Flash Loan Strategy: Can Attackers Take Maker's $700M Collateral?
Editor's Note: This article comes fromBlue Fox Notes (ID: lanhubiji), reprinted by Odaily with authorization.
Blue Fox Notes (ID: lanhubiji)
Summary
Blue Fox Notes (ID: lanhubiji)
, reprinted by Odaily with authorization.
Foreword: Since the bZx incident, flash loans have gradually become familiar to everyone. What would happen if a governance attack on Maker was made using flash loans? Before flash loans, the cost of launching a governance attack was very high, and a crowdfunding strategy might be adopted. With flash loans, as long as there is enough ETH in the liquidity pool, a governance attack on Maker can be launched, thereby taking away all of Maker’s assets. collateral and issue new Dai. Based on this possibility, Maker decided to formulate a new governance contract and launched a vote today to introduce a delay to prevent governance attacks on the system. The emergence of flash loans has put forward higher requirements for the safety of DeFi. In addition, Blue Fox Notes found that the MKR in the current uniswap pool has been greatly reduced, and 16,000 MKRs have dropped to more than 4,000 MKRs. Judging from the current situation, there is a high probability that large players will withdraw to prevent being exploited by attackers. The author of this article, Dominik Harz, was translated by "JT" of the "Blue Fox Notes" community.
Summary
If Maker does not introduce a delay before the liquidity of the flash loan pool exceeds the threshold, there is almost no chance of preventing the attack.
introduce
We contacted Maker on February 8, 2020, and contacted them on February 14, 2020 to discuss our findings.
Maker is aware of the attack vector and will hold a vote at 12 pm PST (Blue Fox Notes: Pacific Standard Time) this Friday (that is, today) to prevent the attack.
secondary title
a16z: 60,000 MKR
0xfc7e22c6afa3ebb723bdde26d6ab3783aab9726b: 51,291 MKR
0x000be27f560fef0253cac4da8411611184356549: 39,645 MKR
Maker and its Dai stablecoin are the most popular projects on Ethereum DeFi, with roughly $700 million locked in their smart contracts. (Blue Fox Note: Currently about 600 million US dollars, related to ETH price fluctuations) The Maker protocol relies on the governance process encoded in the smart contract. MKR token holders can vote to replace the existing governance contract. The number of votes is proportional to the number of MKR. MKR has a total token volume of 987,530, with selected wallets or contracts holding a significant amount of tokens:
Maker Governance Contract: 192,910 MKR
Maker Foundation: 117,993 MKRPlease note: The Maker governance contract contains MKR tokens for multiple entitiessecondary title
In a December 2019 article, Micah Zoltu pointed out how to attack the Maker governance contract. (Blue Fox Notes: For details, refer to "
MKR Governance Attack: Turn $20M Into $340M In 15 Seconds, Is It Possible?
In order to reduce the number of MKR tokens required, he proposes to perform the attack when voting on the new governance protocol. Currently, 192,910 MKR are locked in the governance contract. However, if two or three contracts are assumed to vote in parallel with similar token allocations, the attacker will need fewer tokens. As shown below, this situation has often happened in the past:
image description
The most obvious attack strategy is to crowdfund the required MKR tokens through smart contracts, and distribute the corresponding benefits to each participant after the victory. However, an attacker would likely need to accumulate around 50,000 MKR tokens to have a chance of launching an attack on the system without Maker noticing.Crypto Flash Loans: The Magical New Invention of Internet Money》)
secondary title
Brave New Attack Tactic: Flash Loans
However, if we consider the use of flash loans, we can completely forget about accumulating MKR tokens. Flash loans are a fairly new concept, so we can give a brief explanation. (Blue Fox Note: For flashloan, you can refer to the previous article "
Crypto Flash Loans: The Magical New Invention of Internet Money
Flash Loans removes these requirements because it only happens in a single transaction:
*Alice takes a loan from a flash loan liquidity provider (such as in Aave or dYdX)
*Alice performs some operation (e.g. arbitrage on Uniswap, Fulcurm, Kyber, etc.)
