Breaking
March 20, 2025

Onyx protocol hacked again for $3.8M through exchange rate exploit | usagoldmines.com

The Onyx lending and borrowing platform has been exploited for $3.8M. Hacken, the security auditing hub, analyzed the unusual activity on the platform and estimated the nature of the attack. 

Onyx Protocol has been affected by an exploit, losing $3.8M. The attack was achieved via a custom-generated malicious contract, deployed just minutes before calling to Onyx. The hacker managed to drain Virtual USD (VUSD), the protocol’s native stablecoin. This is the second hack for Onyx since November 3, 2023, when the TVL of the project also crashed. The exploit led to additional social media attacks, with faked links claiming to safeguard assets. The best approach is to only interact with the official social media of Onyx Protocol. 

Onyx announced that VUSD itself is not affected and will continue to function. However, the exploit ended up destroying the stablecoin’s peg, despite the extra collateral. VUSD crashed to a low of $0.39 and did not recover its $1 nominal level immediately. 

Virtual USD (VUSD) lost its $1 peg after the exploit, not recovering despite the collateral. | Source: Coinmarketcap

While the final sum that the hacker managed to withdraw is small, the protocol’s losses may be deeper. The VUSD token has a nominal circulating supply above $51M, but its current market capitalization is at $19M. 

Onyx faced precision exploit of its exchange rate

One of the reasons for the Onyx exploit was the availability of low-liquidity pools. Analysis by Hacken estimated the exploit was due to an exchange rate miscalculation, when there is low liquidity in some pairs. The hacker prepared a smart contract to swap WETH for Onyx ETH (oETH). 

Starting with a 2,000 WETH loan from Balancer, the hacker moved through several crypto assets. At the same time, the malicious contract spammed Onyx with a series of low-value ETH transactions. The result of the swaps and pool transfers netted the hacker with 3.8M VUSD, nominally valued at $3.8M. 

The final transaction managed to withdraw 300K VUSD, which were swapped for ETH using CoW Protocol split trades. The transactions caused some slippage and the VUSD price was lower than the $1 nominal, so one of the outgoing transactions was for $191K

Other assets from Onyx also affected

The series of attacks against Onyx pools affected several assets. Peckshield identified transfers of 4.1m VUSD, 7.35m Onyxcoin (XCN), 5k DAI, 0.23 WBTC, 50k USDT. All of the transfers happened in one transaction, carried out by the malicious smart contract. 

The hacker also took away multiple tokens: WETH, XCN, DAI, WBTC, and USDT. | Source: Etherscan

Onyx is a Compound V2 hard fork, carrying all the flaws of the protocol. Onyx itself has been hacked before in a similar way, exploiting value calculations and the exchange rate on illiquid pairs. 

Sonne Protocol was exploited in May, again due to known flaws on Compound V2, which affected all forked projects and have not been repaired. The flaw is seen whenever the protocol initiates new, unfunded markets. The introduction of new pairs in a dynamic DeFi space has multiplied the problem, leading to several hacks. 

Due to the miscalculation, the hacker could call the protocol’s smart contract and receive much bigger loans in exchange for negligible collateral. 

The current Onyx attack has a similar structure to the Sonne Protocol hack, again withdrawing a substantial amount of tokens for minimal collateral. The long series of 56 spam transactions whittled away at the Onyx exchange rate, again allowing the hacker to withdraw all funds for a tiny collateral. 

So far, no NFTs have been affected. Onyx Protocol hosts Bored Ape (BAYC) and Mutated Ape (MAYC) NFT for up to 37% annualized passive income. PeckShield also detected a flaw with the project’s NFT contract, though this has not led to an additional exploit.

The attack may be the work of a rogue employee

The Onyx protocol attack is relatively small, even compared to individual wallet attacks. The effect on the value of VUSD and other assets may be bigger. But the attack may be exposing another serious threat to crypto projects – rogue employees. 

The Onyx protocol exploit may be due to a North Korean hacker posing as a project developer. Researchers claim they have contacted the Onyx team with potential evidence of ties to DRPK hackers. 

