{"id":19663,"date":"2023-04-10T04:07:01","date_gmt":"2023-04-10T04:07:01","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/sushiswap-smart-contract-bug-results-in-over-3m-in-losses-head-chef-says-hundreds-of-eth-recovered-defi-bitcoin-news\/"},"modified":"2023-04-10T04:07:01","modified_gmt":"2023-04-10T04:07:01","slug":"sushiswap-smart-contract-bug-results-in-over-3m-in-losses-head-chef-says-hundreds-of-eth-recovered-defi-bitcoin-news","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/sushiswap-smart-contract-bug-results-in-over-3m-in-losses-head-chef-says-hundreds-of-eth-recovered-defi-bitcoin-news\/","title":{"rendered":"Sushiswap Smart Contract Bug Results in Over $3M in Losses; Head Chef Says Hundreds of ETH Recovered \u2013 Defi Bitcoin News"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div id=\"\">\n<header class=\"article__header\">\n<\/header>\n<div class=\"featured_image_container\">\n\n<\/div>\n<p><strong>According to several reports, a bug introduced to the decentralized exchange (dex) protocol Sushiswap\u2019s smart contract has resulted in more than $3 million in losses. The blockchain and smart contract security firm Peckshield explained the exploited contract was \u201cdeployed in multiple blockchains.\u201d<\/strong><\/p>\n<h2>Dex Platform Sushiswap Suffers From Smart Contract Exploit<\/h2>\n<p>Over the weekend, the dex platform Sushiswap saw its RouteProcess02 contract exploited and then distributed across various blockchain networks. Blockchain security firm Certik <a href=\"https:\/\/twitter.com\/CertiKAlert\/status\/1644983383498391552?s=20\">published<\/a> an alert after discovering the exploit. The company Peckshield also <a href=\"https:\/\/twitter.com\/peckshield\/status\/1644907207530774530?s=20\">updated<\/a> the crypto community via Twitter, noting that Sushiswap\u2019s \u201cRouterProcessor2 contract has an approve-related bug.\u201d It has also been reported that the victim was a well-known crypto advocate called <a href=\"https:\/\/twitter.com\/0xSifu?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1644907207530774530%7Ctwgr%5E423cbec01897befcb89fafd90a483eb7898f5fe8%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwp.decrypt.co%2Fwp-admin%2Fpost-new.php\">Sifu<\/a>, who reportedly lost 1,800 ether.<\/p>\n<p>Sifu may not have been the only victim, as Certik\u2019s alert mentions that a few USDC users may have been affected. \u201cWe have detected suspicious activity on [0x15d], which is a malicious router,\u201d Certik <a href=\"https:\/\/twitter.com\/CertiKAlert\/status\/1644983383498391552?s=20\">tweeted<\/a>. \u201cRevoke permissions if you have approved this router to spend your tokens. Stay safe. Multiple users who had approved the malicious contract have seen their USDC being transferred to [0x29e]. The wallet has taken about $20,000 in the last two hours,\u201d the company <a href=\"https:\/\/twitter.com\/CertiKAlert\/status\/1644983656648146947?s=20\">added<\/a>.<\/p>\n<p>A developer known as 0xngmi has detailed that the exploit should only be problematic for those who used Sushiswap during the last four days. \u201cOnly users impacted by Sushiswap hack should be those that swapped on Sushiswap in the last 4 days. If you did so, revert approvals ASAP or move your funds in the affected wallet to a new wallet,\u201d 0xngmi tweeted. Sushiswap\u2019s head chef Jared Grey also <a href=\"https:\/\/twitter.com\/jaredgrey\/status\/1644914375151550464?s=20\">confirmed<\/a> the exploit and later <a href=\"https:\/\/twitter.com\/jaredgrey\/status\/1644965948531589120?s=20\">detailed<\/a> that \u201crecovery efforts were underway.\u201d<\/p>\n<p>\u201cWe\u2019ve secured a large portion of affected funds in a whitehat security process. If you have performed a whitehat recovery please contact security@sushi.com for next steps,\u201d Grey <a href=\"https:\/\/twitter.com\/jaredgrey\/status\/1645059641041121280?s=20\">said<\/a> at 9:42 a.m. Eastern Time on April 9. \u201cWe\u2019ve confirmed recovery of more than 300 <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/ETH\" target=\"_blank\" rel=\"noopener\">ETH<\/a> from Coffeebabe of Sifu\u2019s stolen funds. We\u2019re in contact with Lido\u2019s team regarding 700 more <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/ETH\" target=\"_blank\" rel=\"noopener\">ETH<\/a>,\u201d Grey <a href=\"https:\/\/twitter.com\/jaredgrey\/status\/1645065502748704769?s=20\">added<\/a>. Sushiswap\u2019s CTO, Matthew Lilley, followed up later in the day and <a href=\"https:\/\/twitter.com\/MatthewLilley\/status\/1645116456269406212?s=20\">said<\/a> that there are currently no issues with using the Sushiswap dex platform.<\/p>\n<p>\u201cThere is no risk at this time with using Sushi Protocol, and the UI. All exposure to RouterProcessor2 has been removed from the front end, and all LPing \/ current swap activity is safe to do,\u201d the Sushiswap CTO explained. \u201cWe do ask that all users double-check their approvals, and if an address within this list below has an allowance for any of your tokens to please unapprove as soon as you can,\u201d Lilley <a href=\"https:\/\/twitter.com\/MatthewLilley\/status\/1645116500657725441?s=20\">added<\/a>. Just recently, Grey told the community that the Sushiswap team <a href=\"https:\/\/news.bitcoin.com\/sushi-dao-to-set-up-defense-legal-defense-fund-project-receives-unspecified-us-sec-subpoena\/\">received a subpoena<\/a> from the U.S. Securities and Exchange Commission (SEC).