Polkadot-Ecosystem Platform Polkatrain Loses $3 Million In A Rebate Arbitrage Attack

Polkadot-Ecosystem Platform Polkatrain Loses $3 Million In A Rebate Arbitrage Attack

On April 5, 2021, Polkatrain, a decentralized fundraising platform operating in the Polkadot ecosystem, suffered a rebate arbitrage attack resulting in the loss of $3 million.

The attack was detected by blockchain ecosystem security platform SlowMist, indicating that the hack targeted Polkatrain contract with swap functionality and rebate mechanism dubbed POLT_LB. 

The analysis adds that the attackers took advantage of the flaws in the system’s update function. 

In this case, when users purchase the Polkatrain native token PLOT, they are eligible for a certain amount of rebates. The system’s design sends the rebates through the transfer function, where the update function takes over.

SlowMist explains the flaws in the update function that the attackers explored. According to the cybersecurity company: 

“Since the update function does not set the maximum amount of rebates in a pool, nor does it determine whether the total used up rebates, malicious arbitrageurs can continue to call the swap function to exchange tokens to get the contract,” SlowMist said. 

Also Read: The DNC Singapore: Looking At 2 Sides Better

Polkatrain confirms hack

Elsewhere, Polkatrain in a statement confirmed the incident stating that it will follow up in the coming days.

“Polkatrain team has identified and verified that the hacking incident is a malicious attack by hacker, he used the problem similar with slippage tolerance,” Polkatrain said. 

The platform revealed that the name of the hacker has already been identified as Mr. Jiang.

Interestingly, Polkatrain did not specify the amount lost through the hack. Furthermore, the platform urged the hacker to return the stolen funds or risk arrest from authorities in China.

Also Read: 4 Best Practices On How To Use SkillsFuture Credit

The attack contributes to the total cumulative funds lost in blockchain hacks, with SlowMist placing the total figure around $14.5 billion.

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

5 days ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

6 days ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

1 week ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

2 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

2 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

3 weeks ago