquote>Honestly speaking, all the audits are paid services and I am not even sure they do a good job. For grim it is a simple lack of guard in smart contract. How the heck these audits miss this simple fact. I guess, not all bugs are simple even though they are simple in retrospect. But these audit cost from 20k to 50k and they don’t do shit? I think this is an inside job. Go check rugdoc and read their updates for grim finance . It is all fishy.</blockquote><blockquote>Thats absolutely crazy. I had about 40% of my net worth in there. I am in the navy, currently out sailing, and I deleted my metamask browser extension before I left home, for security reasons lol. Now I cant even check my wallet. Hope they will get returned somehow, or magically still be in my wallet. Was all tomb-ftm lps emptied out? Insane if its lost, half a year work out the window.
<ref name="unnamed-11228" /><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp3lesl/ carlit0s_w4y - "Absolutely gutted. At least I was able to get something back. I actually got done twice today as I'm also in charge which also got hacked, 2 in one day seriously hurts, although Charge defi have said they will compensate everyone, its been silence from Grim so far." - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp3iq64/ shiningbird1 - "I've been manually compounding on Tomb once a day. Was tempted to use an autocompounder but didn't want to take on the extra layer of risk just to save a minute of time each day. Really glad I stuck to the manual approach!" - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp4xpmt/ GoldenKnights1023 - "I lost my entire tomb-ftm lp it was substantial. There was also the boo vaults got rekt. So when they dump that boo price will tank. Pod town was using the reaper logic for their pools…rekt. Spirit and gspirit rekt. It’s an awful awful ripple. I’m gutted drunk and sad. I was Christmas shopping with my wife and kid. I saw my chat going bananas. Life is pain and that’s it." - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp4nvya/ TechnicalProposal - "Honestly speaking, all the audits are paid services and I am not even sure they do a good job. For grim it is a simple lack of guard in smart contract. How the heck these audits miss this simple fact. I guess, not all bugs are simple even though they are simple in retrospect. But these audit cost from 20k to 50k and they don’t do shit? I think this is an inside job." - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp4aiwf/ BidProud3017 - "Thats absolutely crazy. I had about 40% of my net worth in there. I am in the navy, currently out sailing, and I deleted my metamask browser extension before I left home, for security reasons lol. Now I cant even check my wallet. Hope they will get returned somehow, or magically still be in my wallet. Was all tomb-ftm lps emptied out? Insane if its lost, half a year work out the window." - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp5we77/ BidProud3017 - Defi is a dangerous place to be, especially as a soft brained monkey. Fantom defi was my dream of financial freedom. APY off more than 1k was too good to be true after all. I think I am done with Defi now. I had all my ftm in grim, half of my life savings gone in 2 seconds. - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp3an82/ DrChew1 - "Holy shit, this sucks. I'm currently at work and dont have my hardware wallet with me, what should i do when i get home? Check the vault? Revoke permissions to grim on debank? Withdraw funds if they are available? This is such a bad situation, have no idea what i should do" - Reddit] (Jul 2, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp37kdx/ AdvancedSimulation - "Can't get my funds out I think they locked the site down." - Reddit] (Jul 3, 2023)</ref><ref>[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp5kk92/ Lightning571 - "Lost 25% of my defi portfolio, really hurts as an 18yo college student" - Reddit] (Jul 3, 2023)</ref><blockquote>Lost my TOMB-FTM LP, but managed to pullout my WMemo. Absolutely gutted. At least I was able to get something back. I actually got done twice today as I'm also in charge which also got hacked, 2 in one day seriously hurts, although Charge defi have said they will compensate everyone, its been silence from Grim so far. Its a stark reminder about the risks involved, my first time experiencing the dark side of defi. To anyone reading this please please ensure you spread your risk across multiple platforms if you're not already. Grim has multiple audits from respected auditors, can happen to any protocol, I'm certainly going to be treading very cautiously moving forward. I have been doing my due diligence yet I still got burnt (luckily not totally rekt), although I'll be spreading my portfolio more thinly in the future, makes it harder to manage, however, will be worth it.</blockquote><blockquote>I've been manually compounding on Tomb once a day. Was tempted to use an autocompounder but didn't want to take on the extra layer of risk just to save a minute of time each day. Really glad I stuck to the manual approach!</blockquote><blockquote>I lost my entire tomb-ftm lp it was substantial. There was also the boo vaults got rekt. So when they dump that boo price will tank. Pod town was using the reaper logic for their pools…rekt. Spirit and gspirit rekt. It’s an awful awful ripple. I’m gutted drunk and sad. I was Christmas shopping with my wife and kid. I saw my chat going bananas. Life is pain and that’s it.</blockquote><blockquote>Honestly speaking, all the audits are paid services and I am not even sure they do a good job. For grim it is a simple lack of guard in smart contract. How the heck these audits miss this simple fact. I guess, not all bugs are simple even though they are simple in retrospect. But these audit cost from 20k to 50k and they don’t do shit? I think this is an inside job. Go check rugdoc and read their updates for grim finance . It is all fishy.</blockquote><blockquote>Thats absolutely crazy. I had about 40% of my net worth in there. I am in the navy, currently out sailing, and I deleted my metamask browser extension before I left home, for security reasons lol. Now I cant even check my wallet. Hope they will get returned somehow, or magically still be in my wallet. Was all tomb-ftm lps emptied out? Insane if its lost, half a year work out the window.


