Defrost Hack
What happened
Defrost has been hacked with losses reaching $12M. The protocol’s V1 and V2 have been affected.
There are suspects the attack was an insider job.
On December 23th 2022, Defrost reported they had been exploited due to missing reentarncy lock in flashloan() and deposit() functions. As a result, the share price of LSWUSDC was manipilated and approximately $173K were gained by the attacker.
Later on, it was revealed that the protocol’s vaults have been exploited as well: a fake collateral token was added, and though calling the setOracleAddress() function, the price oracle was replaced with a malicious one leading to liquidations of user collaterals in Defrost’s vaults. The loss estimation is $12M.
The risk of user funds liquidations in case of replacing oracle to a malicious one was reported by Defiyield in its audit:
https://defiyield.app/audit-database/defiyield/defrost_finance
The attacker address:
https://snowtrace.io/address/0x7373dca2…4469f6
The exploit transaction:
https://snowtrace.io/tx/0xc6fb8217…f0212d
An example transaction of the oracle replacement:
https://snowtrace.io/tx/0x34eb46f4…61c3dd
UPD
On December 26th, the Defrost team reported the stolen funds had been returned, and they are going to check onchain what users have been affected in order to send them their funds back.
Case & protocol details
Funds Recovery
Recovered
$12.0M
Net Loss
$0
Evidence & learning
Proof of concept
1 available- Code Defrost Reentrancy
Sources and on-chain records
- report Report de.fi
- analysis Twitter/X Alert twitter.com
- analysis Web Archive archive.ph
- analysis Website reference twitter.com
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.