DeFi after 25 million USD hack from dForce or LendfMe now finally dead?


8:58 AM. SCT on April 18:
An attacker used a vulnerability in Uniswap and ERC777 to launch an attack.
The partners try to patch it… says everything is ok… Well…

09:28 AM. SCT on April 19:
Tokenlon received a message from about an attack similar to Uniswap that resulted in a large number of abnormal borrowings on the platform.

The capital in dForce dropped by 99.9%!

Comparison of past attacks

This is just one of many attacks in recent months and years:

How did the hacking go? Keyword: Reentrancy Attack

Reentrancy attacks allow hackers to repeatedly withdraw funds in a loop before the original transaction is approved or rejected.

The similarity between Uniswap and is that both platforms use the same 3 protocols:

  1. protocol — a decentralised financial protocol (DeFi) developed by the dForce Foundation to support credit operations on the Ethereum platform.
  2. imBTC — a coin that runs on the Ethereum platform and is covered in a 1:1 ratio with the Bitcoin crypto currency.
  3. ERC-777 — one of the underlying technologies of the Ethereum block chain that is intended to support Smart Contracts (both and imBTC run as such on the Ethereum platform)

The token standard ERC-777 has — according to Tokenlon, the company behind imBTC — no security gaps.

BUT: However, the combination of the use of ERC-777 tokens and Uniswap/ made the reentrancy attacks possible.

The bummer: It appears that the hackers used an exploit published on GitHub in July 2019 by OpenZeppelin, a company that performs security checks for cryptocurrency platforms.

Result: 25 million loss

It is currently estimated that Uniswap has lost between $300,000 and $1.1 million in funds, while has lost more than $24.5 million.

Actual problem:

Wrong risk / benefit assessment of Turing-Komplett Smart Contract platforms, where everything is possible — greed often eats brains here:

Solution approaches:

  1. Better risk assessment of users
  2. Better audits
  3. No Turing complete DeFi? Example: or others

What’s next for LendfMe?

Negotiate with hackers for refunds and commissions:

Confidence-building possible again?

A lot of people lost their money through this hack. The exciting question now will be, how does LendfMe deal with this and how do the members react in the long run?

In the crypto area we have now witnessed some hacks, some were quickly forgotten and trust was quickly rebuilt. Like the hack from Binance, for example. Binance reacted extremely quickly and compensated all those affected, so Binance was able to quickly regain trust. On the other hand, as with Mt. Gox, there was a total loss…

We will find out in the next few days/weeks what exactly happens next.

Your opinion? Should “bad code must die” be implemented?

Cash flow from crypto-currencies secure and verified — but (still) centralized:

Also check for non-turing-complete DeFi, where such things should not happen in the future.

Your Julian

You can find more such contributions to:




I build @CakeDeFi and I love @DeFiChain, EU Blockchain Advisor, Angel Investor, Washington Bureau Speaker, 5x Bestselling Author, Ex-Pro-Athlete, Ex-Medical-Doc

Love podcasts or audiobooks? Learn on the go with our new app.

Recommended from Medium

Adam S. Tracy Provides an Initial Exchange Offering Regulatory Update

Trading Like a Pro with the Mizar AI Marketplace

Separating the Signal from the Noise in Cryptocurrency-Related Youtube Channels

’08 | Bit what? Bitcoin! — Hello world.

AMA Recap 404 Daily Crypto with Centralex

Central Banks and Sushi 🏦🍣 | TradFi to DeFi Weekly Wrap Up

What are Fungible and Non-fungible tokens in the world of Cryptocurrencies?

Ledger Nano S : Step by Step Tutorial

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Julian Hosp

Julian Hosp

I build @CakeDeFi and I love @DeFiChain, EU Blockchain Advisor, Angel Investor, Washington Bureau Speaker, 5x Bestselling Author, Ex-Pro-Athlete, Ex-Medical-Doc

More from Medium

UAE president Sheikh Khalifa bin Zayed dies at 73

How to reduce the cost of gas for delegating your GRT tokens

MOVE2EARN APY: This is a platform that enables cryptocurrency investors to stake their coins and…

Dating Once more? 10 Should Know Tips!