Defi is a dangerous place to be, especially as a soft brained monkey. Fantom defi was my dream of financial freedom. APY off more than 1k was too good to be true after all. I think I am done with Defi now. I had all my ftm in grim, half of my life savings gone in 2 seconds.
Defi is a dangerous place to be, especially as a soft brained monkey. Fantom defi was my dream of financial freedom. APY off more than 1k was too good to be true after all. I think I am done with Defi now. I had all my ftm in grim, half of my life savings gone in 2 seconds.


I need hopium badly right now!</blockquote><blockquote>Holy shit, this sucks. I'm currently at work and dont have my hardware wallet with me, what should i do when i get home? Check the vault? Revoke permissions to grim on debank? Withdraw funds if they are available? This is such a bad situation, have no idea what i should do</blockquote>
I need hopium badly right now!</blockquote><blockquote>Holy shit, this sucks. I'm currently at work and dont have my hardware wallet with me, what should i do when i get home? Check the vault? Revoke permissions to grim on debank? Withdraw funds if they are available? This is such a bad situation, have no idea what i should do</blockquote><blockquote>Can't get my funds out I think they locked the site down.</blockquote><blockquote>Lost 25% of my defi portfolio, really hurts as an 18yo college student</blockquote><blockquote>Recently, Grim Finance was hacked. The hacker's account, 0xDefC385D7038f391Eb0063C2f7C238cFb55b206C has around $3 Million in it. This is devastating for everyone of their users and for the crypto community as a whole. Anyone who would have taken the pains to revoke Smart Contract Authorization after they have done interacting with the Grim Finance Dapp would have been safe from such a hack.</blockquote>


=== Market Price Drop ===
=== Market Price Drop ===
Line 130: Line 141:


== References ==
== References ==
<references><ref name="rektnews-5141">[https://rekt.news/?tag=Grim+Finance Rekt - Home] (Jan 3, 2022)</ref>
<references>
 
<ref name="rektnews-5141">[https://rekt.news/grim-finance-rekt/ Grim Finance - Rekt] (Jan 3, 2022)</ref>
<ref name="grimfinance-5142">[https://www.grim.finance/ Grim Finance] (Jan 3, 2022)</ref>
<ref name="grimfinance-5142">[https://www.grim.finance/ Grim Finance] (Jan 3, 2022)</ref>
<ref name="grimfinancedocs-5143">[https://docs.grim.finance/ Introduction - Grim.Finance] (Jan 3, 2022)</ref>
<ref name="grimfinancedocs-5143">[https://docs.grim.finance/ Introduction - Grim.Finance] (Jan 3, 2022)</ref>
<ref name="ftmscan-5144">[https://ftmscan.com/address/0xdefc385d7038f391eb0063c2f7c238cfb55b206c Address 0xdefc385d7038f391eb0063c2f7c238cfb55b206c | FtmScan] (Jan 3, 2022)</ref>
<ref name="ftmscan-5144">[https://ftmscan.com/address/0xdefc385d7038f391eb0063c2f7c238cfb55b206c Address 0xdefc385d7038f391eb0063c2f7c238cfb55b206c | FtmScan] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5145">[https://twitter.com/financegrim/status/1472351539255783426 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5145">[https://twitter.com/financegrim/status/1472351539255783426 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5146">[https://twitter.com/financegrim/status/1472357770846519312 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5146">[https://twitter.com/financegrim/status/1472357770846519312 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5147">[https://twitter.com/financegrim/status/1473017215469371392 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5147">[https://twitter.com/financegrim/status/1473017215469371392 @financegrim Twitter] (Jan 3, 2022)</ref>
 
<ref name="grimfinance11medium-5148">https://medium.com/@grimfinance11/grim-finance-update-to-exploit-15226e6df736 (Jan 3, 2022)</ref>
<ref name="grimfinance11medium-5148">[https://medium.com/@grimfinance11/grim-finance-update-to-exploit-15226e6df736 https://medium.com/@grimfinance11/grim-finance-update-to-exploit-15226e6df736] (Jan 3, 2022)</ref>
 
