Optimism-based DeFi Protocol Loses $20 Million in Major Attack

As a seasoned crypto investor with a keen interest in DeFi projects, I’ve seen my fair share of ups and downs in this ever-evolving landscape. The news of Sonne Finance’s exploit came as a disheartening reminder of the inherent risks that come with investing in decentralized finance platforms.


As a financial analyst specializing in decentralized finance (DeFi) on the Optimism Mainnet, I’ve unfortunately witnessed a significant setback for Sonne Finance. An exploit, believed to have been masterminded via a time-locked contract vulnerability, has resulted in losses exceeding $20 million. This event, sending ripples of alarm throughout the nascent DeFi community, underscores the importance of continuous security vigilance and innovation within this dynamic sector.

Based on PeckShield’s findings as a leading blockchain security company, Sonne Finance experienced a well-planned attack. The assault took advantage of weaknesses in the finance platform’s smart contract framework. Reminiscent of Compound v2 forks, this exploit employed a known donation attack method. Despite Sonne Finance’s efforts to strengthen its security measures, the breach still occurred.

Optimism markets suspended

Sonne Finance, known for being the initial lending platform on Optimism, quickly addressed the security breach through an official blog post. In this announcement, the team expressed their sincere apologies for the incident and provided a detailed account of how the exploit occurred. The attackers took advantage of a two-day delay in transaction confirmation, skillfully executing transactions to manipulate market creation and collateral factors within the protocol.

As a researcher looking into this incident, I can report that despite our best attempts to prevent and minimize the damage, Sonne Finance admitted to suffering a loss of funds. An immediate investigation was launched to identify the culprits behind the hack. It’s worth noting that the quick actions of Seal contributors were instrumental in mitigating the situation, as they managed to save around $6.5 million by injecting VELO tokens into affected markets.

Approximately 25 minutes after the exploit was discovered by the Sonne Finance team, all markets on Optimism, operated by the protocol, were suspended immediately. The team also announced their intention to reward the exploiters with a bounty if they returned the misappropriated funds, without any legal repercussions.

As a concerned crypto investor, I understand the importance of taking swift action in response to unexpected events. When Sonne Finance was hit by an attack, my top priority was to minimize any potential harm to user assets. To achieve this, I immediately paused all market activities and initiated discussions with key stakeholders. Our team remained committed to maintaining transparency and accountability throughout the process. We pledged to work alongside external experts to thoroughly investigate the situation and implement effective solutions for recovering the funds.

Read More

2024-05-15 13:35