On the other hand, the Compound V2 vulnerability is well-known, and may not have required insider knowledge to exploit. 

Cryptopolitan reporting by Hristina Vasileva

 

Recent:

Crypto News | Coinbase outlines new regulatory roadmap for SEC in crypto clarity push Oluwapelumi Ad...

Tron’s Justin Sun announces TRX CA on Solana blockchain Hannah Collymore | usagoldmines.com

President Trump Once Again Promises To Make US ‘Undisputed Bitcoin Superpower’ Brenda Ngari | usagol...

Bybit CEO Ben Zhou: 88% of Stolen $1.4 Billion Remains Traceable Jimmy Aki | usagoldmines.com

Coinbase controls 11.42% of staked Ethereum, manages 120k validators Across 5 countries Ol | usagold...

Solana Futures ETFs Hit Wall Street — Will SOL Soar Or Crash? Jake Simmons | usagoldmines.com

Crypto News | Ripple CEO Pushes for XRP in US Reserves, Keeps IPO Option Alive Mandy Williams | usa...

Crypto News | Runes Protocol unveils ‘agents’ to enhance Bitcoin DeFi with native AMM capabilities A...

ZachXBT exposes Hyperliquid whale as British man William Parker Jai Hamid | usagoldmines.com

President Trump demands that Congress pass stablecoin bill Jai Hamid | usagoldmines.com

$10 XRP Price Closer Than Ever As Ripple Emerges Victorious in SEC Lawsuit Olivia Brooke | usagoldmi...

3 Budget-Friendly Cryptos Under $1 Set To Skyrocket 10x Cryptopolitan Media | usagoldmines.com

Crypto News | Pumpfun launches its own DEX called PumpSwap amid falling revenue Gino Matos | usagold...

Bitnomial officially launches the first CFTC-regulated $XRP futures product Florence Muchai | usagol...

Pump.fun announced native PumpSwap DEX with potential revenue share for token creators Hristina Vasi...

Can XRP Overtake Ethereum? XRP Price Surges 13% After SEC Case Win  Harvey Hunter | usagoldmines.com

Chainalysis Uncovers Crypto Transactions Linked to Mexican Drug Cartels and Chinese Labs Jimmy Aki |...

Walrus Foundation Raises $140 Million for Decentralized Storage Networks Hongji Feng | usagoldmines....

EU pushes back retaliatory tariffs on Trump’s US to mid-April Jai Hamid | usagoldmines.com

All-In-One Defi Platform Mutuum Finance (MUTM) Presale Skyrockets, Raises Over $4 Million in Just A ...

Solana Price Mirrors Its 2023 Pattern, Turning Point Or New Lows? This Altcoin Could Be a Safer Bet ...

1 Million Bitcoin In New Whale Hands—A Mega BTC Rally On The Horizon? Christian Encila | usagoldmine...

Canary Capital breaks new ground with an NFT-inclusive crypto ETF featuring Pudgy Penguins Gino Mato...

Crypto News | Bitcoin’s Hot Supply Drops 50% in 3 Months – Bullish or Bearish Signal? Mandy William...

Accenture warns Musk’s Doge-led spending crackdown is hurting revenues Florence Muchai | usagoldmine...

The TON Foundation announced $400M in new token-based financing Hristina Vasileva | usagoldmines.com

Russia to test crypto trading on Moscow Exchange Lubomir Tassev | usagoldmines.com

Cardano (ADA) Whales Spotted Buying Mutuum Finance (MUTM) In Huge Numbers, Here’s Why Cryptopolitan ...

Dogecoin Forms A Daily Bullish Pattern – Analyst Expects A Breakout To $0.43 Sebastian Villafuerte |...

Crypto News | LBank Rated by CoinGape, Solidifying Leadership in Memecoin Trading Chainwire | usago...

Crypto News | Aragon Unveils New Tooling, Ushering in a New Era for Onchain Organizations to Accrue...

Crypto News | Plume and Goldfinch Partner to Expand Access to Private Credit from Apollo, Ares, Gol...