<ref name="googledoc-5149">[https://docs.google.com/spreadsheets/d/1jQyiCnEdFWA1CZZCCMeG9g5KTbUNiaL4TdS9MeoBKdo/edit Grim Findings - Google Sheets] (Jan 3, 2022)</ref>
<ref name="googledoc-5149">[https://docs.google.com/spreadsheets/d/1jQyiCnEdFWA1CZZCCMeG9g5KTbUNiaL4TdS9MeoBKdo/edit Grim Findings - Google Sheets] (Jan 3, 2022)</ref>
<ref name="ftmalertstwitter-5150">[https://twitter.com/FTMAlerts/status/1473067104765194252 @FTMAlerts Twitter] (Jan 3, 2022)</ref>
<ref name="ftmalertstwitter-5150">[https://twitter.com/FTMAlerts/status/1473067104765194252 @FTMAlerts Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5151">[https://twitter.com/financegrim/status/1473491310627758087 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5151">[https://twitter.com/financegrim/status/1473491310627758087 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5152">[https://twitter.com/financegrim/status/1473756057646346245 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5152">[https://twitter.com/financegrim/status/1473756057646346245 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5153">[https://twitter.com/financegrim/status/1474899127851012096 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5153">[https://twitter.com/financegrim/status/1474899127851012096 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5154">[https://twitter.com/financegrim/status/1476320989453684740 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5154">[https://twitter.com/financegrim/status/1476320989453684740 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="certik-5155">[https://www.certik.com/projects/grim-finance Grim Finance - CertiK Security Leaderboard] (Jan 3, 2022)</ref>
<ref name="certik-5155">[https://www.certik.com/projects/grim-finance Grim Finance - CertiK Security Leaderboard] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5156">[https://twitter.com/financegrim/status/1476348861283192834 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5156">[https://twitter.com/financegrim/status/1476348861283192834 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5157">[https://twitter.com/financegrim/status/1476748272727433218 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5157">[https://twitter.com/financegrim/status/1476748272727433218 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5158">[https://twitter.com/financegrim/status/1477053839408865282 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5158">[https://twitter.com/financegrim/status/1477053839408865282 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5159">[https://twitter.com/financegrim/status/1477365809571930127 @financegrim Twitter] (Jan 3, 2022)</ref>
<ref name="financegrimtwitter-5159">[https://twitter.com/financegrim/status/1477365809571930127 @financegrim Twitter] (Jan 3, 2022)</ref>
 
<ref name="grimfinance11medium-5160">https://medium.com/@grimfinance11/grim-is-back-platform-v2-updates-47dd51ab2f1 (Jan 3, 2022)</ref>
<ref name="grimfinance11medium-5160">[https://medium.com/@grimfinance11/grim-is-back-platform-v2-updates-47dd51ab2f1 https://medium.com/@grimfinance11/grim-is-back-platform-v2-updates-47dd51ab2f1] (Jan 3, 2022)</ref>
 
<ref name="solidityfinance-5161">[https://solidity.finance/audits/GrimVault/ Grim Finance Audit - Solidity Finance] (Jan 3, 2022)</ref>
<ref name="solidityfinance-5161">[https://solidity.finance/audits/GrimVault/ Grim Finance Audit - Solidity Finance] (Jan 3, 2022)</ref>
<ref name="solidityfinancetwitter-5162">[https://twitter.com/SolidityFinance/status/1472614849230344196 @SolidityFinance Twitter] (Jan 3, 2022)</ref>
<ref name="solidityfinancetwitter-5162">[https://twitter.com/SolidityFinance/status/1472614849230344196 @SolidityFinance Twitter] (Jan 3, 2022)</ref>
<ref name="ftmscan-5163">[https://ftmscan.com/tx/0x19315e5b150d0a83e797203bb9c957ec1fa8a6f404f4f761d970cb29a74a5dd6 Fantom Transaction Hash (Txhash) Details | FtmScan] (Jan 3, 2022)</ref>
<ref name="ftmscan-5163">[https://ftmscan.com/tx/0x19315e5b150d0a83e797203bb9c957ec1fa8a6f404f4f761d970cb29a74a5dd6 Fantom Transaction Hash (Txhash) Details | FtmScan] (Jan 3, 2022)</ref>
<ref name="solidityfinancetwitter-5164">[https://twitter.com/SolidityFinance/status/1472614856629051402 @SolidityFinance Twitter] (Jan 3, 2022)</ref>
<ref name="solidityfinancetwitter-5164">[https://twitter.com/SolidityFinance/status/1472614856629051402 @SolidityFinance Twitter] (Jan 3, 2022)</ref>
<ref name="certik-5262">[https://www.certik.com/ CertiK Blockchain Security Leaderboard] (Jan 4, 2022)</ref>
<ref name="certik-5262">[https://www.certik.com/ CertiK Blockchain Security Leaderboard] (Jan 4, 2022)</ref>
<ref name="cryptonews-9850">[https://cryptonews.com/news/santa-hackathon-visor-finance-marks-7th-hack-december.htm Santa Hackathon? Visor Finance Marks 7th Hack in December] (Dec 1, 2022)</ref>
<ref name="cryptonews-9850">[https://cryptonews.com/news/santa-hackathon-visor-finance-marks-7th-hack-december.htm Santa Hackathon? Visor Finance Marks 7th Hack in December] (Dec 1, 2022)</ref>
<ref name="cryptonews-9854">[https://cryptonews.com/news/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue.htm Hacked Grim Finance's Auditors Blame New Analyst For Missing the Issue] (Dec 1, 2022)</ref>
<ref name="cryptonews-9854">[https://cryptonews.com/news/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue.htm Hacked Grim Finance's Auditors Blame New Analyst For Missing the Issue] (Dec 1, 2022)</ref>
<ref name="unnamed-11224">[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp97uo2/ Tradegrow comments on Grim finance is hacked] (Oct 3, 2022)</ref>
<ref name="unnamed-11224">[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/hp97uo2/ Tradegrow comments on Grim finance is hacked] (Oct 3, 2022)</ref>
 
