No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

Here’s how MEV bots on SushiSwap caused a $3.3m loss

April 9, 2023
in Crypto
0
Here’s how MEV bots on SushiSwap caused a $3.3m loss



A pseudonymous cryptocurrency pentester, known for their white hat hacking activities, found themselves in a race against time and malicious bots after identifying a vulnerability in SushiSwap’s RouterProcessor2 contract.

The hacker managed to secure 100 ethereum (ETH) of the affected funds before malicious bots copied the attack, leading to a loss of over $3.3m (approximately 1800 ETH). The hacker, whose identity remains anonymous, tweeted today that they had successfully “white-hacked” 0xSifu for 100 ETH and were willing to return the funds if contacted. He was later thanked by Sifu in a tweet for the restitution.

However, their attempt to protect the platform was thwarted by the swift actions of miner-extractable value (MEV) bots, which deployed contracts and replicated the attack before the vulnerability could be fully addressed.

Miner Extractable Value (MEV) bots are automated programs designed to exploit opportunities for profit within blockchain networks, specifically within the Ethereum ecosystem. These bots take advantage of the inherent design of decentralized networks, where miners are responsible for validating and ordering transactions within blocks. MEV bots seek to capitalize on the power miners have in choosing which transactions to include in a block and the order in which they are placed.

The primary focus of MEV bots is to identify and act on profitable opportunities, such as frontrunning, backrunning, arbitrage and sandwich attacks. These strategies allow MEV bots to profit from the knowledge of pending transactions by manipulating their placement within the block. WhenTrust was asked why he did not just warn Sifu instead, he wrote:

“I wasn’t aware of how ridiculously advanced MEV bots are (rebuilt 3 TXs), I thought every second matters, and wanted to white-hack a bunch more addresses.”

The question seemingly hinted at the cybersecurity principle of responsible disclosure. Responsible disclosure is a principle within the cybersecurity community that emphasizes the ethical reporting of discovered vulnerabilities in software or systems to the respective developers or vendors before making the information public. The primary goal of responsible disclosure is to provide the affected party an opportunity to address and fix the vulnerability, thus minimizing the risk of exploitation by malicious actors.

In the context of cryptocurrencies and blockchain technology, preemptive hacking to secure funds in a vulnerable position might not be a favorable option due to the public nature of crypto transactions. On decentralized networks, transaction data is transparent and accessible to all participants.

This openness enables bad actors to observe and imitate such transactions. Consequently preemptive hacking is only reasonable when all vulnerable funds can be secured quickly enough, preventing bad actors from replicating the attack in time.

Crypto cybersecurity firm PeckShield weighed in on the situation, revealing that the RouterProcessor2 contract on SushiSwap had an approve-related bug that led to the substantial loss from 0xSifu. The firm urged users who had approved the contract to revoke their approval as soon as possible, providing a link to the contract’s address on Etherscan.

Jared Grey, SushiSwap’s head developer, confirmed the presence of the approval bug in the RouterProcessor2 contract via a tweet. He urged users to revoke their approval immediately and assured them that the platform’s security teams were working on mitigating the issue. Grey also reported that a significant portion of the affected funds had been secured through a white hat security process.

In a follow-up tweet, Grey announced the recovery of more than 300 ETH from CoffeeBabe, a user who had managed to recover some of the stolen funds. SushiSwap is also in contact with Lido’s team to secure an additional 700 ETH.

This incident highlights the ever-evolving landscape of cryptocurrency security, where white hat hackers work to protect platforms and assets, but malicious actors remain a constant threat. It also underscores the need for heightened security measures and collaboration between platforms and white hat hackers to address vulnerabilities and minimize losses.


Follow Us on Google News



Editorial Team

Editorial Team

Related Posts

Tom Lee’s BitMine adds ETH again as BMNR stock stalls
Crypto

Tom Lee’s BitMine adds ETH again as BMNR stock stalls

June 15, 2026
$7B World Cup Volume Can't Boost LINK to $10
Crypto

$7B World Cup Volume Can’t Boost LINK to $10

June 15, 2026
defi ethereum defi
Crypto

Aztec Connect Exploit Shows Why Old DeFi Contracts Can Still Be Dangerous

June 15, 2026
Cointelegraph
Crypto

Bitcoin Tipped for $69,000 as Oil Drops Below $80 on Iran Peace Roadmap

June 15, 2026
Binance bStocks push heats up after $143M equities debut
Crypto

Binance bStocks push heats up after $143M equities debut

June 15, 2026
Cointelegraph
Crypto

Aztec Connect Exploited For $2.1 Million

June 15, 2026
Load More
Next Post
Bitcoin price sets up for an explosive move as ADA, XLM, AAVE and CFX turn bullish

Bitcoin price sets up for an explosive move as ADA, XLM, AAVE and CFX turn bullish

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Solana price could revisit June lows as recovery runs out of steam

    0 shares
    Share 0 Tweet 0
  • JetBlue Seat Selection: What You Need to Know

    0 shares
    Share 0 Tweet 0
  • Demand for protection insurance expected to rise in 2025, survey finds

    0 shares
    Share 0 Tweet 0
  • 3 Tips To Make Your Monday Mornings Better

    0 shares
    Share 0 Tweet 0

Latest News

Veld Capital has announced it has closed anasset-backed credit continuation vehicle at €355m (£307m) following a competitive secondary auction process

Veld Capital closes asset-backed credit continuation vehicle at €355m

June 15, 2026
0

Veld Capital has announced it has closed an asset-backed credit continuation vehicle at €355m (£307m) following a competitive secondary auction...

The Most Popular OPI Nail Polish Shades Of All Time

The Most Popular OPI Nail Polish Shades Of All Time

June 15, 2026
0

OPI has been creating iconic nail polish colors for 45 years. In fact, a bottle from one of its most...

These stocks have been beating the S&P 500 and could keep the bull market going, says Morgan Stanley

These stocks have been beating the S&P 500 and could keep the bull market going, says Morgan Stanley

June 15, 2026
0

The bull market for stocks has been dogged by peak earnings revisions breadth and peak liquidity, but fear not says...

Tom Lee’s BitMine adds ETH again as BMNR stock stalls

Tom Lee’s BitMine adds ETH again as BMNR stock stalls

June 15, 2026
0

BitMine Immersion Technologies said its Ethereum holdings reached 5,620,754 ETH as of June 14, bringing the company closer to its...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.