Crypto News | ZachXBT links high-risk Hyperliquid crypto trader to notorious fraudster in UK Oluwape...

Rising interest costs drive global debt over $100 trillion Jai Hamid | usagoldmines.com

BoE keeps rates on hold at 4.5% Florence Muchai | usagoldmines.com

Trump Coin Volume Surges as Trump Prepares for Talk – Do Insiders Know Something? Alejandro Arrieche...

Saga Origins’ New Partnerships Unveil AI-Driven Characters and Evolving Economies Sead Fadilpašić | ...

Europe Leads in Crypto-Friendly Banking With Over 60 Banks Offering Crypto Services Veronika Rinecke...

HyperLiquid Whale Identified as Convicted Fraudster William Parker — ZachXBT Hassan Shittu | usagold...

Trump Calls for Landmark Stablecoin Regulation and “Simple, Common-Sense Rules” Tanzeel Akhtar | usa...

Story Coin Posts 2.5% Gain, Leads Top 100 with 178% Return in 30 Days Simon Chandler | usagoldmines....

Crypto News | Lagrange Strikes a Deal with Matter Labs to Direct Up to 75% of Outsourced Proofs Cha...

Crypto News | XRP Price Set to Explode? Wild Predictions After Ripple’s SEC Win Dimitar Dzhondzhoro...

S&P 500 wipes out $600B in early-morning flash crash, now in the green Jai Hamid | usagoldmines....

Switzerland central bank says it wants nothing to do with Bitcoin in spite of Trump Jai Hamid | usag...

$500 Invested In These Top 3 XRP Rivals Could Reach $1.5 Million By 2026 Cryptopolitan Media | usago...

Top Asian Investors Dump Toncoin (TON) and Pi Network (PI) to Acquire This Hidden 5000x Altcoin Pric...

MIND of Pepe And Other AI Agent Tokens Eye Market Domination newsbtc | usagoldmines.com

XRP Wave 4 Count: Why $2.66 Is The Most Important Level To Beat Scott Matherson | usagoldmines.com

Crypto News | 190,000,000 ADA: Will a Supply Shock Trigger a Price Rally? Dimitar Dzhondzhorov | us...

Crypto News | How Much Do US Interest Rates Really Matter to Crypto? Wayne Jones | usagoldmines.com

Crypto News | Trezor Suite Now Supports Solana Staking Chainwire | usagoldmines.com

Crypto News | USA to become ‘Bitcoin superpower’ as President Donald Trump appears by video at crypt...

Crypto News | Tether was 7th largest US Treasury holder in 2024, surpassing nations like Canada and ...

Just In: President Trump Declares End to Crypto ‘War’ Anjali Belgaumkar | usagoldmines.com

ECB Executive Board Backs Digital Euro for Stability Victor | usagoldmines.com

Pi Network sentiment drops 80% on Coinmarketcap, gains 85% on Coingecko – Bot activity suspected Flo...

Will Binance ever list Pi coin? Here’s what to know Florence Muchai | usagoldmines.com

Here’s How Bitcoin Hits $180,000 This Cycle, According To NBA Legend Who Predicted BTC’s Bull Run Br...

Korean Prosecutors Raid Bithumb Over Ex-CEO’s Alleged Funds Misuse in Property Deal Hassan Shittu | ...

Pi Network Sees Massive $400M in Trading Volume – Can Pi Coin Overtake Bitcoin? Harvey Hunter | usag...

Solana (SOL) Whales Tired Of Waiting, Start To Move Towards Mutuum Finance (MUTM) Cryptopolitan Medi...

Grok 3 Analyzes Top Altcoins To See Which Could Follow Shiba Inu’s Legendary 2021 Run Cryptopolitan ...

Bitcoin To Align With Wall Street? BlackRock Predicts A Price Shift Ahead Christian Encila | usagold...

Crypto News | Claims Against BE Club Founders Concerning OneCoin Withdrawn Chainwire | usagoldmines...

Crypto News | XION Now Available from the Anchorage Digital Platform, Expanding Institutional Acces...