<ref name="unnamed-11225">[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/ Grim finance is hacked - FantomFoundation Reddit] (Jun 5, 2023)</ref>
<ref name="unnamed-11225">[https://old.reddit.com/r/FantomFoundation/comments/rjezb4/grim_finance_is_hacked/ Grim finance is hacked : FantomFoundation] (Jun 5, 2023)</ref>
<ref name="unnamed-11226">https://apeboard.finance/dashboard/0xdefc385d7038f391eb0063c2f7c238cfb55b206c?tab=HISTORY (Jun 5, 2023)</ref>
 
<ref name="unnamed-11226">[https://apeboard.finance/dashboard/0xdefc385d7038f391eb0063c2f7c238cfb55b206c?tab=HISTORY https://apeboard.finance/dashboard/0xdefc385d7038f391eb0063c2f7c238cfb55b206c?tab=HISTORY] (Jun 5, 2023)</ref>
 
<ref name="unnamed-11227">[https://web.archive.org/web/20211218195658/https://apeboard.finance/dashboard/0xdefc385d7038f391eb0063c2f7c238cfb55b206c?tab=HISTORY Ape Board | Cross-chain DeFi Dashboard] (Jun 24, 2023)</ref>
<ref name="unnamed-11227">[https://web.archive.org/web/20211218195658/https://apeboard.finance/dashboard/0xdefc385d7038f391eb0063c2f7c238cfb55b206c?tab=HISTORY Ape Board | Cross-chain DeFi Dashboard] (Jun 24, 2023)</ref>
 
<ref name="unnamed-11228">[https://old.reddit.com/r/CryptoCurrency/comments/rjl6nr/revoke_unlimited_usage_from_contracts/ Oneofmanyshades - Revoke Unlimited Usage from Contracts. - CryptoCurrency Reddit] (Jun 24, 2023)</ref>
<ref name="unnamed-11228">[https://old.reddit.com/r/CryptoCurrency/comments/rjl6nr/revoke_unlimited_usage_from_contracts/ Revoke Unlimited Usage from Contracts. : CryptoCurrency] (Jun 24, 2023)</ref></references>
</references>

Revision as of 10:03, 3 July 2023

Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

Grim Finance

Despite an audit, Grim Finance's smart contract hot wallets suffered an exploit where they allowed an attacker to add a malicious smart contract, gaining extra shares. The attacker appears to have gotten away with roughly $30m in Fantom. Grim Finance is working on a compensation plan for affected users. Solidity Finance, who provided the audit, deflected blame to a junior developer who they hired to perform that particular audit.

This is a global/international case not involving a specific country.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21][22][23][24][25][26][27][28][29][30][31]


The Grim Finance platform, associated with the self.FantomFoundation, was hacked by an unknown individual or group. The hacker's account was identified as 0xdefc385d7038f391eb0063c2f7c238cfb55b206c. The stolen amount at the time was reported to be €24,583,420.676 €29,080,834.875. Users who had invested in Grim Finance expressed their disappointment and shared their experiences. Some users mentioned losing their LP (liquidity provider) tokens, while others mentioned being affected by the hack. There were discussions about the risks involved in decentralized finance (DeFi) and the need to diversify investments across multiple platforms. Some users shared their strategies for reducing risk, such as manually compounding earnings on Tomb Finance or reducing their exposure to specific platforms. There were also mentions of other projects affected by the hack, such as Boo Vaults, Pod Town, Spirit, and gSpirit. Some users expressed their intent to buy TOMB and other assets during the dip caused by the hack. The hack itself was discussed in a Twitter thread, where it was explained that the hacker exploited a vulnerability in the vault by making multiple deposits simultaneously. Concerns were raised about the effectiveness of audits and the possibility of insider involvement in the hack. Overall, the hack of Grim Finance had a significant impact on users and raised questions about the security and reliability of DeFi platforms.

