Platypus Finance Unchecked Stablecoin Collateral
Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Platypus has introduced a new kind of AMM for stableswap that manages risk autonomously based on the coverage ratio. The new design is intended to solve the problem of liquidity fragmentation and to simplify pool compositions, leading to a better user experience. Platypus recently launched its own stablecoin, USP, but the mechanism was attacked, depegging USP and leaving it heavily undercollateralized. The hack was due to a flaw in USP's solvency check mechanism that allowed the attacker to withdraw the supplied collateral while keeping the borrowed USP. The stolen $8.5M remain in the hacker's contract, of which, $1.5M of stolen USDT has been blacklisted. The culprit has been identified, and the Platypus team is setting up a bounty and encouraging the hacker to reach out to them.
About Platypus Finance
Platypus Finance has launched a new stablecoin AMM platform on Avalanche which features an asset liability management model. The platform uses a single-variant slippage function instead of invariant curves, allowing it to better manage liquidity fragmentation and increasing capital efficiency. The platform also allows for open liquidity single-sided AMM managing risk autonomously based on the coverage ratio. Other stableswaps can have complicated pool compositions which can result in higher slippage and bad user experiences, whereas Platypus' new design addresses this. The new AMM platform is a major improvement over first generation stableswaps. Platypus Finance describes their protocol on their website[1].
"This Changes Everything. A whole new kind of AMM for stableswap. Lower Slippage. Simpler UX."
"One of the major problems found in the first generation stableswaps’ Closed liquidity pools is liquidity fragmentation, where the liquidity of different pools cannot be shared with one another, resulting in higher slippage."
"The design of other stableswaps requires multiple tokens of equal value within a pool, often complicating its pool compositions (pairing up LP token with new tokens). It significantly hinders the scalability of the protocol and leads to bad user experience."
"Platypus invents a whole new AMM on Avalanche - Open liquidity single-sided AMM managing risk autonomously based on the coverage ratio, allowing maximal capital efficiency."
"The key concept underpinning Platypus’ design is asset liability management (ALM). Platypus is the first of its kind to use a single-variant slippage function instead of invariant curves."
The Reality
"A highly-specialised creature may be well suited to its own habitat, but Platypus’ attempts to adapt have ended up dead in the water.
Adding to its existing stableswap AMM platform, Platypus recently launched its own stablecoin, USP. However, just 10 days after launch, the new mechanism was attacked, depegging USP and leaving it heavily undercollateralised."
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
- When the service was actually started (if different than the "official story").
- Who actually ran a service and their own personal history.
- How the service was structured behind the scenes. (For example, there was no "trading bot".)
- Details of what audits reported and how vulnerabilities were missed during auditing.
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
| Date | Event | Description |
|---|---|---|
| February 16th, 2023 12:16:54 PM MST | Exploit Transaction | The exploit transaction on the Avalanche blockchain[2]. |
| February 16th, 2023 6:42:00 PM MST | Platypus Finance Announcement | Platypus Finance posts an announcement on their Twitter about the exploit. They report that the attacker exploited a flaw in the USP solvency check mechanism, using a flashloan to take advantage of a logic error in the contract holding the collateral, resulting in a loss of 8.5 million dollars from their main pool. Platypus Finance has reached out to the hacker to negotiate a bounty in exchange for the return of the funds, and is currently working with Binance, Tether, and Circle to freeze the hacker's funds and prevent further losses. The protocol is covering 35% of user deposits, and the funds in the other pool are unaffected. Platypus Finance is also exploring options for compensation and reimbursement for affected investors. The community has been reassured that the matter is being treated with utmost seriousness and that they will be updated on any progress[3]. |
| February 16th, 2023 9:12:00 PM MST | ZachXbt Calls Out The Attacker | ZachXbt traces the attack to Twitter user retlqw, and calls them out publicly after they deactivate their account[4]. |
| February 16th, 2023 9:28:00 PM MST | Attacker Deletes Instagram | The reported attacker has apparently deleted their Instagram account[5]. |
| Funds Recovered From Smart Contract | This is crossposted by Zachxbt[6]. | |
| February 17th, 2023 9:40:00 AM MST | RektHQ Article | The situation gets an honourable mention on the RektHQ aggregator[7]. They report that the platform lost $8.5 million to a flash loan attack on its recently launched stablecoin, USP. The attack occurred just 10 days after the launch and resulted in USP being heavily undercollateralized. The attacker exploited a flaw in Platypus’ USP solvency check mechanism, withdrawing collateral while keeping the borrowed USP. The attack drained the liquidity of other stables, leaving USP depegged by over 50%. The attacker’s address and ENS address were identified by Platypus users, and the team has appealed to the attacker to come forward. This incident highlights the importance of robust security measures in DeFi protocols[8]. |
| Exploiters Arrested By French Police | This is shared by Zachxbt[9]. |
Technical Details
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?
Exploiter contract: https://snowtrace.io/address/0x67afdd6489d40a01dae65f709367e1b1d18a5322/
Exploit: https://snowtrace.io/tx/0x1266a937c2ccd970e5d7929021eed3ec593a95c68a99b4920c2efa226679b430
Exploiter: 0xeff003d64046a6f521ba31f39405cb720e953958
"The attacker first took a flash loan of 44M USDC which was deposited into Platypus. The resulting LP tokens were then used as collateral to borrow 41.7M USP.
The emergencyWithdraw() function only checks whether the user’s position is currently solvent, but neglects to first check against any the effect of any borrowed funds. This allows the attacker to withdraw the supplied collateral while keeping the borrowed USP.
