Platypus Finance Unchecked Stablecoin Collateral: Difference between revisions
(Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/platypusfinanceuncheckedstablecoincollateral.php}} {{Unattributed Sources}} thumb|Platypus FinancePlatypus has introduced a new kind of AMM for stableswap that manages risk autonomously based on the coverage ratio. The new design is intended to solve the problem of liquidity fragmentation and to simplify pool compositions, leading to a better user experience. Platypus...") |
(Initial 30 minutes. All sources integrated.) |
||
| Line 1: | Line 1: | ||
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/platypusfinanceuncheckedstablecoincollateral.php}} | {{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/platypusfinanceuncheckedstablecoincollateral.php}}[[File:Platypusfinance.jpg|thumb|Platypus Finance]]Platypus has introduced a new kind of AMM for stableswap that manages risk autonomously based on the coverage ratio. The new design is intended to solve the problem of liquidity fragmentation and to simplify pool compositions, leading to a better user experience. Platypus recently launched its own stablecoin, USP, but the mechanism was attacked, depegging USP and leaving it heavily undercollateralized. The hack was due to a flaw in USP's solvency check mechanism that allowed the attacker to withdraw the supplied collateral while keeping the borrowed USP. The stolen $8.5M remain in the hacker's contract, of which, $1.5M of stolen USDT has been blacklisted. The culprit has been identified, and the Platypus team is setting up a bounty and encouraging the hacker to reach out to them. | ||
[[File:Platypusfinance.jpg|thumb|Platypus Finance]]Platypus has introduced a new kind of AMM for stableswap that manages risk autonomously based on the coverage ratio. The new design is intended to solve the problem of liquidity fragmentation and to simplify pool compositions, leading to a better user experience. Platypus recently launched its own stablecoin, USP, but the mechanism was attacked, depegging USP and leaving it heavily undercollateralized. The hack was due to a flaw in USP's solvency check mechanism that allowed the attacker to withdraw the supplied collateral while keeping the borrowed USP. The stolen $8.5M remain in the hacker's contract, of which, $1.5M of stolen USDT has been blacklisted. The culprit has been identified, and the Platypus team is setting up a bounty and encouraging the hacker to reach out to them. | |||
== About Platypus Finance == | == About Platypus Finance == | ||
"This Changes Everything. A whole new kind of AMM for stableswap. Lower Slippage. Simpler UX." | Platypus Finance has launched a new stablecoin AMM platform on Avalanche which features an asset liability management model. The platform uses a single-variant slippage function instead of invariant curves, allowing it to better manage liquidity fragmentation and increasing capital efficiency. The platform also allows for open liquidity single-sided AMM managing risk autonomously based on the coverage ratio. Other stableswaps can have complicated pool compositions which can result in higher slippage and bad user experiences, whereas Platypus' new design addresses this. The new AMM platform is a major improvement over first generation stableswaps. Platypus Finance describes their protocol on their website<ref name="platypusfinance-10860" />.<blockquote>"This Changes Everything. A whole new kind of AMM for stableswap. Lower Slippage. Simpler UX." | ||
"One of the major problems found in the first generation stableswaps’ Closed liquidity pools is liquidity fragmentation, where the liquidity of different pools cannot be shared with one another, resulting in higher slippage." | "One of the major problems found in the first generation stableswaps’ Closed liquidity pools is liquidity fragmentation, where the liquidity of different pools cannot be shared with one another, resulting in higher slippage." | ||
| Line 15: | Line 10: | ||
"Platypus invents a whole new AMM on Avalanche - Open liquidity single-sided AMM managing risk autonomously based on the coverage ratio, allowing maximal capital efficiency." | "Platypus invents a whole new AMM on Avalanche - Open liquidity single-sided AMM managing risk autonomously based on the coverage ratio, allowing maximal capital efficiency." | ||
"The key concept underpinning Platypus’ design is asset liability management (ALM). Platypus is the first of its kind to use a single-variant slippage function instead of invariant curves." | "The key concept underpinning Platypus’ design is asset liability management (ALM). Platypus is the first of its kind to use a single-variant slippage function instead of invariant curves."</blockquote> | ||
== The Reality == | |||