About Grim Finance

"Compounding Yield Optimizer Built on Fantom Opera. Allowing users to reap more crypto with crypto."

"Grim Finance is a Smart Yield Optimizer Platform that allows users to stake LP-Tokens issued from AMMs (Automated Market Makers) in Grim Vaults, which automatically harvest and re-stake their rewards as LP-Tokens for a compounding effect. Helping users reap more rewards, hassle-free."

"Grim Finance is a fork from Beefy Finance, Convex Finance, hybrid of different complex strategies and with an enhanced user experience and expansive selection of Fantom pools spanning the entire ecosystem. Grim users have access to Liquid Boost Vaults, which were designed to boost liquidity to a designated pool in the AMM’s."

The Reality

"When [Solidity Finance was] conducting the Grim Finance audit ~4 months ago, [their] firm was experiencing rapid growth and hiring. This audit was performed by an analyst who was new to the team & while [their] CTO was on vacation; and unfortunately this issue was not caught in [their] peer review process."


[32]

If you compound manually on Tomb yourself, your tokens are only exposed to Tomb's code. If you autocompound through Reaper or a similar site, you're exposing your tokens to their code, in addition to Tomb's code (i.e. two layers of smart contracts). So you're doubling your risk of losing your tokens due to a bug or exploit.

What Happened

The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.

Key Event Timeline - Grim Finance Reentrancy Attack
Date Event Description
December 18th, 2021 12:45:19 PM MST Hack Shared To Reddit The hacking event is shared to Reddit by ricardo_mribeiro[29] on the FantomFoundation subreddit. The hacker's account was identified as 0xdefc385d7038f391eb0063c2f7c238cfb55b206c. The stolen amount at the time was reported to be €24,583,420.676, revised to €29,080,834.875. Users who had invested in Grim Finance expressed their disappointment and shared their experiences. Some users mentioned losing their LP (liquidity provider) tokens, while others mentioned being affected by the hack. There were discussions about the risks involved in decentralized finance (DeFi) and the need to diversify investments across multiple platforms. Some users shared their strategies for reducing risk, such as manually compounding earnings on Tomb Finance or reducing their exposure to specific platforms. There were also mentions of other projects affected by the hack, such as Boo Vaults, Pod Town, Spirit, and gSpirit. Some users expressed their intent to buy TOMB and other assets during the dip caused by the hack. The hack itself was discussed in a Twitter thread, where it was explained that the hacker exploited a vulnerability in the vault by making multiple deposits simultaneously. Concerns were raised about the effectiveness of audits and the possibility of insider involvement in the hack[29].
December 18th, 2021 6:06:09 PM MST Revoke Permissions Reference A Reddit thread references the recent hack of Grim Finance, where the hacker's account holds around $3 million, as a devastating blow to both the platform's users and the wider crypto community. To protect ourselves from such hacks, it states the importance of revoking the authorization of smart contracts. This can be done through the Token Approval option on blockchain trackers, typically found under the three-dot overflow menu. By doing this, we can prevent smart contracts from having unlimited access to the tokens they interacted with in our wallets. Although revoking authorization may involve gas fees, it is a simple step we can take to ensure our safety in the world of DeFi. Additionally, tools like allowance.beefy.finance can help purge contracts and allowances, offering further protection against potential exploits[33].
December 20th, 2021 Incident Shared To Rekt The Grim Finance hack is shared to Rekt[1]. Grim Finance, a fork of Beefy Finance, has suffered a devastating attack resulting in an 80% drop in the price of its native token, $GRIM. The attack exploited a vulnerability related to reentrancy in the depositFor() function. By looping false deposits within the initial call, the hacker was able to increase their share of the vault significantly. The attacker's address has been identified as 0xdefc385d7038f391eb0063c2f7c238cfb55b206c, and the Grim Finance team is conducting an investigation to trace the movement of funds and has found connections to various centralized exchanges (CEXs). Charge DeFi, another project, also fell victim to a similar attack just hours before. While Charge DeFi claims to have warned other projects about the vulnerability, it appears that the warnings may not have had the desired effect. There are claims from a Discord user that some of the stolen funds will be donated to charity, but the incident remains a grim Christmas for the unwilling donors.

Technical Details

This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?


"The root cause of the issue was the ability of users to input arbitrary addresses and have them called within the depositFor function. Via reentrancy, the issue allowed users to falsely increase their shares in Grim's vaults and subsequently withdraw more than they had deposited."

"This was an advanced attack. The attacker attacked using the function titled beforeDeposit() from our vault strategy entering a malicious token contract." "The malicious contract was used as the token input parameter to the depositFor() function in the Vault."

