BlockSec Phalcon said BarnBridge SMART Yield (cUSDC) was attacked on Ethereum, with losses estimated at about $776,000. The monitoring data points to a suspected governance attack. According to the alert, the attacker first obtained DAO governance permissions, then upgraded the SmartYield/controller proxy to a malicious implementation contract. That contract later called CompoundProvider’s privileged _takeUnderlying function. BlockSec Phalcon said the attacker then used pre-existing USDC approvals from 50 user accounts and moved the pooled funds through transferFees. The incident centers on governance access, proxy upgrade control, and privileged contract execution inside the protocol’s architecture.
BarnBridge SMART Yield (cUSDC) on Ethereum was attacked, with losses of about $776,000, according to BlockSec Phalcon. The security monitor said the incident is suspected to be a governance attack.
BlockSec Phalcon said the attacker first obtained DAO governance permissions and then upgraded the SmartYield/controller proxy to a malicious implementation contract. That contract later called CompoundProvider’s privileged _takeUnderlying function. Using pre-existing USDC approvals from 50 user accounts, the attacker moved aggregated funds through transferFees.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.