image description
Flash loans are executed in three steps in one transaction
Therefore, Alice can take the risk of the loan, i.e., if she cannot repay the loan, she will never take the risk. Liquidity providers also win: they will only lend Alice's funds if she is able to repay the loan.Inspiration from the bZx incident》)
Arbitrage or oracle manipulation using flash loans
On February 14 and February 18, two incidents related to flash loans caused bZx to suspend its platform. In the first transaction, a flash loan made a profit of 1,193 ETH, about $298,250. The trade was executed using a smart contract, opening a short position on wBTC on Fulcrum. In the same transaction, the transaction took out a wBTC loan from Compound and traded the wBTC in kyber’s Uniswap reserve pool, causing a lot of slippage and ultimately lowering the price of Fulcrum as well. For details, please refer to the analysis of bZx and peckShield. (Blue Fox Notes: You can also refer to the previous Blue Fox Notes article "
Inspiration from the bZx incident
Similarly, a second incident occurred on February 18, in which the “attacker” gained 2,378 ETH (approximately $600,000) in this transaction. The transaction involved initially borrowing 7,500 ETH to take a long position in Synthetix’s sUSD. (Blue Fox Note: The general attack steps are as follows: 1. Lend 7,500 ETH through flash loan; 2. Exchange 3,517 ETH of it on Synthetix for 940,000 US dollars of sUSD, and the price of sUSD is about 1 US dollar at this time; 3. Use 900ETH bought sUSD on Kyber and Uniswap, pushing the price of sUSD up to $2; 4. Borrowing 6,796ETH by pledging sUSD, the reason why so much ETH was able to be borrowed with the previous 940,000 sUSD was because the price of sUSD was pushed up to $2 U.S. dollars, that is to say, a collateral equivalent to a value of 1.88 million U.S. dollars; 5. Use the borrowed 6,796 ETH and the remaining 3,083 ETH to repay the 7,500 ETH flash loan, then there will be 6,796+3,083-7500=2,379 ETH proceeds)
Oracle manipulation to reduce required liquidity
At the current exchange rate, the attacker needs about 485,000 ETH to buy MKR, since only one exchange, Kyber, has enough. However, the attacker can also buy MKR on multiple exchanges, buying 38,000 MKR from Kyber, 11,500 MKR from Uniswap, and 500 MKR from Switcheo, which requires a total of 378,940 ETH. This number is still high, but it has been reduced by nearly 100,000 ETH.
Attackers can use oracle manipulation strategies to effectively lower the price of MKR on Kyber and Uniswap. These are the two largest MKR providers and appear to be vulnerable to oracle price manipulation. Further analysis is needed to determine how much lower the MKR price can be. However, with less liquid tokens like wBTC, the attacker was able to manipulate the exchange rate by about 285%.
secondary title
get enough liquidity
ETH locked on Aave
Even with oracle manipulation, a large amount of ETH is required to perform an attack on Maker. However, an attacker can increase its liquidity by making two flash loans in the same transaction. Aave and dYdX only allow a single flash loan in a transaction in order to protect themselves from reentrancy attacks. However, an attacker can lend ETH from these two different protocols in the same transaction.
Thus, as of February 18th, the attacker had a pool of 90,000 ETH on dYdX and a pool of 17,000 ETH on Aave. Therefore, with the current liquidity, the attacker can obtain a total of about 107,000 ETH in loans from dYdX and Aave, and try to use the borrowed ETH to manipulate the price of MKR tokens, and thus obtain enough MKR tokens to Replaces the current Make governance contract.
For this method to be successful, the attacker must be able to reduce the average MKR price by at least 3.54 times. Alternatively, the attacker could wait for dYdX and Aave to increase their liquidity pools. Since the current liquidity pool growth rate for both protocols is around 5%, it seems unlikely that this attack will be possible within two months.
secondary title
Combined attack?
Also note: the top four account holders (actually 5, but not considering the current Maker governance contract) are able to carry out the attack without crowdfunding.
No time to wait.
Once sufficient liquidity (with or without a combination of oracle manipulation) is obtained through the flash pool, anyone can take over the Maker governance contract. When liquidity pool funds reach this threshold, once Makers start voting, Makers need to ensure that as few MKR tokens as possible are distributed. If at any time during this voting process, the distribution of MKR is allowed to exploit this vulnerability, then any collateral could be taken away.
The attacker would be able to take away $700 million worth of ETH collateral and print new Dai at will. This kind of attack will spread to the entire DeFi field, because Dai is used as a collateral asset in other protocols. Additionally, the attackers could use the new Dai to trade other tokens worth $230 million.