The collateral was then withdrawn to repay the flash loan, and the USP was swapped via Platypus pools, draining the existing liquidity of other stables (USDC, USDT, DAI, BUSD, etc.)."
Total Amount Lost
The total amount lost has been estimated at $8,500,000 USD.
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Immediate Reactions
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Platypus Finance Twitter Announcement
Platypus Finance posted about the incident on Twitter shortly after it happened[3].
Dear Community,
We regret to inform you that our protocol was hacked recently, and the attacker took advantage of a flaw in our USP solvency check mechanism. They used a flashloan to exploit a logic error in the USP solvency check mechanism in the contract holding the collateral.
Exploiter contract: 0x67afdd6489d40a01dae65f709367e1b1d18a5322/
Exploit: 0x1266a937c2ccd970e5d7929021eed3ec593a95c68a99b4920c2efa226679b430
Exploiter: 0xeff003d64046a6f521ba31f39405cb720e953958
3/ There were losses totaling 8.5M from the main pool. Right now deposits from users are covered up to 35% of their deposits. Funds in other pool are unaffected. The hacker has been contacted to negotiate a bounty in exchange for return of the funds.
4/ We understand that this news may be alarming and unsettling, and we want to assure you that we are treating this matter with the utmost seriousness. We are currently working with several parties,
5/ including Binance, Tether, and Circle, to freeze the funds of the hacker and prevent further losses. Right now, the USDT has been frozen. We are also exploring options for compensation and reimbursement for affected investors.
6/ We understand that this is a difficult time for our community, and we appreciate your patience and understanding. We want to assure you that we are taking this matter seriously and will keep you informed as we make progress. Thank you for your continued support.
ZachXbt Tracing The Funds
ZachXbt reportedly traced the funds to Twitter user retlqw[4].
Hi @retlqw since you deactivated your account after I messaged you.
I've traced addresses back to your account from the @Platypusdefi exploit and I am in touch with their team and exchanges.
We’d like to negotiate returning of the funds before we engage with law enforcement.
Ultimate Outcome
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?
"The hack has left USP depegged by over 50% as the attacker swapped the USP for other stables. The stolen $8.5M remain in the hacker’s contract, of which, $1.5M of stolen USDT has been blacklisted."
"The rather simple vulnerability, combined with the loot being left (or possibly trapped) as freezable, centralised stables suggests this heist may have been pulled off by a relatively inexperienced amateur."
"After just a few hours, fellow platypus ZachXBT managed to identify the culprit via their ENS address, linked to the exploiter’s transaction history. The same alias was used for now-deleted Twitter and Instagram accounts. The Platypus team have since appealed to the doxxed exploiter:
We're in the process of setting up a bounty & encourage the hacker to reach out to us. We also welcome anyone with useful information to come forward to us."
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
What parts of this case are still remaining to be concluded?
Individual Prevention Policies
Avoid the use of smart contracts unless necessary. Minimize the level of exposure by removing or withdrawing assets whenever possible. Aim to choose smart contracts which have obtained third party security audits, preferably having been audited by at least three separate reputable firms. Pay attention to the audit reports, which smart contracts are covered, and whether the smart contract has been upgraded or modified since the report. Ensure that any administrative functions with the ability to remove funds from the smart contract are under the authority of a multi-signature wallet which is controlled by at least three separate and reputable entities.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
All aspects of any platform should undergo a regular validation/inspection by experts. This validation should include a security audit of any smart contracts, reporting any risks to the backing (of any customer assets, ensuring treasuries or minting functions are properly secured under the control of a multi-signature wallet, and finding any inadequacies in the level of training or integrity of the team. The recommended interval is twice prior to launch or significant system upgrade, once after 3 months, and every 6 months thereafter. It is recommended that the third party performing the inspection not be repeated within a 14 month period.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
All platforms should undergo published security and risk assessments by independent third parties. Two assessments are required at founding or major upgrade, one after 3 months, and one every 6 months thereafter. The third parties must not repeat within the past 14 months. A risk assessment needs to include what assets back customer deposits and the risk of default from any third parties being lent to. The security assessment must include ensuring a proper multi-signature wallet, and that all signatories are properly trained. Assessments must be performed on social media, databases, and DNS security.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ Platypus - A Novel StableSwap: simple, flexible and scalable (May 3, 2023)
- ↑ Avalanche Theft Transaction - SnowTrace (May 3, 2023)
- ↑ 3.0 3.1 Platypus Finance - "We regret to inform you that our protocol was hacked recently, and the attacker took advantage of a flaw in our USP solvency check mechanism." - Twitter (May 3, 2023)
- ↑ 4.0 4.1 zachxbt - "Hi @retlqw since you deactivated your account after I messaged you. I've traced addresses back to your account from the @Platypusdefi exploit and I am in touch with their team and exchanges. We’d like to negotiate returning of the funds before we engage with law enforcement." - Twitter (May 30, 2023)
- ↑ ZachXbt - "You Deactivated your Instagram too?" - Twitter (May 30, 2023)
- ↑ Zachxbt - "Update: Some of the funds were recovered from the contract." - Twitter (May 30, 2023)
- ↑ RektHQ - "@Platypusdefi lost $8.5M to a flash loan attack on its new stablecoin." - Twitter (May 3, 2023)
- ↑ Rekt - Platypus Finance - REKT (May 3, 2023)
- ↑ Zachxbt - "Update: Suspects caught by French law enforcement" - Twitter (May 30, 2023)