DeFi Protocol SIR.trading Suffers $350,000 Hack

The recent hack on SIR.trading raises significant concerns about the security of Ethereum's transient storage feature and its implications for decentralized finance protocols.

Summary

On March 30, 2023, the DeFi protocol SIR.trading was exploited, resulting in a total loss of $355,000. The attack, first reported by TenArmor, exploited a vulnerability in the Vault contract's transaction verification process. Security experts warn that this incident highlights critical security flaws in the use of transient storage in smart contracts, necessitating stronger safeguards.

Terms & Concepts
  • Transient Storage: A temporary storage technique in Ethereum introduced in the EIP-1153 upgrade, which resets only after a transaction ends.
  • Vault Contract: A smart contract used in DeFi protocols to manage and secure user funds.
  • Decentralized Finance (DeFi): A blockchain-based form of finance that does not rely on central financial intermediaries.