Nick C. Profile picture
17 Nov, 12 tweets, 3 min read
Another one bites the dust: Origin Dollar (OUSD) exploited for $2.25m in DAI and $1m in Ethereum.

Flash loan attacker/exploiter is already washing the funds via RenBTC.
This is the fifth flash loan attack of the past three weeks alone.

Harvest, Akropolis, Value, and CheeseBank were all hit for millions in stables.
I believe he stole even more ETH than I first thought. Trying to figure it out.
Attack confirmed by core team member.
I think the amount stolen is a lot higher than the ~$3.5m as I first thought. I misread the attack txes.

Funds stolen (I think):
- $2.25m in DAI
- $3.3m in ETH
- $1.9m in ETH->RenBTC
This might have something to do with the rebase mechanism:

The attacker obtained 28,000,000 OUSD by depositing a combination of USDT and DAI, though somehow exited with 33,270,000 OUSD and then some. The remaining OUSD was subsequently withdrawn and liquidated into DAI and ETH.
The attack txes are inherently convoluted because part of the attack required deposits into the OUSD Vault. When depositing stables into OUSD, the funds are automatically put into the yield-bearing strategies.

Might have something to do with this as well.
Upon further analysis, it might have been a reentrancy attack that exploited the way in which OUSD rebases.

OUSD rebases continuously as users interact with Origin contracts.

In simple terms, a re-entrancy attack is basically like paying someone with a cheque that will bounce.
Forgot to mention, I believe I saw a tx where the attacker returned ~536,000 OUSD to a contract address or the Origin deployer.

Technically, that OUSD can't be redeemed for anything but it does have a bit of value on the secondary market (SushiSwap and Uniswap).
Messages are starting to be sent to the Origin attacker, where $5.5m remains.

One user said they lost $1,000, which they said came from their student loans.

Another claimed to have lost 0.5 ETH trying to trade the crash.

No dice... yet
On-chain communication with an attacker was recently popularized with the Value exploit, though it's existed for all of the major hacks as of late.

I remember DForce initially negotiating the return of $25m hacked via embedded messages.
Just saw the response from the Origin team. They are committed "to making things right" and have asked the attacker to return the funds.

They also gave a bit more context about the attack.

I wish them and depositors well.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Nick C.

Nick C. Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @n2ckchong

18 Nov
What's beautiful (and kind of scary) about DeFi is that we can see everything that happens on-chain and connect addresses to identities and firms.

Here's a breakdown of the known Ethereum addresses of Three Arrows Capital, Polychain Capital, and Jump Trading.

👇 Image
Three Arrows Capital (1/2):

One of the biggest Compound suppliers, with $100m in WBTC, $50m in ETH, and $6m in DAI.

3AC is also supplying 275 YFI and $13m in LINK to Aave and is farming SUSHI with 1.5m *recently-acquired* SUSHI.

3AC acquired 351k LINK during recent dip. Image
3AC (2/2):

With the collateral, 3AC is withdrawing stables and sending them to FTX. We've seen millions upon millions sent to an FTX address.

It is unclear what happens to the funds once they're there but 3AC is often on the profit + volume leaderboards on FTX.
Read 10 tweets
17 Nov
Since UNI rewards ended yesterday, Uniswap's TVL has dropped by 40% to $1.9 billion. The bleeding shows no signs of abating yet.

Let's take a quick look at a few large liquidity providers (at random) and what they are doing with their freed-up capital. 👇
0xe0e withdrew $1.7m worth of liquidity from Uniswap's ETH-DAI pair.

They deposited all of that capital immediately into cAssets, cDAI and cETH. ImageImage
0x975 withdrew $2.8m worth of liq from ETH-DAI.

They deposited all that capital back into Binance without converting the ETH into DAI or vice-versa.

They made this addy with the sole purpose of farming UNI, meaning they're probs looking to re-allocate to DeFi or BTC (UOA). ImageImage
Read 10 tweets
15 Nov
~$1 billion of $ETH is likely to be deployed into DeFi and the market in the coming days as Unsiwap's first UNI yield farming scheme comes to an end.

Let's look over a few places where you could put that Ethereum to work and their risks.👇

1/ ETH 2.0

If the bare minimum ETH gets staked in the Beacon Chain, validators will get paid 22% APR.

Risks:

- ETH2 will b untradable
- Slashing if you don't run your validator properly
- Extreme opportunity cost; can't bring ETH back from Beacon Chain
2/ Alpha Homora Pools

Alpha Homora allows ETH holders to easily farm yield farming pools (SushiSwap, Uniswap, Index, Mstable, etc.) and LP on AMMs with leverage.

Yields are quite high (15-100%+) due to IL.

Risks:
- Impermanent loss. IL risk is magnified if you take on leverage
Read 13 tweets
27 Oct
Bitcoin is resilient around $13k, Ethereum hit $420, and DeFi TVL is at an ATH at $12 billion.

As DeFi continues to grow, decentralized exchanges will remain pivotal.

Here’s a thread on the outlook of the AMM market (Uniswap, Balancer, Sushiswap, LinkSwap, DODO).
Before we get into it, a brief explainer of automated market makers.

AMMs are a type of decentralized exchange where users pool liquidity, then trade with the coins in the pool. AMMs price liquidity with a formula (often x * y = k), algorithmically matching purchases and sales.
AMMs are starting to overtake centralized exchanges.

Uniswap alone did more volume than Coinbase in September. AMM liquidity pools can sometimes be deeper than centralized exchanges, sans trading fees (see image #1).

AMM also enable-chain arbitrage, a massive market.
Read 16 tweets
19 Oct
There's been a bunch of buzz about @barn_bridge over recent days. The project's stablecoin seed pool has $180m just 24 hours after its launch. This makes it one of the biggest Ethereum yield farms ever.

But what exactly is BarnBridge?

An ELI5 Thread - 👇
DeFi is currently disjointed and risky compared to TradFi.

Yields differ wildly (see below), there are no fixed yield products, there is no yield curve, crypto is high vol, etc.

Those are issues that "degens" can disregard. But big money, maybe not so much.
There's no doubt that capital is entering DeFi at a rapid clip. DeFi Pulse is reporting that TVL has reached $11 billion — a 1,000% gain in just over six months.

But the aforementioned inefficiencies are preventing the next wave of capital.

Enter BarnBridge.
Read 15 tweets
18 Oct
Whoever is farming @barn_bridge / (starting in 24 hrs), I made a spreadsheet with the annualized yields of the stablecoin pool. USDC, DAI, and sUSD accepted.

Not an endorsement - seems to be one of the better, relatively safe stablecoin yield farms, though. Image
Here's a matrix for the yields on the / Uniswap LP pool, starting in eight days.

Yields are much higher as I assume TVL will be much lower due to potential impermanent loss risks. Image
Pool #1 (stablecoins) will be open for 25 weeks, with 32,000 BOND released a week.

Pool #2 (BOND/USDC LP) will be open for 100 weeks, with 20,000 BOND released a week.

In total, 2,800,000 tokens—28% of the total supply—will be distributed through these pools.

More data below: ImageImage
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!