MEV bot earns $1M but loses everything to a hacker an hour later

CoinTelegraph
CoinTelegraph September 28, 2022
Updated 2022/09/28 at 1:50 PM
3 Min Read

An Ethereum arbitrage trading bot managed to hit the jackpot and lose it all on the same day in an ironic turn of events in decentralized finance (DeFi)[1].

In a Twitter thread, Robert Miller, who works at the research firm Flashbots, shared[2] how a Maximal Extractable Value (MEV) bot with the prefix 0xbadc0de[3] was able to earn 800 Ether (ETH[4]), around $1 million, through arbitrage trades.

According to Miller, the bot took advantage of a huge arbitrage opportunity that came when a trader attempted to sell $1.8 million in cUSDC through the decentralized exchange (DEX)[5] Uniswap v2 and only got $500 worth of assets in return. The bot detected this chance and immediately sprung to action and gained massive profits.

However, only an hour later, a hacker exploited a vulnerability in 0xbadc0de’s “bad code” and tricked it into authorizing a transaction that drained its balance of 1,101 ETH, which was around $1.41 million at the time of writing.

According to the blockchain security firm PeckShield, the bug can be traced back to the bot’s callback routine, and this was exploited[9] by the hacker to approve an arbitrary address for spending.

Related: Pantera CEO bullish on DeFi, Web3 and NFTs as Token2049 gets underway[10]

On Sept. 18, a vulnerability in Profanity, an Ethereum vanity address generator, was exploited, draining $3.3 million in funds[11] from various wallets. Investigations done by the decentralized exchange (DEX) aggregator 1inch Network highlighted that there was ambiguity in terms of the creation of the wallets. The DEX warned users that their wallets were at risk and urged them to transfer their assets.

More than a week later, another vanity wallet address was exploited and drained of almost $1 million[12] worth of ETH. After stealing the funds, the hackers immediately sent them to the controversial crypto mixer Tornado Cash.

References

  1. ^ decentralized finance (DeFi) (cointelegraph.com)
  2. ^ shared (twitter.com)
  3. ^ 0xbadc0de (etherscan.io)
  4. ^ ETH (cointelegraph.com)
  5. ^ decentralized exchange (DEX) (cointelegraph.com)
  6. ^ #MEV (twitter.com)
  7. ^ https://t.co/FxXSY8AyhX (t.co)
  8. ^ September 27, 2022 (twitter.com)
  9. ^ exploited (twitter.com)
  10. ^ Pantera CEO bullish on DeFi, Web3 and NFTs as Token2049 gets underway (cointelegraph.com)
  11. ^ draining $3.3 million in funds (cointelegraph.com)
  12. ^ drained of almost $1 million (cointelegraph.com)

 

This article was first published on Cointelegraph.com

Share this Article