ChargeDeFi Hacked: The Attacker Gained Approximately $500K

Share IT

Key Takeaways:

  • This morning an attack was made on ChargeDeFi Vault that enabled the attacker to drain 1849 Charge from the vault.
  • It is estimated that the attacker gained approximately $500k before making his getaway.
  • This attack is not a standard flash loan attack, but a flash loan was used to increase his gains.
  • The exploited platform has set up a compensation package and there is a proposal on their Discord.
  • The main focus of this compensation plan is to reimburse the affected investors without causing a major price impact on other holders.ย 
Chargedefi Hacked
ChargeDeFi Hacked

This morning around 07:12 UTC, an attack was made on ChargeDeFi Vault that enabled the attacker to drain 1849 Charge from the vault. The funds were swapped for BNB and immediately sent to tornado.cash, a privacy proxy. It is estimated that the attacker gained approximately $500k before making his getaway. The attacker also made a flash loan on PCS to fund part of this attack. So this is not a standard flash loan attack, but a flash loan was used to increase his gains.

Several forensics agencies have been contacted and ChargeDeFi is continuously investigating this incident as well. The code for these vaults is in use in other projects as well. ChargeDeFi has reached out to them to warn them and have informed them of the details of the attack. ChargeDeFi is waiting for their response, so they have not shared any information on this yet. If they have an issue, they need time to fix it.

ChargeDeFi vaults have been paused while they are investigating it. In addition, a warning has been added to their website. ChargeDeFi has advised that people should remove their Vault stake and move it to the app.beefy.finance for now. The boardroom and all other aspects of ChargeDeFi are unaffected by this incident. 

They have set up a compensation package and there is a proposal on their Discord. The main focus of this compensation plan is to reimburse the affected investors without causing a major price impact on other holders. 

In short, they will identify affected wallets and their Vault value and share all the information with the community, so people know what their balances were. All affected wallets will receive an airdrop of $50 BUSD per Charge that they lost. ChargeDeFi will create a pool to return the missing Charge. Over a period of 30 days, this pool will yield Charge to affected wallets. The affected people can claim and use them at will. At the end of these 30 days, all $Charge will have been returned. The Charge DeFi team will not increase their stake in the boardroom during the compensation period to balance the APR impact of the extra charge entering the ecosystem.

Share IT
Chaahat Girdhar
Chaahat Girdhar

I'm Chaahat Girdhar, a journalist by profession who's turning her dreams into vision and vision into reality. I'm curious and have an appetite for gaining new knowledge. So I'm looking forward to learning things in the better way possible.

Can’t find what you’re looking for? Type below and hit enter!