Crypto News | OPT Token to list on XT.com as Optio Blockchain Expands with Edgecast Cloud Relaunch ...

Crypto News | Ethereum Price Analysis: Is ETH Ready for a Decisive Break Above $2K? CryptoVizArt | ...

Crypto News | Bitcoin Price Analysis: Is BTC on Track for $92K? CryptoVizArt | usagoldmines.com

Crypto News | Bybit CEO describes how hackers launder stolen Ethereum via Bitcoin mixers Oluwapelumi...

Coinbase Becomes Ethereum’s Top Node Operator with 11% Stake Victor | usagoldmines.com

ChainGPT Integrates with Sonic for Faster AI & DeFi Upgrades Victor | usagoldmines.com

Starlink gains entry into India, but these two guys hold the key to success Jai Hamid | usagoldmines...

LTP Acquires Spain’s Turing Capital Brokerage to Expand MiCA-Compliant Crypto Services Ruholamin Haq...

Dubai Reveals Pilot Phase of Real Estate Tokenization Project Sead Fadilpašić | usagoldmines.com

DeFi Platform RedStone Denies Partnership Rumors with Web3Port and Whisper Hassan Shittu | usagoldmi...

Crypto News | Pump Fun’s slowdown triggers 97% collapse in Solana network earnings Oluwapelumi Adeju...

Crypto News | Kraken acquires US retail derivatives platform NinjaTrader for $1.5 billion Liam 'Akib...

Coinbase Sells 12,652 ETH in Q4 – Despite These Ethereum Price Jump By 7% Mustafa Mulla | usagoldmin...

Tether Becomes 7th Largest Buyer of U.S. Treasuries in 2024 Victor | usagoldmines.com

WhiteBIT Hosts International Live Stream Championship Hristina Vasileva | usagoldmines.com

Majority of EU crypto payments spent on retail, food, and beverages: Report Vignesh Karunanidhi | us...

Kraken acquires NinjaTrader in $1.5 billion deal Jai Hamid | usagoldmines.com

The Fed Blinked — The Bitcoin Bull Run Return Is Now Inevitable Jake Simmons | usagoldmines.com

Crypto News | Has Bitcoin Really Entered a Bear Market? Analyst Weighs In Mandy Williams | usagoldm...

Crypto News | Bitcoin miners struggle, seek derivatives for risk management amid Bitcoin revenue dec...

Digital Asset Summit 2025: Institutional Investors Eye Trump’s Crypto Vision Vignesh S G | usagoldmi...

Coinbase Survey: Institutional Optimism for Crypto in 2025 Victor | usagoldmines.com

Gotbit founder Aleksey Andryunin reaches settlement with US authorities, forfeits $23M in crypto Hri...

Fired Democrat FTC commissioner warns of the ‘corrupting influence of billionaires’ Florence Muchai ...

European equity funds see largest 4-week inflows of the decade as interest shifts from U.S. stocks C...

Ex-SoftBank Exec Akshay Naheta Joins Bakkt as Co-CEO to Revive Crypto Platform Ruholamin Haqshanas |...

Ripple’s $125M Appeal & Trump’s Bitcoin Move: Will BTC Hit $90K Next? Arslan Butt | usagoldmines...

Coinbase Becomes Largest Ethereum Node Operator, Controlling 11.42% of Staked ETH Ruholamin Haqshana...

The Man Who Predicted The 2024 Altcoin Rally Says Mutuum Finance (MUTM) And Dogecoin (DOGE) Will Be ...

$1 Dogecoin? Whale Accumulation Suggests A Rebound—Analyst Christian Encila | usagoldmines.com

Crypto News | Ripple v. SEC: Is the Lawsuit Really Over, or Is There More to the Story? Dimitar Dzh...

Crypto News | Malaysian Prime Minister Anwar Engages with Klickl Group on the Future of Web3 Financ...

Crypto News | Coinbase stakes its claim as Ethereum’s largest independant node operator Oluwapelumi ...

Kraken Set to Acquire NinjaTrader for $1.5B Victor | usagoldmines.com

Leave a Reply