DeFi protocol SIR.trading loses entire $355K TVL in ‘worst news’ possible

Ethereum-based DeFi protocol SIR.trading, also known as Synthetics Implemented Right, has been hacked, resulting in the loss of its entire total value locked (TVL) — $355,000 at the time of the attack.
The hack, which occurred March 30, was initially detected by blockchain security firms TenArmorAlert and Decurity, both of which posted warnings on X to alert users of the protocol.
The protocol’s founder, known only as Xatarrer, described the hack as “the worst news a protocol could received [sic],” but suggested they intend to try to keep the protocol going despite the setback.
Source: SIR.trading on X
“Clever attack” targeted contract vault
Decurity described the hack as a “clever attack” that targeted a callback function used in the protocol’s “vulnerable contract Vault” which leverages Ethereum’s transient storage feature.
According to Decurity the attacker was able to replace the real Uniswap pool address used in this callback function with an address under the hacker’s control, allowing them to redirect the funds in the vault to their address. TenArmorAlert further explained that by repeatedly calling this callback function, the attacker was able to fully drain the protocol’s TVL.
Source: Decurity
SupLabsYi, from blockchain security firm Supremacy, went into more detail on the attack in an X post, stating it may demonstrate a security flaw in Ethereum’s transient storage.
Transient storage was added to Ethereum with last year’s Dencun upgrade. The new feature allows for temporary storage of data leading to lower gas fees than regular storage.
According to SupLabsYi, it’s still a “nascent feature,” and the attack may be one of the first to exploit its vulnerabilities.
“This isn’t merely a threat aimed at a single instance of uniswapV3SwapCallback,” SupLabsYi said.
TenArmorSecurity said the stolen funds have now been deposited into an address funded through the Ethereum privacy solution, Railgun. Xatarrer has since reached out to Railgun for assistance.
Related: DeFi hacks drop 40% in 2024, CeFi breaches surge to $694M — Hacken
SIR.trading’s documentation shows that it was billed as “a new DeFi protocol for safer leverage.” The stated purpose of the protocol was to address some of the challenges of leveraged trading, “such as volatility decay and liquidation risks, making it safer for long-term investing.”
While it aimed for safer leveraged trading, the protocol’s documentation did warn users that despite being audited, its smart contracts could still contain bugs that could lead to financial losses — highlighting the platform’s vaults as a particular area of vulnerability.
“Undiscovered bugs or exploits in SIR’s smart contracts could lead to fund losses. These might stem from complex logic in vault mechanics or leverage calculations that audits failed to catch, exposing users to rare but critical failures,” the project’s documentation states.
Magazine: What are native rollups? Full guide to Ethereum’s latest innovation
Bitcoin (BTC) $ 105,451.00
Ethereum (ETH) $ 2,525.78
Tether (USDT) $ 1.00
XRP (XRP) $ 2.16
BNB (BNB) $ 647.55
Solana (SOL) $ 146.07
USDC (USDC) $ 0.999803
TRON (TRX) $ 0.274763
Dogecoin (DOGE) $ 0.169206
Lido Staked Ether (STETH) $ 2,519.84
Cardano (ADA) $ 0.597415
Wrapped Bitcoin (WBTC) $ 105,315.00
Hyperliquid (HYPE) $ 36.64
Wrapped stETH (WSTETH) $ 3,045.68
Bitcoin Cash (BCH) $ 486.32
Sui (SUI) $ 2.81
Chainlink (LINK) $ 13.04
LEO Token (LEO) $ 8.85
Stellar (XLM) $ 0.249380
Avalanche (AVAX) $ 18.13
Toncoin (TON) $ 2.99
WhiteBIT Coin (WBT) $ 49.43
USDS (USDS) $ 0.999807
Shiba Inu (SHIB) $ 0.000012
WETH (WETH) $ 2,528.94
Wrapped eETH (WEETH) $ 2,706.06
Litecoin (LTC) $ 85.39
Hedera (HBAR) $ 0.149275
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998695
Monero (XMR) $ 312.17
Ethena USDe (USDE) $ 1.00
Polkadot (DOT) $ 3.55
Bitget Token (BGB) $ 4.32
Coinbase Wrapped BTC (CBBTC) $ 105,470.00
Uniswap (UNI) $ 7.65
Pepe (PEPE) $ 0.000010
Pi Network (PI) $ 0.549072
Aave (AAVE) $ 260.56
Dai (DAI) $ 0.999331
OKB (OKB) $ 53.55
Ethena Staked USDe (SUSDE) $ 1.18
Bittensor (TAO) $ 347.79
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
Aptos (APT) $ 4.41
Cronos (CRO) $ 0.090204
Internet Computer (ICP) $ 5.09
NEAR Protocol (NEAR) $ 2.16
Jito Staked SOL (JITOSOL) $ 177.20
Ethereum Classic (ETC) $ 16.71
Ondo (ONDO) $ 0.766631
sUSDS (SUSDS) $ 1.06
Tokenize Xchange (TKX) $ 29.58
USD1 (USD1) $ 0.998893
Mantle (MNT) $ 0.629180
Gate (GT) $ 16.67
Fasttoken (FTN) $ 4.46
Official Trump (TRUMP) $ 9.39
VeChain (VET) $ 0.021759
Kaspa (KAS) $ 0.070119
Cosmos Hub (ATOM) $ 4.03
Lombard Staked BTC (LBTC) $ 105,204.00
Artificial Superintelligence Alliance (FET) $ 0.685612
Ethena (ENA) $ 0.285126
POL (ex-MATIC) (POL) $ 0.189823
Sky (SKY) $ 0.079282
Render (RENDER) $ 3.16
Filecoin (FIL) $ 2.34
USDT0 (USDT0) $ 1.00
Binance-Peg WETH (WETH) $ 2,521.43
Arbitrum (ARB) $ 0.304980
Worldcoin (WLD) $ 0.922505
Jupiter Perpetuals Liquidity Provider Token (JLP) $ 4.38
Algorand (ALGO) $ 0.170317
First Digital USD (FDUSD) $ 0.999571
USDtb (USDTB) $ 0.999653
Quant (QNT) $ 99.38
KuCoin (KCS) $ 11.03
Binance Staked SOL (BNSOL) $ 154.98
NEXO (NEXO) $ 1.24
Rocket Pool ETH (RETH) $ 2,880.27
Flare (FLR) $ 0.017485
Jupiter (JUP) $ 0.398039
Kelp DAO Restaked ETH (RSETH) $ 2,647.06
Sei (SEI) $ 0.208358
Kaia (KAIA) $ 0.197152
SPX6900 (SPX) $ 1.22
Celestia (TIA) $ 1.65
Injective (INJ) $ 11.37
Virtuals Protocol (VIRTUAL) $ 1.69
Bonk (BONK) $ 0.000014
Polygon Bridged USDT (Polygon) (USDT) $ 0.999949
Binance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999151
Fartcoin (FARTCOIN) $ 0.969134
Sonic (S) $ 0.308336
Stacks (STX) $ 0.646945
Optimism (OP) $ 0.568605
XDC Network (XDC) $ 0.059202
PayPal USD (PYUSD) $ 0.999786
Mantle Staked Ether (METH) $ 2,701.19
StakeWise Staked ETH (OSETH) $ 2,654.71