Close Menu
    Facebook X (Twitter) Instagram
    Facebook Instagram YouTube
    Crypto Go Lore News
    Subscribe
    Wednesday, May 21
    • Home
    • Market Analysis
    • Latest
      • Bitcoin News
      • Ethereum News
      • Altcoin News
      • Blockchain News
      • NFT News
      • Market Analysis
      • Mining News
      • Technology
      • Videos
    • Trending Cryptos
    • AI News
    • Market Cap List
    • Mining
    • Trading
    • Contact
    Crypto Go Lore News
    Home»Ethereum»SIR.trading DeFi Protocol Loses $355K in Hack Targeting Ethereum’s Transient Storage
    Ethereum

    SIR.trading DeFi Protocol Loses $355K in Hack Targeting Ethereum’s Transient Storage

    CryptoExpertBy CryptoExpertMarch 31, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    SIR.trading DeFi Protocol Loses 5K in Hack Targeting Ethereum’s Transient Storage
    Share
    Facebook Twitter Pinterest Email Copy Link
    Coinmama


    TLDR

    SIR.trading DeFi protocol lost its entire $355K TVL in a hack on March 30, 2025
    The attack exploited a vulnerability in the protocol’s Vault contract by manipulating a callback function
    This may be one of the first real-world attacks targeting Ethereum’s transient storage feature introduced in the Dencun upgrade
    The stolen funds were transferred to an address funded through Railgun, an Ethereum privacy solution
    Despite the setback, the protocol’s founder (Xatarrer) indicated interest in continuing the project

    Ethereum-based DeFi protocol SIR.trading was completely drained of funds in a hack on March 30, 2025. The attack resulted in the loss of approximately $355,000, which represented the protocol’s entire total value locked (TVL).

    The hack was first detected by blockchain security firms TenArmorAlert and Decurity. Both companies posted warnings on X (formerly Twitter) to alert users of the breach.

    🚨TenArmor Security Alert🚨

    Our system has detected a suspicious attack involving #SIR.trading @leveragesir on #ETH, resulting in an approximately loss of $353.8K.

    The stolen funds have been deposited into RailGun.

    Attack transaction: https://t.co/W5SRnzKjDF… pic.twitter.com/e1OOQoKbhz

    — TenArmorAlert (@TenArmorAlert) March 30, 2025

    SIR.trading, which stands for Synthetics Implemented Right, was designed as “a new DeFi protocol for safer leverage.” The platform aimed to address common challenges in leveraged trading such as volatility decay and liquidation risks.

    okex

    The protocol’s founder, known only by the pseudonym Xatarrer, described the incident as “the worst news a protocol could receive.” Despite this major setback, Xatarrer suggested the team plans to continue developing the protocol.

    So we go the worst news a protocol could received and got hacked for our entire TVL ($355k).

    I (@Xatarrer) would like to not throw the towel here as I truly believe in SIR.

    If you also believe in the core protocol and have any idea on how to proceed forward, please DM. https://t.co/FD6QxwfXP4

    — SIR.trading (🦍^🎩) (@leveragesir) March 30, 2025

    Security experts have described the attack as “clever.” It specifically targeted a callback function in the protocol’s Vault contract that leverages Ethereum’s transient storage feature.

    According to an analysis by Decurity, the attacker was able to replace the real Uniswap pool address with an address they controlled. This allowed them to redirect funds from the vault to their own address.

    TenArmorAlert explained that by repeatedly calling this callback function, the hacker drained the protocol’s entire TVL. The stolen funds have reportedly been deposited into an address funded through Railgun, an Ethereum privacy solution.

    Exploiting Ethereum’s New Feature

    SupLabsYi from blockchain security firm Supremacy provided more technical details about the attack. They noted that it may demonstrate a security flaw in Ethereum’s transient storage feature.

    6/ What’s striking is that transient storage, introduced via EIP-1153 in the Dencun hard fork, is still a nascent feature. This may be one of the first real-world attacks exploiting its vulnerabilities, may signal further changes in attack trends.https://t.co/8du3e1IVDV

    — Yi (@SuplabsYi) March 30, 2025

    Transient storage was added to Ethereum with the Dencun upgrade last year. This feature allows for temporary storage of data and leads to lower gas fees than regular storage options.

