Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»HACKING NEWS»Junami Hack Postmortem: What Happened?
HACKING NEWS

Junami Hack Postmortem: What Happened?

By Crypto FlexsApril 18, 20242 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Junami Hack Postmortem: What Happened?
Share
Facebook Twitter LinkedIn Pinterest Email

Note: Ackee audited previous versions of the protocol before the attacked MimCurveStakeDAO strategy was added.

Exploit Causes

The exploit consisted of two hacks, both of which: Price caching vulnerability The first target was Zunami ETH (zETH) and the second target was Zunami Stable (UZD). The first attack was drained. Only 26 WETH, the second is a whopping 1178 WETH.

The root cause was price manipulation using . MIMCurveStakeDao The strategy is to then cache the inflated price for an entire block of UZD (suitable for flash lending) and then reverse the previous operation to profit from the inflated price.

price caching

UZD’s Liquidity Pool (LP) price caching was partially implemented in version 1.0. thanked By Ackee Blockchain. However, it is not used globally and functions as follows: balanceOf Instead of caching, we were making multiple costly calls (calculating LP prices in our strategy).

Caching has been expanded with the following features: totalSupply, balanceOf and allowance later UZD version 1.1. Caching has been adjusted in the following way:

source

This allowed inflated prices to be called in other contracts. balanceOf function.

Version 1.1 was released without an audit. It was later audited by HashEx for the release of v1.2 on October 29, 2023. audit reportNo attack vectors using cached functions were found.

MIMCurveStakeDao Strategy

This strategy was introduced in commit. 6df0ae5. Since the calculation depends on the price and balance of the strategy, an attacker can change the LP price calculation by donating SDT tokens to the strategy. This strategy was audited by HashEx before release (see this). audit report) However, no exploitability was found.

attack

The attack occurred on August 13 and can be viewed here. https://explorer.phalcon.xyz/tx/eth/0x0788ba222970c7c68a738b0e08fb197e669e61f9b226ceec4cab9b85abe8cceb

Or you can check: PoC (Good job DeFiHackLabs!)

We hope this postmortem will be helpful and contribute to making web3 a safer place free of hacking and exploits.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Quantum-secure data storage for app developers with open source Shamir secret sharing for capacitors

November 26, 2025

The Shai Hulud malware has hit NPM as cryptocurrency libraries face a growing security crisis.

November 24, 2025

Aave launches V4 testnet with developer preview of upcoming “Pro” experience.

November 22, 2025
Add A Comment

Comments are closed.

Recent Posts

A Retired Italian Couple Earns $998 Per Day Passively Through 8hoursmining Cloud Cryptocurrency Mining.

November 27, 2025

Mantle And Bybit Unite To Bring USDT0, The Omnichain Deployment Of Tether’s USDT Stablecoin, To The Largest Exchange-Related Network

November 27, 2025

A Retired Italian Couple Earns $998 Per Day Passively Through 8hoursmining Cloud Cryptocurrency Mining.

November 27, 2025

Technance Introduces Institutional-Grade Infrastructure For Exchanges, Fintech Platforms, And Web3 Applications

November 27, 2025

Investors Eye 900× ROI Potential as Ozak AI Continues Record Presale Momentum

November 27, 2025

Korea’s Upbit reports $36 million loss due to Solana hot wallet breach

November 27, 2025

Bitcoin remains stable as Texas allocates $5 million to BlackRock’s IBIT.

November 26, 2025

Bull and Bear Scenarios for XRP That Could Happen in November

November 26, 2025

Quantum-secure data storage for app developers with open source Shamir secret sharing for capacitors

November 26, 2025

Bybit’s 7th Anniversary Shares A $2.5 Million Thank-You With Nearly 80 Million Traders Worldwide

November 26, 2025

MEXC Launches Year-End Golden Era Showdown With 2,000g Gold Bar And BTC From 10 Million USDT Prize Pool

November 26, 2025

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

A Retired Italian Couple Earns $998 Per Day Passively Through 8hoursmining Cloud Cryptocurrency Mining.

November 27, 2025

Mantle And Bybit Unite To Bring USDT0, The Omnichain Deployment Of Tether’s USDT Stablecoin, To The Largest Exchange-Related Network

November 27, 2025

A Retired Italian Couple Earns $998 Per Day Passively Through 8hoursmining Cloud Cryptocurrency Mining.

November 27, 2025
Most Popular

Bitcoin ASIC Creator Says Next Wave of Mining Efficiency Is Coming

May 15, 2024

Tether and Africa Blockchain Institute Partner to Provide Blockchain Education to Students in Côte d’Ivoire

August 9, 2024

Binance Futures Adjusts Leverage and Margin Tiers for Multiple Perpetual Contracts

August 4, 2024
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2025 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.