>third hack in 1 year
>THE REAL lend/aave they sad

I was about to buy that shitcoin last week but then I saw that terrible shit logo and turned 360 degrees and walked away

but the logo is turning 270 degrees

I'm so happy I doubles my money and got out of this thing.

>they read the recipient's balance before applying the change to the sender's balance

Can anyone familiar with Solidity explain why moving those two terms without changing anything leads to the exploit?

I thought it was audited multiple times? Kek. Should I sell?

im noob but...
if the array index variables match, youre able to transfer to yourself even if you have 0 or less eth

e.g. say some user with id 400 has 2 eth

_balancesFrom = balances[400]
_balancesTo = balances[400]

the code is getting the balances for both users first (aka the same user) then subtracting the eth WITHOUT recalculating the now corrected balance ready for the send.

im phone posting so could explain better but essentially the .sub tracted value is being set to the balance, however the unsubtracted value is being set back to the balance during the .add

>turned 360 degrees
>walked away

absolute state of US education

that's been a meme for 14 years newfag

are you absolutely new to the internet, zoomer?

>turned 360 degrees and walked away

I still don't get it, but thanks for the (you), anon. Don't the calculations still get carried out in the same code block? I don't see where _from and _to are being compared.

yeah i fucked up the explanation

the users balance is being deducted properly during the From aka .sub section, however in the To aka .add section, the users balance is being changed back to what it originally was PLUS the transfer amount.

so if a user has 10 eth and transfers 2 eth to himself, he ends up with 12 eth, instead of just staying at 10. this is because the second operation is using the original balance amount for its calculation instead of the updated deducted value (which would be a balance of 8 in this case)

the code essentially does this:
balance = 10
balance = 8 (-2)
balance = 10
balance = 12 (+2)

so i was looking at this code and i'm pretty amateur with solidity and coding in general but heres my explanation...
example, user id 400, he has 1 ETH

on the left:
balancesFrom = balances[400] = 1 ETH
balancesTo = balances[400] = 1 ETH

then balancesfromnew executes using balancesFrom, subtracing 1 eth from balancesFrom to 0 eth final

then balancestonew executes, using balancesto, adding 1 eth to balances[_to] which results in 2 eth total

on the right, balances[_from] gets subtracted from first, and in the case that balances[_from] and balances[_to] are the exact same thing, then balances[_to] gets updated at this moment, too.

also the code on the right in your pic is the fixed code, the left is the exploitable shit

holy fuck

and this code was supposedly audited?

oof bzrx took a nasty hit on this hack didn't they? hope you anons are at stop losses

How to set a stop loss on uniswap

its bad. i can see how it was overlooked though, because it only works when you transfer to yourself, which is something people wouldnt really think about being a normal action.

Ah, I get it, since the two balance addresses are the same, the _to overwrites the _from. Thanks, fellas.

So all that shite on the website about how they adopted TDD and testing after the last hack, was bullshit. Because this is the exact kind of edge case that TDD should catch.

i will say its pretty fucking hilarious how bzrx touted being the "most audited DeFi protocol" and then got fucked by a smart contract vulnerability within weeks of releasing

I don't see an option to transfer on their site.

>> No.22464568

yeah, and they're already using their insurance fund lol

you need to interact with the Eth contract directly.

It's less surprising if all the audits are caused by repeated hacks. But it's a nice spin on their own mess-ups. Kek.

now you know audits are a scam

They keep talking about an insurance fund, is this really going to fucking happen. Because how could they have an insurance fund after 10 days

they are going to dump bzrx to fund the losses of course.

everyone who loses money on this fully deserves it. Only a complete idiot invests in something that was hacked in such a dumb way before.

220k link missing to apparently

>> No.22464725

Nice bait

4.7k ETH
220k LINK


so glad i got out holy shit.

i sold. i could made over 100 grand in profit but i held through the crash a few days ago and now there is another fucking hack. unbelievable

I should be good right then? because I dont hold any bzrx but I was lending

I don't know, is there even enough demand for bzrx to fill the 4.7k eth loss?

This happened 2 day ago too. They've been lying, this is close to fraud at this point

fuck thank god i was planning to lend it to them

How do I learn how to drain pools? it doesn't seem that hard if there's shitty abusable code/features involved. Btw how come the original AMPL didn't get its geyser drained?

>> No.22464895

I know almost nothing about programming and yet that seems like the most basic shit ever.

How could they make such a simple mistake, and even worse, how could the auditors not catch it?