"The malicious token contract can start 5 reentrancy loops from safeTransferFrom(), where in all 5 rentrancies, the _pool value is set to the current balance(). On the last safeTransferFrom(), the rentrancy loop is broken, and some want can be transferred to the strategy, which will increase the _amount to put the vault in a state to mint shares."

"On the unwinding of the 5 rentrancies, each loop will see that the _amount is not 0, and mint the corresponding shares, mint the same share count 5x (the number of rentrancy loops)." "The code which was exploited was present in multiple vaults, resulting in a loss of funds across the platform's vaults."

The hacker's account was identified as 0xdefc385d7038f391eb0063c2f7c238cfb55b206c[29].


https://twitter.com/RugDocIO/status/1472293717725913089

Total Amount Lost

The total amount lost has been estimated at $30,000,000 USD.

How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?

Immediate Reactions

How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?


"Grim Finance vaults were exploited today by unknown 3rd party." "It is with heavy hearts that we inform you that our platform was exploited today by an external attacker roughly 6 hours ago. The attackers address has been identified with over 30 million dollars worth of theft."

"Both the Grim Team and our external auditing firm Solidity Finance failed to detect an external threat in our code in the Grim Vault contract. The attacker used a malicious token contract to mint shares of the vaults and dilute the pools, allowing them to steal funds within the vaults."

"We have paused all of the vaults to prevent any future funds from being placed at risk, please withdraw all of your funds IMMEDIATLY as Nikar0 mentioned in the previous post." "They will need to be unpaused for users to remove their funds. More info on that asap. Do try to keep withdrawing, as the vaults will have to be unpaused 1 by 1 for funds to be withdrawn."

"We have contacted and notified Circle (USDC), DAI, and AnySwap regarding the attacker address to potentially freeze any further fund transfers." "Reached out to CoinHomes, DAI, USDC anyswap etc to report the theft, main account has been flagged and we are tracking additional accounts via the form above."

"The depositFor exploited function has been removed from the vault contract. Sentinel contract (killswitch) created to remotely lock all vaults to help stop any future attack. TVL monitor for vaults routinely checking for abnormal TVL movements to notify team."

Community Reactions on Reddit

[33][34][35][36][37][38][39][40][41][42]

Lost my TOMB-FTM LP, but managed to pullout my WMemo. Absolutely gutted. At least I was able to get something back. I actually got done twice today as I'm also in charge which also got hacked, 2 in one day seriously hurts, although Charge defi have said they will compensate everyone, its been silence from Grim so far. Its a stark reminder about the risks involved, my first time experiencing the dark side of defi. To anyone reading this please please ensure you spread your risk across multiple platforms if you're not already. Grim has multiple audits from respected auditors, can happen to any protocol, I'm certainly going to be treading very cautiously moving forward. I have been doing my due diligence yet I still got burnt (luckily not totally rekt), although I'll be spreading my portfolio more thinly in the future, makes it harder to manage, however, will be worth it.

I've been manually compounding on Tomb once a day. Was tempted to use an autocompounder but didn't want to take on the extra layer of risk just to save a minute of time each day. Really glad I stuck to the manual approach!

I lost my entire tomb-ftm lp it was substantial. There was also the boo vaults got rekt. So when they dump that boo price will tank. Pod town was using the reaper logic for their pools…rekt. Spirit and gspirit rekt. It’s an awful awful ripple. I’m gutted drunk and sad. I was Christmas shopping with my wife and kid. I saw my chat going bananas. Life is pain and that’s it.

Honestly speaking, all the audits are paid services and I am not even sure they do a good job. For grim it is a simple lack of guard in smart contract. How the heck these audits miss this simple fact. I guess, not all bugs are simple even though they are simple in retrospect. But these audit cost from 20k to 50k and they don’t do shit? I think this is an inside job. Go check rugdoc and read their updates for grim finance . It is all fishy.

Thats absolutely crazy. I had about 40% of my net worth in there. I am in the navy, currently out sailing, and I deleted my metamask browser extension before I left home, for security reasons lol. Now I cant even check my wallet. Hope they will get returned somehow, or magically still be in my wallet. Was all tomb-ftm lps emptied out? Insane if its lost, half a year work out the window.

Defi is a dangerous place to be, especially as a soft brained monkey. Fantom defi was my dream of financial freedom. APY off more than 1k was too good to be true after all. I think I am done with Defi now. I had all my ftm in grim, half of my life savings gone in 2 seconds.

I need hopium badly right now!

Holy shit, this sucks. I'm currently at work and dont have my hardware wallet with me, what should i do when i get home? Check the vault? Revoke permissions to grim on debank? Withdraw funds if they are available? This is such a bad situation, have no idea what i should do

Can't get my funds out I think they locked the site down.