    Security researchers believe this may be one of the first attacks to exploit vulnerabilities in this new feature. SupLabsYi warned that “this isn’t merely a threat aimed at a single instance of uniswapV3SwapCallback.”

    The vulnerability seems related to how the SIR.trading contract verified transactions. Typically, smart contracts should only permit transactions from trusted sources like a Uniswap pool.

    However, the contract relied on transient storage, which resets only after a transaction ends. The hacker exploited this by overwriting important security data while the transaction was still running.

    According to blockchain researcher Yi, the attacker brute-forced a unique vanity address. This enabled the contract to register their fake address as legitimate.

    The hacker then used a custom contract to drain all funds from SIR.trading’s vault. Xatarrer has reached out to Railgun for assistance in potentially tracking or recovering the stolen funds.

    Interestingly, SIR.trading’s documentation did warn users about potential risks. It stated that despite being audited, its smart contracts could still contain bugs that might lead to financial losses.

    The documentation specifically highlighted the platform’s vaults as a particular area of vulnerability. It warned that “undiscovered bugs or exploits in SIR’s smart contracts could lead to fund losses.”

    This incident raises questions about the security of transient storage in Ethereum. Security experts caution that unless developers implement stronger safeguards in their smart contracts, similar attacks could occur in the future.





    Source link

    okex
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    CryptoExpert
    • Website

    Related Posts

    Ethereum

    SEC delays decision on Ether staking and XRP ETFs, as analysts expected

    May 21, 2025
    Ethereum

    Technical Indicators Show Resistance at $2,800 Level

    May 20, 2025
    Ethereum

    Ethereum sees smart wallet activity spike as Pectra impact is felt

    May 19, 2025
    Ethereum

    51% attack on Ethereum more difficult than on Bitcoin — Justin Drake

    May 18, 2025
    Ethereum

    Bitcoin breaks out while Coinbase breaks down: Finance Redefined

    May 17, 2025
    Ethereum

    Is This Correction the Calm Before a Storm to $5,000?

    May 16, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Recommended
    Editors Picks

    SEC delays decision on Ether staking and XRP ETFs, as analysts expected

    May 21, 2025

    Together AI Launches Code Sandbox and Interpreter for Enhanced AI Development

    May 21, 2025

    Texas House Advances Bitcoin Reserve Bill With Bipartisan Backing

    May 21, 2025

    Coinbase faces SEC probe over historical user metrics: report

    May 21, 2025
    Latest Posts

    We are a leading platform dedicated to delivering authoritative insights, news, and resources on cryptocurrencies and blockchain technology. At Crypto Go Lore News, our mission is to empower individuals and businesses with reliable, actionable, and up-to-date information about the cryptocurrency ecosystem. We aim to bridge the gap between complex blockchain technology and practical understanding, fostering a more informed global community.

    Latest Posts

    SEC delays decision on Ether staking and XRP ETFs, as analysts expected

    May 21, 2025

    Together AI Launches Code Sandbox and Interpreter for Enhanced AI Development

    May 21, 2025

    Texas House Advances Bitcoin Reserve Bill With Bipartisan Backing

    May 21, 2025
    Newsletter

    Subscribe to Updates

    Get the latest Crypto news from Crypto Golore News about crypto around the world.

    Facebook Instagram YouTube
    • Contact
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    © 2025 CryptoGoLoreNews. All rights reserved by CryptoGoLoreNews.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 106,686.58
    ethereum
    Ethereum (ETH) $ 2,541.06
    tether
    Tether (USDT) $ 1.00
    xrp
    XRP (XRP) $ 2.36
    bnb
    BNB (BNB) $ 654.69
    solana
    Solana (SOL) $ 169.68
    usd-coin
    USDC (USDC) $ 1.00
    dogecoin
    Dogecoin (DOGE) $ 0.22694
    cardano
    Cardano (ADA) $ 0.756276
    tron
    TRON (TRX) $ 0.270713