I'm actually more worried about the quality of these audits than this one coin...

>Women in programming

Why hasn't this shitty team said anything about the 220k link? I'm a Link whale and four days ago put 100k, yes I'm fucking serious (sadly), into this shit project because I was an IDIOT who bought into "we're the most audited protocol in DeFi hype". Am I fucked? How is their insurance going to cover $2m in lost Link when this dumpster fire will be heading to $0.

It's not
I feel sorry for you guys who will lose their Link from thhis

well atleast u still have ilink

yes you are, and so am I

youre going to get vbzrx tokens mate, gutted for you.

nah you're good link fren. market always forgets

Jesus christ man yo put $1.2 million in link in fulcrum? Was that your whole stack did you get blinded by the APR return?

I just looked at the stats page and there is 24 ilink left.

Basically I think they will try and sell of vbzrx to pay you back but those tokens are now pretty much worthless.

Basically I think you are about to take a 97% loss sorry mate hope that wanst everything you had jesus man.

Sorry, I'm a newfag and I'm trying to get out of this shitshow by selling it off through kyberswap, but it looks like the transaction on ethescan is pending and will take more than an hour. How do I cancel the transaction?

Send the same transaction, or different one just sending 0 eth to yourself, with the same nonce. You need to enable nonces in advanced settings of Metamask. Metamask also has an "attempt cancel" function that does the same thing.

ffs the incompetence in the defi space is next level. bzrx is now yam tier, except yam at least wasn't exploited 3x

Thankfully I still have 700k remaining. I'll stick to usng AAVE and yearn.finance going forward. I was lured in by the attractive lending apy and the "We're so secure" bullshit marketing. I got what I deserve for being a dumbass. Lesson learned.

You can't be serious, why in the hell would you risk that much link in a pajeet coded platform ... you only have one option left: take the bzx team to kleros court

>you only have one option left: take the bzx team to kleros court

What's the current APY on USDC? I'm on mobile and have had a 5x ETH short going. I guess I'll probably lose everything by the time I get home. That was half my stack.

Just know that yearn is also barely audited unless you purchase insurance through nexus but they are maxed out. Dont do it bro the risks are to high right now to lend in my opinion for the returns its not worth it.

IF Yearn gets haccked ur gonna get fucked out of everything.

there are 73 usdc left in the contract, I'm sorry anon.
It's possible they sell bzrx to fill some losses.

>turned 360 degrees and walked away
So you didn't walk away

APY is i think 80% good luck bro hurry back if you can but i think they froze the withdrawals looooool they still arent calling it a hack what a shitshow.

I ape went all in a week ago and happened to be up so I ran to the pc and snap withdrew all my lending tokens. Could have lost it all. Lesson learned no more lending for me fuck too much risk

compound is safe, I don't understand why people think in categories like that. It's just one dapp made by retards

I have 400k untouched in a hardware wallet, 60k LINK in the yaLink vault which I'll be taking out tomorrow, and 250k Link in AAVE as collateral on a 500k usdt loan that was put into the Curve ypool. That yCRV in the yCRV vault on yearn is making me $4-500 per day. Going to leave that in there and take the risk like a degen.

Holy shit i didnt realize just saw that so the 593k usdc locked up is the borrower side right? So basically if you lent out usdc you are fucked woowwwwww.

LIke a few hours ago there was 900k usdc in total avaliable pool i guess there was a "bank" run on usdc tokens as lenders were panic withdrawing thank god i got out jesus christ.

There is no insurance fund team is lying vbzrx is fucking worthless there is no insurance if you havent withdrawn your fucked.

you now remember the music video they made for the relaunch

Fuck man how much LINK did you buy presale? Wow congrats even though you took a loss you got deep pockets.

Question for you im poorfag with 160k usdc is it worth it for me to yolo into curve pool or no?

>Just know that yearn is also barely audited
wrong lesson
what you should learn from this is:
- audits are borderline useless
- trust things made by smart people (like Andre) even if they are unaudited over things made by idiots (bzrx) even if they are audited several times

Thank you.

Little bitch acap strikes again.