Lost 25% of my defi portfolio, really hurts as an 18yo college student

Recently, Grim Finance was hacked. The hacker's account, 0xDefC385D7038f391Eb0063C2f7C238cFb55b206C has around $3 Million in it. This is devastating for everyone of their users and for the crypto community as a whole. Anyone who would have taken the pains to revoke Smart Contract Authorization after they have done interacting with the Grim Finance Dapp would have been safe from such a hack.

Market Price Drop

[43]

Agreed - wasn't FUD that dropped TOMB price, but the massive sell pressure from the hacker who drained the $25m FTM/TOMB vault from Grim.

Ultimate Outcome

What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?

Solidity Finance Audit Compensation

"We are working with auditing firms to have our contracts audited fully reviewed." "Solidity finance will be providing a free full review of all of our new contracts by a senior member of their staff AND will be paying for an additional audit from another firm (in contact with QuantStamp and Certik but open to suggestions and contact from other established and reputable agencies)." "@certik_io has officially on boarded @financegrim!"

Solidity Finance said "We have scanned all prior audits and can confirm the issue in Grim is not present in any other codebase we've reviewed. Our team has conducted 900+ audits and Grim is the 2nd exploit that has slipped past our process since the firm's founding in 2020 (an exploit rate of ~0.22%)."

Development Of Restitution Plan

"Releasing new token which will be proportionally airdropped to all users impacted by the exploit based on the amount of funds lost. The token will receive 50% of all platform revenues indefinitely and the goal is to have the token appreciate to a level that will be sufficient compensation to the impacted users by creating wealth."

"With GRIM ATH $2 with 10M tokens (ATH market cap of 20 million) we believe that this has the potential to reimburse users significantly Existing GRIM tokens will be able to mint new tokens with existing Grim tokens at an (estimated) 10:1 ratio for the new token, resulting in a capped total supply under 2 million tokens."

"0.2% of all platform fees will be sent to an untouched insurance wallet that will be used to compensate users for the current loss and for any potential future exploits indefinitely." "We are continuing to reach out to project leads from other projects for further avenues to provide restitution to our users via partnerships and any additional means."

"A google form will be released soon requesting detailed information about each user’s scenario to collect information from all impacted users on our platform. In conjunction with our automation, this information will help us in identifying which users were impacted and to what levels and will help us determine the share of the new tokens to be minted along with the total dollar value of compensation required to become whole again through all additional avenues as we continue to explore other means of compensation in depth." "The submission deadline for the form has been set to January 7th allowing just over 2 weeks to submit your claims at which time in coordination with our automation to identify impacted users and the allocation of tokens they will receive as compensation."

"The team has been hard at work at implementing our restitution plan. Our number one priority during this time has been removing the exploit, applying new upgrades and deploying new vaults (154 new vaults to be precise) in order to establish an income allocated to the impacted users of our platform. So far we have completed the implementation of the platforms listed below, and the subsequent list of vaults are awaiting implementation."

"The entire team sincerely apologizes to all of the victims for their loss during the exploit and we will continue to update you on the situation in the coming days."

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

What funds were recovered? What funds were reimbursed for those affected users?

Ongoing Developments

What parts of this case are still remaining to be concluded?

General Prevention Policies

Our framework has two reviews prior to launch, which should come from independent experts. In the case of a smart contract, this would be different firms. However, it's important to understand that smart contract hot wallets can never be certain to be completely secure, and it's best to have most funds in cold storage protected by multi-signature authorization.

Individual Prevention Policies

No specific policies for individual prevention have yet been identified in this case.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Policies for platforms to take to prevent this situation have not yet been selected in this case.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

No specific regulatory policies have yet been identified in this case.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