"A highly-specialised creature may be well suited to its own habitat, but Platypus’ attempts to adapt have ended up dead in the water. | "A highly-specialised creature may be well suited to its own habitat, but Platypus’ attempts to adapt have ended up dead in the water. | ||
Adding to its existing stableswap AMM platform, Platypus recently launched its own stablecoin, USP. However, just 10 days after launch, the new mechanism was attacked, depegging USP and leaving it heavily undercollateralised." | Adding to its existing stableswap AMM platform, Platypus recently launched its own stablecoin, USP. However, just 10 days after launch, the new mechanism was attacked, depegging USP and leaving it heavily undercollateralised." | ||
This sections is included if a case involved deception or information that was unknown at the time. Examples include: | This sections is included if a case involved deception or information that was unknown at the time. Examples include: | ||
| Line 76: | Line 35: | ||
|February 16th, 2023 12:16:54 PM MST | |February 16th, 2023 12:16:54 PM MST | ||
|Exploit Transaction | |Exploit Transaction | ||
|The exploit transaction on the Avalanche blockchain. | |The exploit transaction on the Avalanche blockchain<ref name="snowtrace-10863" />. | ||
|- | |||
|February 16th, 2023 6:42:00 PM MST | |||
|Platypus Finance Announcement | |||
|Platypus Finance posts an announcement on their Twitter about the exploit. They report that the attacker exploited a flaw in the USP solvency check mechanism, using a flashloan to take advantage of a logic error in the contract holding the collateral, resulting in a loss of 8.5 million dollars from their main pool. Platypus Finance has reached out to the hacker to negotiate a bounty in exchange for the return of the funds, and is currently working with Binance, Tether, and Circle to freeze the hacker's funds and prevent further losses. The protocol is covering 35% of user deposits, and the funds in the other pool are unaffected. Platypus Finance is also exploring options for compensation and reimbursement for affected investors. The community has been reassured that the matter is being treated with utmost seriousness and that they will be updated on any progress<ref name="platypusdefitwitter-10862" />. | |||
|- | |||
|February 17th, 2023 9:40:00 AM MST | |||
|RektHQ Article | |||
|The situation gets an honourable mention on the RektHQ aggregator<ref>[https://twitter.com/RektHQ/status/1626622511873155072 RektHQ - "@Platypusdefi lost $8.5M to a flash loan attack on its new stablecoin." - Twitter] (May 3, 2023)</ref>. They report that the platform lost $8.5 million to a flash loan attack on its recently launched stablecoin, USP. The attack occurred just 10 days after the launch and resulted in USP being heavily undercollateralized. The attacker exploited a flaw in Platypus’ USP solvency check mechanism, withdrawing collateral while keeping the borrowed USP. The attack drained the liquidity of other stables, leaving USP depegged by over 50%. The attacker’s address and ENS address were identified by Platypus users, and the team has appealed to the attacker to come forward. This incident highlights the importance of robust security measures in DeFi protocols<ref name="rektnews-10861" />. | |||
|} | |} | ||
== Technical Details == | == Technical Details == | ||
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited? | This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited? | ||
Exploiter contract: <nowiki>https://snowtrace.io/address/0x67afdd6489d40a01dae65f709367e1b1d18a5322/</nowiki> | |||
Exploit: <nowiki>https://snowtrace.io/tx/0x1266a937c2ccd970e5d7929021eed3ec593a95c68a99b4920c2efa226679b430</nowiki> | |||
Exploiter: 0xeff003d64046a6f521ba31f39405cb720e953958 | |||
"The attacker first took a flash loan of 44M USDC which was deposited into Platypus. The resulting LP tokens were then used as collateral to borrow 41.7M USP. | |||
The emergencyWithdraw() function only checks whether the user’s position is currently solvent, but neglects to first check against any the effect of any borrowed funds. This allows the attacker to withdraw the supplied collateral while keeping the borrowed USP. | |||
The collateral was then withdrawn to repay the flash loan, and the USP was swapped via Platypus pools, draining the existing liquidity of other stables (USDC, USDT, DAI, BUSD, etc.)." | |||
== Total Amount Lost == | == Total Amount Lost == | ||
| Line 89: | Line 68: | ||
== Immediate Reactions == | == Immediate Reactions == | ||
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed? | How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed? | ||
=== Platypus Finance Twitter Announcement === | |||
Platypus Finance posted about the incident on Twitter shortly after it happened<ref name="platypusdefitwitter-10862" />.<blockquote>Dear Community, | |||
