• bitcoinBitcoin (BTC) $ 100,358.00
  • ethereumEthereum (ETH) $ 3,223.73
  • tetherTether (USDT) $ 0.999489
  • xrpXRP (XRP) $ 2.15
  • bnbBNB (BNB) $ 910.49
  • usd-coinUSDC (USDC) $ 0.999707
  • staked-etherLido Staked Ether (STETH) $ 3,225.21
  • tronTRON (TRX) $ 0.279747
  • dogecoinDogecoin (DOGE) $ 0.156410
  • cardanoCardano (ADA) $ 0.510304
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • wrapped-stethWrapped stETH (WSTETH) $ 3,933.44
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 100,296.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,487.69
  • hyperliquidHyperliquid (HYPE) $ 36.78
  • chainlinkChainlink (LINK) $ 14.16
  • usdsUSDS (USDS) $ 0.999968
  • bitcoin-cashBitcoin Cash (BCH) $ 471.53
  • ethena-usdeEthena USDe (USDE) $ 0.996632
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998045
  • leo-tokenLEO Token (LEO) $ 9.52
  • wrapped-eethWrapped eETH (WEETH) $ 3,482.60
  • stellarStellar (XLM) $ 0.260009
  • whitebitWhiteBIT Coin (WBT) $ 50.89
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 100,269.00
  • wethWETH (WETH) $ 3,228.77
  • suiSui (SUI) $ 1.91
  • hedera-hashgraphHedera (HBAR) $ 0.162892
  • zcashZcash (ZEC) $ 398.30
  • avalanche-2Avalanche (AVAX) $ 15.48
  • litecoinLitecoin (LTC) $ 82.84
  • moneroMonero (XMR) $ 341.19
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • the-open-networkToncoin (TON) $ 1.88
  • daiDai (DAI) $ 0.999963
  • usdt0USDT0 (USDT0) $ 0.999075
  • crypto-com-chainCronos (CRO) $ 0.117156
  • mantleMantle (MNT) $ 1.24
  • polkadotPolkadot (DOT) $ 2.43
  • memecoreMemeCore (M) $ 2.33
  • susdssUSDS (SUSDS) $ 1.07
  • bittensorBittensor (TAO) $ 390.33
  • internet-computerInternet Computer (ICP) $ 6.31
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.110084
  • usd1-wlfiUSD1 (USD1) $ 0.998531
  • uniswapUniswap (UNI) $ 4.91
  • bitget-tokenBitget Token (BGB) $ 4.04
  • aaveAave (AAVE) $ 185.12
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999422
  • okbOKB (OKB) $ 118.72
  • pepePepe (PEPE) $ 0.000005
  • nearNEAR Protocol (NEAR) $ 1.78
  • ethenaEthena (ENA) $ 0.312433
  • jito-staked-solJito Staked SOL (JITOSOL) $ 190.21
  • ethereum-classicEthereum Classic (ETC) $ 13.87
  • falcon-financeFalcon USD (USDF) $ 0.999315
  • tether-goldTether Gold (XAUT) $ 3,928.64
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.93
  • solanaWrapped SOL (SOL) $ 153.17
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,221.21
  • aster-2Aster (ASTER) $ 0.935339
  • usdtbUSDtb (USDTB) $ 1.00
  • aptosAptos (APT) $ 2.54
  • ondo-financeOndo (ONDO) $ 0.571597
  • pi-networkPi Network (PI) $ 0.213175
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.157779
  • htx-daoHTX DAO (HTX) $ 0.000002
  • worldcoin-wldWorldcoin (WLD) $ 0.680169
  • kucoin-sharesKuCoin (KCS) $ 11.55
  • official-trumpOfficial Trump (TRUMP) $ 7.34
  • dashDash (DASH) $ 114.54
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,703.88
  • hash-2Provenance Blockchain (HASH) $ 0.027714
  • binance-staked-solBinance Staked SOL (BNSOL) $ 164.76
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.10
  • arbitrumArbitrum (ARB) $ 0.246224
  • bfusdBFUSD (BFUSD) $ 0.999318
  • algorandAlgorand (ALGO) $ 0.149364
  • pax-goldPAX Gold (PAXG) $ 3,924.33
  • gatechain-tokenGate (GT) $ 11.01
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 36.94
  • pump-funPump.fun (PUMP) $ 0.003569
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.13
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,417.22
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,409.35
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 100,567.00
  • ignition-fbtcFunction FBTC (FBTC) $ 98,893.00
  • wbnbWrapped BNB (WBNB) $ 910.52
  • skySky (SKY) $ 0.051552
  • story-2Story (IP) $ 3.61
  • vechainVeChain (VET) $ 0.013581
  • cosmosCosmos Hub (ATOM) $ 2.44
  • kaspaKaspa (KAS) $ 0.043086
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,466.07
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999712
  • jupiter-exchange-solanaJupiter (JUP) $ 0.336173
  • flare-networksFlare (FLR) $ 0.013587
  • nexoNEXO (NEXO) $ 1.04
  • ripple-usdRipple USD (RLUSD) $ 0.999539
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,426.30
  • quant-networkQuant (QNT) $ 70.34
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 99,914.00
  • global-dollarGlobal Dollar (USDG) $ 0.999733
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.995735
  • sei-networkSei (SEI) $ 0.153995
  • render-tokenRender (RENDER) $ 1.83
  • filecoinFilecoin (FIL) $ 1.33
  • xdce-crowd-saleXDC Network (XDC) $ 0.049970
  • bonkBonk (BONK) $ 0.000011
  • fasttokenFasttoken (FTN) $ 2.01
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.013750
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.32
  • morphoMorpho (MORPHO) $ 1.59
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.88
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,515.32
  • hashnote-usycCircle USYC (USYC) $ 1.10
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 100,070.00
  • immutable-xImmutable (IMX) $ 0.400687
  • ousgOUSG (OUSG) $ 113.16
  • clbtcclBTC (CLBTC) $ 97,991.00
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 175.86
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.13
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • aerodrome-financeAerodrome Finance (AERO) $ 0.764439
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,441.29
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.997070
  • decredDecred (DCR) $ 39.31
  • celestiaCelestia (TIA) $ 0.756867
  • lido-daoLido DAO (LDO) $ 0.704863
  • optimismOptimism (OP) $ 0.332091
  • blockstackStacks (STX) $ 0.345706
  • injective-protocolInjective (INJ) $ 6.27
  • msolMarinade Staked SOL (MSOL) $ 204.19
  • tbtctBTC (TBTC) $ 100,163.00
  • beldexBeldex (BDX) $ 0.080512
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999709
  • usdaiUSDai (USDAI) $ 1.00
  • curve-dao-tokenCurve DAO (CRV) $ 0.406575
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999747
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,229.13
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,420.43
  • the-graphThe Graph (GRT) $ 0.053352
  • spx6900SPX6900 (SPX) $ 0.589402
  • doublezeroDoubleZero (2Z) $ 0.158402
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,228.42
  • flokiFLOKI (FLOKI) $ 0.000056
  • tezosTezos (XTZ) $ 0.507953
  • usual-usdUsual USD (USD0) $ 0.997822
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.201316
  • pyth-networkPyth Network (PYTH) $ 0.088595
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.995233
  • iotaIOTA (IOTA) $ 0.121543
  • stader-ethxStader ETHx (ETHX) $ 3,463.43
  • gtethGTETH (GTETH) $ 3,224.95
  • kaiaKaia (KAIA) $ 0.084154
  • true-usdTrueUSD (TUSD) $ 0.995736
  • cognifyCognify (SN115) $ 1,762.47
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 100,435.00
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • ether-fiEther.fi (ETHFI) $ 0.833762
  • newton-projectAB (AB) $ 0.005443
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.10
  • starknetStarknet (STRK) $ 0.100796
  • humanityHumanity (H) $ 0.249251
  • sbtc-2sBTC (SBTC) $ 100,279.00
  • plasmaPlasma (XPL) $ 0.233688
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,551.28
  • conflux-tokenConflux (CFX) $ 0.084837
  • sonic-3Sonic (S) $ 0.115150
  • pendlePendle (PENDLE) $ 2.55
  • swethSwell Ethereum (SWETH) $ 3,553.40
  • bittorrentBitTorrent (BTT) $ 0.00000043
  • ghoGHO (GHO) $ 0.999103
  • ark-3ARK (ARK) $ 39.36
  • bitcoin-svBitcoin SV (BSV) $ 21.05
  • usddUSDD (USDD) $ 0.999303
  • the-sandboxThe Sandbox (SAND) $ 0.169028
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,220.52
  • sun-tokenSun Token (SUN) $ 0.021261
  • ethereum-name-serviceEthereum Name Service (ENS) $ 12.22
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.155805
  • satoshi-stablecoinSatoshi Stablecoin (SATUSD) $ 0.997967
  • usdbUSDB (USDB) $ 0.981972
  • jasmycoinJasmyCoin (JASMY) $ 0.008159
  • heliumHelium (HNT) $ 2.11
  • apenftAINFT (NFT) $ 0.00000040
  • dogwifcoindogwifhat (WIF) $ 0.392838
  • theta-tokenTheta Network (THETA) $ 0.390843
  • syrupMaple Finance (SYRUP) $ 0.350470
  • vaultaVaulta (A) $ 0.241471
  • galaGALA (GALA) $ 0.008293
  • jelly-my-jellyJelly-My-Jelly (JELLYJELLY) $ 0.379690
  • wrapped-hypeWrapped HYPE (WHYPE) $ 37.04
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.20
  • zksyncZKsync (ZK) $ 0.051974
  • decentralandDecentraland (MANA) $ 0.195233
  • flowFlow (FLOW) $ 0.229808
  • myx-financeMYX Finance (MYX) $ 1.93

