OVIX, a Polygon-based lending protocol, recently suffered a major setback after being hit by an exploit that cost the platform at least $2 million.
In response, OVIX temporarily halted its POS and zkEVM operations while it worked to address the issue and minimize the impact on its users.
The intrusion was initially reported by blockchain security company CertiK, and was later substantiated by Arkham Intelligence.
The OVIX protocol allows borrowing against a variety of stablecoins, including Ethereum derivatives and Polygon’s native MATIC token, as well as Aavegotchi’s staked token, vGHST.
Arkham claims that the exploiter deliberately raised the price of vGHST in order to obtain substantial USDC in loans. Once on the Ethereum (ETH) mainnet, the hacker exchanged the stablecoins for 757 ETH.
The intruder utilized the borrowed stablecoins to gain access to the vGHST lending pool and the OVIX lending platform.
Pumping The Price Of GHST
Blockchain data from CoinMarketCap shows that they borrowed substantial amounts of vGHST, driving up the price of the native currency $GHST by as much as 25% in just half an hour.
The perpetrator made off with the collateral and later traded it in for more tokens.
The Aavegotchi blockchain gaming project uses vGHST as its staking token. It serves as the share token for the native Aavegotchi token, $GHST.
Blocksec, a security and auditing organization, has verified that the value of vGHST was increased artificially, and that the pricing oracle was tampered with.
The hacker had used the vGHST token to exploit the protocol, according to the findings of a study by blockchain security firm PeckShield.
0VIX is working with its security partners to look into the current situation that seems to be related to vGHST.
As a result, POS and zkEVM markets have been paused this includes pausing oToken transfers, minting, and liquidations.
Only POS has been currently affected but zkEVM…
— 0VIX | live on zkEVM (@0vixProtocol) April 28, 2023
In a statement released on April 28th, O
Go to Source to See Full Article
Author: Christian Encila