We regret to inform you that our protocol was hacked recently, and the attacker took advantage of a flaw in our USP solvency check mechanism. They used a flashloan to exploit a logic error in the USP solvency check mechanism in the contract holding the collateral. | |||
Exploiter contract: 0x67afdd6489d40a01dae65f709367e1b1d18a5322/ | |||
Exploit: 0x1266a937c2ccd970e5d7929021eed3ec593a95c68a99b4920c2efa226679b430 | |||
Exploiter: 0xeff003d64046a6f521ba31f39405cb720e953958 | |||
3/ There were losses totaling 8.5M from the main pool. Right now deposits from users are covered up to 35% of their deposits. Funds in other pool are unaffected. The hacker has been contacted to negotiate a bounty in exchange for return of the funds. | |||
4/ We understand that this news may be alarming and unsettling, and we want to assure you that we are treating this matter with the utmost seriousness. We are currently working with several parties, | |||
5/ including Binance, Tether, and Circle, to freeze the funds of the hacker and prevent further losses. Right now, the USDT has been frozen. We are also exploring options for compensation and reimbursement for affected investors. | |||
6/ We understand that this is a difficult time for our community, and we appreciate your patience and understanding. We want to assure you that we are taking this matter seriously and will keep you informed as we make progress. Thank you for your continued support.</blockquote> | |||
== Ultimate Outcome == | == Ultimate Outcome == | ||
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done? | What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done? | ||
"The hack has left USP depegged by over 50% as the attacker swapped the USP for other stables. The stolen $8.5M remain in the hacker’s contract, of which, $1.5M of stolen USDT has been blacklisted." | |||
"The rather simple vulnerability, combined with the loot being left (or possibly trapped) as freezable, centralised stables suggests this heist may have been pulled off by a relatively inexperienced amateur." | |||
"After just a few hours, fellow platypus ZachXBT managed to identify the culprit via their ENS address, linked to the exploiter’s transaction history. The same alias was used for now-deleted Twitter and Instagram accounts. The Platypus team have since appealed to the doxxed exploiter: | |||
We're in the process of setting up a bounty & encourage the hacker to reach out to us. We also welcome anyone with useful information to come forward to us." | |||
== Total Amount Recovered == | == Total Amount Recovered == | ||
| Line 116: | Line 122: | ||
== References == | == References == | ||
<references><ref name="platypusfinance-10860">[https://platypus.finance/ Platypus - A Novel StableSwap: simple, flexible and scalable] (May 3, 2023)</ref> | <references> | ||
<ref name="platypusfinance-10860">[https://platypus.finance/ Platypus - A Novel StableSwap: simple, flexible and scalable] (May 3, 2023)</ref> | |||
<ref name="rektnews-10861">[https://rekt.news/platypus-finance-rekt/ Rekt - Platypus Finance - REKT] (May 3, 2023)</ref> | <ref name="rektnews-10861">[https://rekt.news/platypus-finance-rekt/ Rekt - Platypus Finance - REKT] (May 3, 2023)</ref> | ||
<ref name="platypusdefitwitter-10862">[https://twitter.com/Platypusdefi/status/1626396538611310592 Platypus Finance - "We regret to inform you that our protocol was hacked recently, and the attacker took advantage of a flaw in our USP solvency check mechanism." - Twitter] (May 3, 2023)</ref> | |||
<ref name="platypusdefitwitter-10862">[https://twitter.com/Platypusdefi/status/1626396538611310592 | <ref name="snowtrace-10863">[https://snowtrace.io/tx/0x1266a937c2ccd970e5d7929021eed3ec593a95c68a99b4920c2efa226679b430 Avalanche Theft Transaction - SnowTrace] (May 3, 2023)</ref> | ||
</references> | |||
<ref name="snowtrace-10863">[https://snowtrace.io/tx/0x1266a937c2ccd970e5d7929021eed3ec593a95c68a99b4920c2efa226679b430 Avalanche Transaction | |||
Revision as of 21:55, 3 May 2023
Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Platypus has introduced a new kind of AMM for stableswap that manages risk autonomously based on the coverage ratio. The new design is intended to solve the problem of liquidity fragmentation and to simplify pool compositions, leading to a better user experience. Platypus recently launched its own stablecoin, USP, but the mechanism was attacked, depegging USP and leaving it heavily undercollateralized. The hack was due to a flaw in USP's solvency check mechanism that allowed the attacker to withdraw the supplied collateral while keeping the borrowed USP. The stolen $8.5M remain in the hacker's contract, of which, $1.5M of stolen USDT has been blacklisted. The culprit has been identified, and the Platypus team is setting up a bounty and encouraging the hacker to reach out to them.