  1. 1.0 1.1 Grim Finance - Rekt (Jan 3, 2022)
  2. Grim Finance (Jan 3, 2022)
  3. Introduction - Grim.Finance (Jan 3, 2022)
  4. Address 0xdefc385d7038f391eb0063c2f7c238cfb55b206c | FtmScan (Jan 3, 2022)
  5. @financegrim Twitter (Jan 3, 2022)
  6. @financegrim Twitter (Jan 3, 2022)
  7. @financegrim Twitter (Jan 3, 2022)
  8. https://medium.com/@grimfinance11/grim-finance-update-to-exploit-15226e6df736 (Jan 3, 2022)
  9. Grim Findings - Google Sheets (Jan 3, 2022)
  10. @FTMAlerts Twitter (Jan 3, 2022)
  11. @financegrim Twitter (Jan 3, 2022)
  12. @financegrim Twitter (Jan 3, 2022)
  13. @financegrim Twitter (Jan 3, 2022)
  14. @financegrim Twitter (Jan 3, 2022)
  15. Grim Finance - CertiK Security Leaderboard (Jan 3, 2022)
  16. @financegrim Twitter (Jan 3, 2022)
  17. @financegrim Twitter (Jan 3, 2022)
  18. @financegrim Twitter (Jan 3, 2022)
  19. @financegrim Twitter (Jan 3, 2022)
  20. https://medium.com/@grimfinance11/grim-is-back-platform-v2-updates-47dd51ab2f1 (Jan 3, 2022)
  21. Grim Finance Audit - Solidity Finance (Jan 3, 2022)
  22. @SolidityFinance Twitter (Jan 3, 2022)
  23. Fantom Transaction Hash (Txhash) Details | FtmScan (Jan 3, 2022)
  24. @SolidityFinance Twitter (Jan 3, 2022)
  25. CertiK Blockchain Security Leaderboard (Jan 4, 2022)
  26. Santa Hackathon? Visor Finance Marks 7th Hack in December (Dec 1, 2022)
  27. Hacked Grim Finance's Auditors Blame New Analyst For Missing the Issue (Dec 1, 2022)
  28. Tradegrow comments on Grim finance is hacked (Oct 3, 2022)
  29. 29.0 29.1 29.2 29.3 Grim finance is hacked - FantomFoundation Reddit (Jun 5, 2023)
  30. https://apeboard.finance/dashboard/0xdefc385d7038f391eb0063c2f7c238cfb55b206c?tab=HISTORY (Jun 5, 2023)
  31. Ape Board | Cross-chain DeFi Dashboard (Jun 24, 2023)
  32. shiningbird1 - "If you compound manually on Tomb yourself, your tokens are only exposed to Tomb's code. If you autocompound through Reaper or a similar site, you're exposing your tokens to their code, in addition to Tomb's code (i.e. two layers of smart contracts). So you're doubling your risk of losing your tokens due to a bug or exploit." - Reddit (Jul 2, 2023)
  33. 33.0 33.1 Oneofmanyshades - Revoke Unlimited Usage from Contracts. - CryptoCurrency Reddit (Jun 24, 2023)
  34. carlit0s_w4y - "Absolutely gutted. At least I was able to get something back. I actually got done twice today as I'm also in charge which also got hacked, 2 in one day seriously hurts, although Charge defi have said they will compensate everyone, its been silence from Grim so far." - Reddit (Jul 2, 2023)
  35. shiningbird1 - "I've been manually compounding on Tomb once a day. Was tempted to use an autocompounder but didn't want to take on the extra layer of risk just to save a minute of time each day. Really glad I stuck to the manual approach!" - Reddit (Jul 2, 2023)
  36. GoldenKnights1023 - "I lost my entire tomb-ftm lp it was substantial. There was also the boo vaults got rekt. So when they dump that boo price will tank. Pod town was using the reaper logic for their pools…rekt. Spirit and gspirit rekt. It’s an awful awful ripple. I’m gutted drunk and sad. I was Christmas shopping with my wife and kid. I saw my chat going bananas. Life is pain and that’s it." - Reddit (Jul 2, 2023)
  37. TechnicalProposal - "Honestly speaking, all the audits are paid services and I am not even sure they do a good job. For grim it is a simple lack of guard in smart contract. How the heck these audits miss this simple fact. I guess, not all bugs are simple even though they are simple in retrospect. But these audit cost from 20k to 50k and they don’t do shit? I think this is an inside job." - Reddit (Jul 2, 2023)
  38. BidProud3017 - "Thats absolutely crazy. I had about 40% of my net worth in there. I am in the navy, currently out sailing, and I deleted my metamask browser extension before I left home, for security reasons lol. Now I cant even check my wallet. Hope they will get returned somehow, or magically still be in my wallet. Was all tomb-ftm lps emptied out? Insane if its lost, half a year work out the window." - Reddit (Jul 2, 2023)
  39. BidProud3017 - Defi is a dangerous place to be, especially as a soft brained monkey. Fantom defi was my dream of financial freedom. APY off more than 1k was too good to be true after all. I think I am done with Defi now. I had all my ftm in grim, half of my life savings gone in 2 seconds. - Reddit (Jul 2, 2023)
  40. DrChew1 - "Holy shit, this sucks. I'm currently at work and dont have my hardware wallet with me, what should i do when i get home? Check the vault? Revoke permissions to grim on debank? Withdraw funds if they are available? This is such a bad situation, have no idea what i should do" - Reddit (Jul 2, 2023)
  41. AdvancedSimulation - "Can't get my funds out I think they locked the site down." - Reddit (Jul 3, 2023)
  42. Lightning571 - "Lost 25% of my defi portfolio, really hurts as an 18yo college student" - Reddit (Jul 3, 2023)
  43. Eivad69 - "Agreed - wasn't FUD that dropped TOMB price, but the massive sell pressure from the hacker who drained the $25m FTM/TOMB vault from Grim. RIP my $500..." - Reddit (Jun 2, 2023)