Midas Capital Virtual Price Reentrancy

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Revision as of 00:47, 4 May 2023 by Azoundria (talk | contribs) (Initial 30 minutes. All sources integrated.)
Jump to navigation Jump to search

Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Midas Capital

Midas Capital is a DeFi protocol that allows users to lend and borrow digital assets, enabling anyone to create and deploy their own lending and borrowing pool. The protocol allows users to choose all of their custom parameters and isolate risk. Pools can be made public or private, depending on the creator's preference, and any asset with on-chain liquidity can be supported within Midas pools. Midas recently added WMATIC-stMATIC Curve LP token for use as collateral, but it has a read-only reentrancy vulnerability that allows the token's virtual price to be manipulated when improperly implemented. This vulnerability led to a recent exploit in which the attacker borrowed several assets against inflated collateral and swapped them for approximately $660k worth of MATIC, which was sent to Kucoin and Binance. Jarvis Network will cover the shortfall in backing of jFIATs resulting from the exploit, and Midas Capital is attempting to negotiate a bounty with the hacker. They are also working on a plan to re-collateralize the jFIATs the protocol lost and reimburse affected users, with the support of their community, partners, investors, and liquidity provider.

About Midas Capital

[1][2]

"CAPITAL EFFICIENT ISOLATED LENDING AND BORROWING POOLS. Create your own custom money markets and maximize capital efficiency for any group of assets."

"There are 3 parts to "Midas Capital," and it is important to recognize the differences between each party involved. The Midas Capital Protocol [is a] DeFi protocol that is built using Smart Contracts and run autonomously on EVM compatible blockchains in order to put crypto assets to use. The Midas Capital UI [is a] web app that provides easy to use tooling in order to interact with the decentralized protocol. This interface is one of the many ways of interacting with the Smart Contracts. The core Midas team that will lead the protocol to full decentralization."

"Midas Capital is an open interest rate protocol that allows users to lend and borrow digital assets. The Midas protocol enables anyone to instantly create and deploy their own lending and borrowing pool. The protocol allows users (individuals, protocols, DAOs, institutions) to choose all of their custom parameters and isolate risk, rather than using a large lending and borrowing pool on other platforms. Pools can be made public or private depending on the creator's preference."

"As Uniswap is to permissionless trading markets, Midas pool has permissionless lending and borrowing. If there is an asset that has on-chain liquidity, it can be supported within Midas pools via a pre-built or custom oracle."

"The nature of Midas Protocol completely removes the need to lobby to money market protocols such as Compound Finance or Aave. Generally, newer tokens to the ecosystem have a very low chance of being listed on these large money markets given their possible risk to the rest of the pool. Midas Protocol allows for isolated versions of Compound Finance which provides users' with full range of composability with their digital assets and the financial freedom not seen in the traditional banking industry."

"Midas recently added WMATIC-stMATIC Curve LP token for use as collateral. These tokens have a read-only reentrancy vulnerability which allows the token's virtual price to be manipulated when improperly implemented."

"Both organisations announced the cause of the attack as the use of WMATIC-stMATIC Curve LP token. The read-only reentrancy vulnerability is a known weakness of this type of LP token, and had previously led to a $220k loss on market.xyz in October."

"[T]he calculation of a position's collateral depends on self.D and totalSupply

self.D is updated after an unexcepted callback, so the four borrows use an outdated self.D.

the contract burns stMATIC-f before the unexcepted callback, which causes the four borrows to use an updated stMATIC-f.totalSupply()."

"As a result, @MidasCapitalxyz over-estimated the attack contract's position and lent excessive assets to the contract."

"The attacker was able to borrow the following assets against the inflated collateral: jCHF: 273,973, jEUR: 368,058, jGBP: 45,250, agEUR: 45,435, Which were then swapped to ~660k MATIC ($660k) and sent on to Kucoin and Binance."

"Jarvis Network will cover the (~$350k) shortfall in backing of jFIATs that resulted from the exploit, and Midas Capital have reached out to the hacker in an attempt to negotiate a bounty."

"We have decided to do not wait after Midas, and we are working on a plan to re-collateralize the jFIATs the protocol lost, and reimburse the users who were victim of the exploit. We will propose to the Jarvis governance to allocate part of the protocol’s revenus (liquidity provision, lending interests, protocol fee and farming with POL) and part of the protocol treasury to it, and we will ask for the help and support of our community, partners, investors, and “frens”. I have already discussed with many of them and they have expressed their will to support us in this difficult moment, either with or without counterparty. Also, the company which is the main liquidity provider within the protocol, will help, with both its treasury and revenues (±$700k last year with swap fees, interests and market making)."

This is a global/international case not involving a specific country.

The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.

Include:

  • Known history of when and how the service was started.
  • What problems does the company or service claim to solve?
  • What marketing materials were used by the firm or business?
  • Audits performed, and excerpts that may have been included.
  • Business registration documents shown (fake or legitimate).
  • How were people recruited to participate?
  • Public warnings and announcements prior to the event.

Don't Include:

  • Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
  • Anything that wasn't reasonably knowable at the time of the event.

There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.

The Reality

[3]

This sections is included if a case involved deception or information that was unknown at the time. Examples include:

  • When the service was actually started (if different than the "official story").
  • Who actually ran a service and their own personal history.
  • How the service was structured behind the scenes. (For example, there was no "trading bot".)
  • Details of what audits reported and how vulnerabilities were missed during auditing.

What Happened

The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.

Key Event Timeline - Midas Capital Virtual Price Reentrancy
Date Event Description
January 15th, 2023 10:43:37 AM MST Exploit Transcation One of the blockchain transactions involved in the exploit[4].
January 15th, 2023 10:56:00 PM MST BlockSecTeam Analysis BlockSecTeam posts an analysis of the exploit on Twitter[5]. TBD review.
January 16th, 2023 1:40:00 AM MST Beosin Alert Posted Beosin posts an alert analysis on Twitter[6]. TBD analysis
January 20th, 2023 9:25:00 AM MST RektHQ Article [7][8]

Technical Details

This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?

Total Amount Lost

The total amount lost has been estimated at $660,000 USD.

How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?

Immediate Reactions

How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?

Ultimate Outcome

What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

What funds were recovered? What funds were reimbursed for those affected users?

Ongoing Developments

What parts of this case are still remaining to be concluded?

Individual Prevention Policies

No specific policies for individual prevention have yet been identified in this case.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Policies for platforms to take to prevent this situation have not yet been selected in this case.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

No specific regulatory policies have yet been identified in this case.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References