About Platypus Finance
Platypus Finance has launched a new stablecoin AMM platform on Avalanche which features an asset liability management model. The platform uses a single-variant slippage function instead of invariant curves, allowing it to better manage liquidity fragmentation and increasing capital efficiency. The platform also allows for open liquidity single-sided AMM managing risk autonomously based on the coverage ratio. Other stableswaps can have complicated pool compositions which can result in higher slippage and bad user experiences, whereas Platypus' new design addresses this. The new AMM platform is a major improvement over first generation stableswaps. Platypus Finance describes their protocol on their website[1].
"This Changes Everything. A whole new kind of AMM for stableswap. Lower Slippage. Simpler UX."
"One of the major problems found in the first generation stableswaps’ Closed liquidity pools is liquidity fragmentation, where the liquidity of different pools cannot be shared with one another, resulting in higher slippage."
"The design of other stableswaps requires multiple tokens of equal value within a pool, often complicating its pool compositions (pairing up LP token with new tokens). It significantly hinders the scalability of the protocol and leads to bad user experience."
"Platypus invents a whole new AMM on Avalanche - Open liquidity single-sided AMM managing risk autonomously based on the coverage ratio, allowing maximal capital efficiency."
"The key concept underpinning Platypus’ design is asset liability management (ALM). Platypus is the first of its kind to use a single-variant slippage function instead of invariant curves."
The Reality
"A highly-specialised creature may be well suited to its own habitat, but Platypus’ attempts to adapt have ended up dead in the water.
Adding to its existing stableswap AMM platform, Platypus recently launched its own stablecoin, USP. However, just 10 days after launch, the new mechanism was attacked, depegging USP and leaving it heavily undercollateralised."
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
- When the service was actually started (if different than the "official story").
- Who actually ran a service and their own personal history.
- How the service was structured behind the scenes. (For example, there was no "trading bot".)
- Details of what audits reported and how vulnerabilities were missed during auditing.
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
| Date | Event | Description |
|---|---|---|
| February 16th, 2023 12:16:54 PM MST | Exploit Transaction | The exploit transaction on the Avalanche blockchain[2]. |
| February 16th, 2023 6:42:00 PM MST | Platypus Finance Announcement | Platypus Finance posts an announcement on their Twitter about the exploit. They report that the attacker exploited a flaw in the USP solvency check mechanism, using a flashloan to take advantage of a logic error in the contract holding the collateral, resulting in a loss of 8.5 million dollars from their main pool. Platypus Finance has reached out to the hacker to negotiate a bounty in exchange for the return of the funds, and is currently working with Binance, Tether, and Circle to freeze the hacker's funds and prevent further losses. The protocol is covering 35% of user deposits, and the funds in the other pool are unaffected. Platypus Finance is also exploring options for compensation and reimbursement for affected investors. The community has been reassured that the matter is being treated with utmost seriousness and that they will be updated on any progress[3]. |
| February 17th, 2023 9:40:00 AM MST | RektHQ Article | The situation gets an honourable mention on the RektHQ aggregator[4]. They report that the platform lost $8.5 million to a flash loan attack on its recently launched stablecoin, USP. The attack occurred just 10 days after the launch and resulted in USP being heavily undercollateralized. The attacker exploited a flaw in Platypus’ USP solvency check mechanism, withdrawing collateral while keeping the borrowed USP. The attack drained the liquidity of other stables, leaving USP depegged by over 50%. The attacker’s address and ENS address were identified by Platypus users, and the team has appealed to the attacker to come forward. This incident highlights the importance of robust security measures in DeFi protocols[5]. |
Technical Details
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?