<\/p>\n<div class=\"article__body__tags-related__tags\">\n<h6 class=\"article__body__tags-related__title\">\nTags in this story<br \/>\n<\/h6>\n<div class=\"article__body__tags\"><a href=\"https:\/\/news.bitcoin.com\/tag\/2023-defi-hack\/\">2023 defi hack<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/advocate\/\">Advocate<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/approval\/\">approval<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/blockchain\/\">Blockchain<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/certik\/\">certik<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/coffeebabe\/\">Coffeebabe<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/crypto\/\">Crypto<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/cto\/\">CTO<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/decentralized-exchange\/\">decentralized exchange<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/decentralized-finance\/\">decentralized finance<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/defi\/\">DeFi<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/defi-hack\/\">Defi Hack<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/dex\/\">DEX<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/ether\/\">ether<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/exploit\/\">Exploit<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/funds\/\">Funds<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/hacker\/\">Hacker<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/head-chef\/\">Head Chef<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/jared-grey\/\">Jared Grey<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/lido\/\">Lido<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/lping\/\">LPing<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/matthew-lilley\/\">Matthew Lilley<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/peckshield\/\">Peckshield<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/recovery\/\">recovery<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/routeprocess02\/\">RouteProcess02<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/routerprocessor2\/\">RouterProcessor2<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/sec\/\">SEC<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/security\/\">Security<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/sifu\/\">Sifu<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/smart-contract\/\">Smart Contract<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/subpoena\/\">Subpoena<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/sushi-protocol\/\">Sushi Protocol<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/sushiswap\/\">Sushiswap<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/swap\/\">swap<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/ui\/\">UI<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/usdc\/\">USDC<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/vulnerability\/\">Vulnerability<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/vulnerability-disclosure\/\">vulnerability disclosure<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/whitehat\/\">whitehat<\/a><\/div>\n<\/div>\n<p><em><strong>What do you think can be done to prevent smart contract bugs like this in the future? Share your thoughts in the comments below.<\/strong><\/em><\/p>\n<div class=\"article__body__author\">\n<div class=\"article__body__author__avatar\">\n<img src=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg\" srcset=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg 1x, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-300x300.jpg 2x\" class=\"avatar avatar-150 photo\"\/>\n<\/div>\n<div class=\"article__body__author__info\">\n<h6 class=\"article__body__author__info__name\">\nJamie Redman <\/h6>\n<p class=\"article__body__author__info__about\">\nJamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 6,000 articles for Bitcoin.com News about the disruptive protocols emerging today.<br \/><span class=\"td-social-icon-wrap\"><br \/>\n<a target=\"_blank\" href=\"https:\/\/twitter.com\/jamieCrypto\" title=\"Twitter\" rel=\"noopener\"><br \/>\n<i class=\"td-icon-font td-icon-twitter\"\/><br \/>\n<\/a><br \/>\n<\/span>\n<\/p>\n<\/div>\n<\/div>\n<p class=\"images_credits\"><em><b>Image Credits<\/b>: Shutterstock, Pixabay, Wiki Commons<\/em><\/p>\n<div class=\"disclaimer\">\n<p><strong>Disclaimer<\/strong>: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. <a href=\"https:\/\/bitcoin.com\">Bitcoin.com<\/a> does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.<\/p>\n<\/div>\n<div class=\"bottom_article_widgets\">\n<aside id=\"bn_widget_spacing-18\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-21\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>More Popular News<\/span><\/h4>\n<\/aside>\n<aside id=\"bn_widget_spacing-19\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-46\" class=\"widget_text td_block_template_1 widget widget_custom_html\"\/>\n<aside id=\"bn_widget_spacing-20\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-30\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>In Case You Missed It<\/span><\/h4>\n<\/aside>\n<\/div>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script>(function(d, s, id) {\n        var js, fjs = d.getElementsByTagName(s)[0];\n        if (d.getElementById(id)) return;\n        js = d.createElement(s); js.id = id;\n        js.src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&version=v3.2\";\n        fjs.parentNode.insertBefore(js, fjs);\n    }(document, 'script', 'facebook-jssdk'));<\/script><br \/>\n<br \/><a href=\"https:\/\/news.bitcoin.com\/sushiswap-smart-contract-bug-results-in-over-3m-in-losses-head-chef-says-hundreds-of-eth-recovered\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) According to several reports, a bug introduced to the decentralized exchange (dex) protocol Sushiswap\u2019s smart contract has resulted in more than $3 million in losses. The blockchain and smart contract security firm Peckshield explained the exploited contract was \u201cdeployed in multiple blockchains.\u201d Dex Platform Sushiswap Suffers From Smart [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":19664,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/19663"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=19663"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/19663\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/19664"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=19663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=19663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=19663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}