Asymmetric Research discloses Marginfi flash loan bug that risked $160M

0 19

Asymmetric Research discloses Marginfi flash loan bug that risked $160M

Marginfi, a Solana-based lending and borrowing protocol, has patched a critical vulnerability in its flash loan mechanism that briefly placed more than $160 million in user deposits at risk.

The bug, disclosed by security researcher Felix Wilhelm through Marginfi’s bug bounty program, would have allowed an attacker to borrow funds without repaying them. The issue was resolved before any exploit occurred, and no funds were lost, according to Asymmetric Research’s report.

Flash loans, a common DeFi feature, allow users to borrow nearly all available liquidity on the condition that the funds are repaid within the same blockchain transaction. Solana protocols typically enforce this by introspecting instructions in a transaction to ensure a repayment step is included.

According to Asymmetric, Marginfi followed this approach but introduced a new instruction, transfer_to_new_account, that unintentionally bypassed repayment checks. This meant liabilities could be shifted to a new account mid-loan, enabling funds to be drained without triggering safeguards.

The report indicates that the Marginfi team swiftly deployed a patch to block account transfers during flash loans and prevent disabled accounts from being used for repayment. While Solana’s architecture limits some common Ethereum-style exploits, the vulnerability underscores that logic errors remain a critical threat.

The swift resolution demonstrates the role of bug bounty programs in preventing systemic losses. Similar past incidents, including attacks on Mango Markets and other Solana-based protocols, have shown how flash loan vulnerabilities can lead to multimillion-dollar losses.

Marginfi representatives did not respond to Blockworks’ request for comment before publication.

Source

Leave A Reply

Your email address will not be published.