Exploiter contract: https://snowtrace.io/address/0x67afdd6489d40a01dae65f709367e1b1d18a5322/
Exploit: https://snowtrace.io/tx/0x1266a937c2ccd970e5d7929021eed3ec593a95c68a99b4920c2efa226679b430
Exploiter: 0xeff003d64046a6f521ba31f39405cb720e953958
"The attacker first took a flash loan of 44M USDC which was deposited into Platypus. The resulting LP tokens were then used as collateral to borrow 41.7M USP.
The emergencyWithdraw() function only checks whether the user’s position is currently solvent, but neglects to first check against any the effect of any borrowed funds. This allows the attacker to withdraw the supplied collateral while keeping the borrowed USP.
The collateral was then withdrawn to repay the flash loan, and the USP was swapped via Platypus pools, draining the existing liquidity of other stables (USDC, USDT, DAI, BUSD, etc.)."
Total Amount Lost
The total amount lost has been estimated at $8,500,000 USD.
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Immediate Reactions
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Platypus Finance Twitter Announcement
Platypus Finance posted about the incident on Twitter shortly after it happened[3].
Dear Community,
We regret to inform you that our protocol was hacked recently, and the attacker took advantage of a flaw in our USP solvency check mechanism. They used a flashloan to exploit a logic error in the USP solvency check mechanism in the contract holding the collateral.
Exploiter contract: 0x67afdd6489d40a01dae65f709367e1b1d18a5322/
Exploit: 0x1266a937c2ccd970e5d7929021eed3ec593a95c68a99b4920c2efa226679b430
Exploiter: 0xeff003d64046a6f521ba31f39405cb720e953958
3/ There were losses totaling 8.5M from the main pool. Right now deposits from users are covered up to 35% of their deposits. Funds in other pool are unaffected. The hacker has been contacted to negotiate a bounty in exchange for return of the funds.
4/ We understand that this news may be alarming and unsettling, and we want to assure you that we are treating this matter with the utmost seriousness. We are currently working with several parties,
5/ including Binance, Tether, and Circle, to freeze the funds of the hacker and prevent further losses. Right now, the USDT has been frozen. We are also exploring options for compensation and reimbursement for affected investors.
6/ We understand that this is a difficult time for our community, and we appreciate your patience and understanding. We want to assure you that we are taking this matter seriously and will keep you informed as we make progress. Thank you for your continued support.
Ultimate Outcome
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?
"The hack has left USP depegged by over 50% as the attacker swapped the USP for other stables. The stolen $8.5M remain in the hacker’s contract, of which, $1.5M of stolen USDT has been blacklisted."
"The rather simple vulnerability, combined with the loot being left (or possibly trapped) as freezable, centralised stables suggests this heist may have been pulled off by a relatively inexperienced amateur."
"After just a few hours, fellow platypus ZachXBT managed to identify the culprit via their ENS address, linked to the exploiter’s transaction history. The same alias was used for now-deleted Twitter and Instagram accounts. The Platypus team have since appealed to the doxxed exploiter:
We're in the process of setting up a bounty & encourage the hacker to reach out to us. We also welcome anyone with useful information to come forward to us."
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
What parts of this case are still remaining to be concluded?
Individual Prevention Policies
No specific policies for individual prevention have yet been identified in this case.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Policies for platforms to take to prevent this situation have not yet been selected in this case.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
No specific regulatory policies have yet been identified in this case.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ Platypus - A Novel StableSwap: simple, flexible and scalable (May 3, 2023)
- ↑ Avalanche Theft Transaction - SnowTrace (May 3, 2023)
- ↑ 3.0 3.1 Platypus Finance - "We regret to inform you that our protocol was hacked recently, and the attacker took advantage of a flaw in our USP solvency check mechanism." - Twitter (May 3, 2023)
- ↑ RektHQ - "@Platypusdefi lost $8.5M to a flash loan attack on its new stablecoin." - Twitter (May 3, 2023)
- ↑ Rekt - Platypus Finance - REKT (May 3, 2023)