>There is no insurance fund team is lying vbzrx is fucking worthless there is no insurance if you havent withdrawn your fucked
Yes, my 5k usdc lent out is not withdrawable. Fucking piece of shit pajeet team

>> No.22466064


I actually bought ETH early, and then after some dumb losses from trading after ETH seemed like it was grabbing around $300 for a while, I discovered Link from Reddit shortly after it started trading on Ether Delta. Pretty much all my Link was bought on there and on Binance within the first week or two of Link trading going live. Been holding for the last three years, but thanks to ChainlinkGod, yearn finance got me interested in actually doing something with my Link since I have the capital. Believe or not I come from a lower middle class family, but threw all $20k of my savings I had after working as a teacher in Asia into Eth and it's changed my life. I can't say what you should or shouldn't do, but I just trust Andre. He was the first to put his money into the protocol and will be the last to take it out. He also has his friends and family's money in yearn, so perhaps not in the vaults. Because I perceive my liquidation risk on Aave of being very low because I'm borrowing less than a quarter of my collateral value, the main risks are with security flaws in curve or yearn, but considering how much value is locked in each, the fact that they haven't been exploited yet with presumably many malicious eyes focused on them is a positive sign. Obviously there's still a high degree of risk.

Holy shit, it's too late for me to make it if whales are already making $400 a day just by sitting on their stacks. Are you looking at any other coins?

right again

Thanks bro and congrats i also had like 20k from propping poker games lol around the time you were teaching in Asia but i bought some eth at $20 and panic sold when the DAO happened and didnt sell the top in 2017 so got fukked hard again just trying to make it.

I will probably loan out some but like you said there is still some risk with yearn but things looking good so far with how much value is locked up.

My only concern is in a bear market if they keep dumping crv wont the aprs go way down for the y pools??

Sorry to hear that man the team is working on a statement loool. They will give you pajeet vbzrx tokens when the bzx token is already crashed another 50% looooooool.

>the next AAVE they called it

use a question mark when you ask a question ffs.

he lost so much he can't afford question marks anymore

Fucking burgers mate

The irony is, there's not yet a secure decentralised platform on which to short bzrx with leverage.

>Thankfully I still have 700k remaining
lmao fuck you dude that's 10x my stack

Fuk that would be epic i would short this shit to 5 cents kek.

been here for 3 years and never heard it

every loss is covered. everyone gets their money back

>hacked in such a dumb way before
it was an oracle exploit... am i missing something? everyone acts like they knew this shit AFTER it has happened. fuck off

>> No.22467019

>> No.22467079

>> No.22467109

>> No.22467115

>> No.22467126

>> No.22467157

>> No.22467163

>> No.22467205

that is a sad story fren

i hope it works out and you get everything back

this. maybe you retards shouldnt have dumped anything in until its survived a while. their code is 99% there. no little homo hack is going to end them. what they should have done is published the code then prevented it going live for 3 months or so while offering a 1m bug bounty. game theory would have solved the rest.

welcome to the wild west.

we all know this project is a fucking joke and will remind everyone at every possible chance

you nigger faggot scammers lost

please simply hold and do not lend. please anon do it for your children and your descendants

that line about battle scars

>> No.22467292
Why exit the yaLink vault?

after warning people multiple times about this incompetent team that still owes me money from their previous hacks, the only thing I got in response is bzrx niggers talking about most audited project and huuurrr durrrr midwit thinks they will be hacked for a THIRD time

hope you all dumped
>he just wants in cheaper
no one is going to touch this shit ever again

Faggots in the telegram are saying this is the bottom little do they know the bottom for bzrx is zero.

Everyone says shit like that all the time about every single coin. If nobody bought anything that was fudded, crypto would no longer exist.

It looks like my margin trade is still going but the APY is up to fucking 120%.

Should I withdraw? It feels risky and the interest is insane but ETH is gonna dump so hard next week.

every single platform that I used doesn't owe me money for their incompetence

in fact only 1 does so no this isn't like every single other coin, keep coping with fact that they fucked up yet again

It's about time to hand out rangebans for promoting ANY crypto related shill. Samson option for /biz/

Get out. If there's a question about the pooled assets, you finna get dumped on. APY makes 100% of the farming profit, but is only a fraction of the risk assesment for the investment.

Did they say they were going to give you money back?

I had 10k in there. Nearly shat myself this morning when the box was empty.. then magically, it showed up again.. earning at 54%apr. Fuck me bros, that was close.

Most of those affected by the old hack have already been paid out.
Those who have not been refunded have not informed themselves about it.

Can you withdraw?? IF you cant that apr is worthless.

>> No.22467611

Found the kike

you cant fucking withdraw

nobody owes you shit. the insurance fund is for retards who cant read contracts they deposit into. youre literally an insurancefund baby kek.

