Lending Protocol Sonne Finance Exploited for $20M

Lending Protocol Sonne Finance Exploited for $20M

Reported by The Block, Sonne Finance, a decentralized lending protocol, experienced an exploit on Wednesday morning in Asia, resulting in losses amounting to approximately $20 million.

The project said in a post-mortem report that it was exploited due to a vulnerability in Compound v2 forks (Sonne is one). The hacker “was able to exploit the protocol for ~$20M with the known donation attack.”

In response to the attack, Sonne Finance wrote in a post on X that it had paused all markets on Optimism, while those on Base remained operational.

Sonne Finance’s move came shortly after blockchain security firm PeckShield warned on X and advised Sonne to check their timelock contract. The team added that it became aware of the issue “25 minutes after the exploit.”

The team explained in the post-mortem that it recently passed a proposal to add VELO markets to Sonne.

“We scheduled the transactions on multisig wallet, and because there is 2 days timelock, we also scheduled c-factors to be executed in 2-days,” the team wrote. “The exploiter executed 4 of the transactions when 2-day timelock ends for the creation of markets, and after that, executed the transaction for adding c-factor to the markets.”

Sonne added that while they aren’t able to save the funds, “the investigation on the exploiter’s identity is still going on.”

The project said it is ready to offer a bounty to the exploiter in exchange for return without disclosing more details.

Source

Security Incidents

In This Article

Related News
Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain
Stablecoin neobank Infini exploited for $49 million: security analysts Stablecoin neobank Infini exploited for $49 million: security analysts
NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation
Users Lost $69M in $WBTC due to Address Poisoning Users Lost $69M in $WBTC due to Address Poisoning
Prisma Finance Exploited for $12M Prisma Finance Exploited for $12M
Latest News More More
1 Day Ago Eliza Labs unveils auto.fun, a no-code AI agent launchpad with 'fairer than fair' token model
1 Day Ago Non-KYC exchange eXch to close down under money laundering scrutiny tied to Lazarus Group
2 Days Ago Base scrutinized over promotion of token that briefly crashed 95%; says part of 'contentcoin' vision
4 Days Ago Layer 1 MANTRA's token falls 90% in sudden crash; team blames 'reckless liquidations'
4 Days Ago Canada to launch spot Solana ETFs this week: report
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open