Just got out. No hassle. Maybe it freed up some USD for someone else to withdraw.

>insufficient liquidity for unlend..

>been here for 3 years and never heard it
Because you've only been here for 3 years, newfriend.

yeah. we're fucked.

funds have been stolen

>Kike calling others kike
Classic. I'm going to make some calls tomorrow. I believe in self regulation, but its time to set the wheels for the end if defi on the us and eu market into motion

So your stuck. Enjoy worthless vbzrx tokens lol if they "reimburse" you

>> No.22467755

this fckn lmao
never fails to get (you)s even in [current_year]

Live and learn I guess. That was 1/3 of my link. I will however keep hoping and coping until I can't anymore.

had a good chuckle at this post kek

official incident report is out:

>> No.22468116

>> No.22468174

>> No.22468248

>everyone acts like they knew this shit AFTER it has happened
if I knew how bzx uses uniswap1 as an oracle I could tell you in an instant how to hack it. The first competent guy that looked at it hacked it.

New article on the attack, seems that insurance will cover all losses...

>> No.22468316

>> No.22468347

>> No.22468406

>> No.22468446

>> No.22468487

>> No.22468505

>> No.22468511

>> No.22468544

Wow fuck this. I knew the team was a bit shit but getting exploited another time after all that "most audited" nonsense really takes the cake. Am presaler and held quite a bit of tokens, dumped after the twitter post. I'll be staying out of defi for a while.

Apparently Marc Zeller of Aave was the hacker and was set out to destroy BZX's reputation further. This is clear because some of the wallets involved in the hack had PNK.

>> No.22468636

they should have released the contract with limits so anyone who finds the bug looking for a bigger payday risks getting cucked by someone willing to work for less. saving everyone money.

>219,199.66 LINK
>4,502.70 ETH
>1,756,351.27 USDT
>1,412,048.48 USDC
>667,988.62 DAI


How the fuck are these guys going to recover

File: 71 KB, 760x619, ss+(2020-09-14+at+03.02.20).png [View same] [iqdb] [saucenao] [google]


>> No.22468788

>> No.22468827

>> No.22468851

That was already there from quite some time ago
>> No.22468873

Should I buy BZRX right now? It seems that fear is maxed out right now

>> No.22468960

>> No.22468998

>> No.22469073

one is psychology the other is logical decline in future value.

>> No.22469075

>> No.22469109

>> No.22469118

>> No.22469147

>> No.22469463
What in the living fuck were you thinking to put $1.2m dollars into this???????? You knew they botched the launch already and no one was using their platform right? You just threw over a million dollars down the drain m8.

>> No.22469491
Went all in on this and I have nothing to blame but myself. Should have sold off on the first dip when btc was bleeding back in aug.

Going for the “safe” cryptos for now.

This one hurt.

Bought in around .30, watched it climb to 1.60, fall last week, rise back up to .70 and left work this afternoon to find it shit the bed completely. It might crab back to .60 before dying but I don't want the anxiety anymore

Yeah, the past few days I have been price checking this coin per hour. Stress the hell out of me. Well, live and learn I guess.

>> No.22469643

>> No.22469784

Well, either i'm fucked out of my 10k link, or I end up making a decent return at 53% rewards.
I'm so fucking numb right now.

Aave had a bug too in their app, a week ago, they even disabled all transactions.
Ppl should not make a big deal of it since the bzrx team patched the bug

File: 34 KB, 300x200, 360 degrees.gif [View same] [iqdb] [saucenao] [google]

I've been around since presale till now, totally lost trust in the team after this event
They have great ideas but execution-wise it's just... poor
>> No.22470577

>> No.22470839

>> No.22471000

Presaler here too. I've finally exited all of my BZRX positions. I had some hope when their TVL was coming back up after their botched launch, but now I'm finally seeing that the incompetence of the team will be this project's downfall. I'm happy to take my 20x in $ and a lesson learned even though I could have earned a whole lot more like 60x if I didn't hold hoping that the staking rewards would actually amount to something reasonable. I'm just glad I somehow managed to unlend all my funds that were on Fulcrum. Back to breathing in that LINK hopium I guess.

>> No.22471163

>> No.22471262

>> No.22471329

>> No.22471360

>> No.22471457

>> No.22471492

>> No.22471725

>> No.22471973
i feel your pain. similar to you except i put 50% of my portfolio in

Sold off 250k at around 55cents. I hate myself for not selling the top.

>> No.22472071
>> No.22472073

>> No.22472369

for what reason?