'Free Money' Bug Hits DeFi Platform Alchemix

The bug resulted in roughly 2,000 ETH (or $4.8 million at today's prices) being returned to borrowers prematurely.

AccessTimeIconJun 16, 2021 at 6:12 p.m. UTC
Updated Sep 14, 2021 at 1:12 p.m. UTC

Decentralized finance (DeFi) protocol Alchemix has resolved a bug that seemingly forgave borrowers’ loans prematurely, essentially giving them free money.

One DeFi observer on Twitter called it a “reverse rug pull,” referring to the crypto slang for when project founders abscond with user funds.

For an unknown amount of time, Alchemix borrowers could deposit ETH, get the project's alETH token in return and then withdraw the ETH used to secure their loans without having to pay them back.

"I was successfully able to borrow alETH, and take my collateral," user ptp1600 said in the Alchemix Discord server.

The issue seemingly affected the alETH pool, which was launched yesterday.

The Alchemix team said it’s investigating the issue and will publish a postmortem shortly. In the meantime, “the alETH contract has been paused and will remain so until our solution is implemented,” the project tweeted.

Alchemix co-founder Scoopy Trooples did not return a request for comment when initially contacted.

Postmortem

Alchemix published a postmortem of the snafu at 3:29 p.m. ET. No user funds were lost, rather users were able to withdraw ETH they should not have. 

The bug started around midnight UTC, when users discovered they had “no outstanding debt even though they previously borrowed alETH at a 4:1 collateral ratio,” project admin n4n0 wrote.

It took about 15 minutes for Alchemix to halt the minting of alETH once the team started looking into the issue, n4n0 said.

The root cause: “the alETH vault accidentally created additional vaults,” the incident report notes.

The post concludes with an ask:

“If you would like to support the protocol, the DAO, and the devs, please consider distributing any excess ETH gained during this time to the new Transmuter, to allow it to back the outstanding loans that it created (and you are likely still holding). A portal will be created in the next few days to facilitate this. This will go a long way towards correcting the alETH shortfall and will impact DAO’s treasury much less.”

Alchemix’s native token, ALCX, is down 21.5% since the bug was first noticed, according to CoinGecko.

Brady Dale contributed reporting.

UPDATE (June 17, 1:51 UTC): Adds information from Alchemix's incident report.


Read more about

DISCLOSURE

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

Trending

1
CoinDesk - Unknown
First Mover Asia: Bitcoin Holds Above $21K in Weekend Trading; Solana Web3 Phone Faces Long Odds

Ether stays over $1,200; prior blockchain phones have failed because the market has realized their functionalities are already available via apps that can be loaded onto any old phone.

CoinDesk - Unknown
2
CoinDesk - Unknown
Opaque Platforms and Intertwined Protocols Pose Big Risk to Crypto

Second article in a series about risks we’re thinking about during these crypto down days.

CoinDesk - Unknown
3
CoinDesk - Unknown
Putin Weaponizes Inflation

Examining a recent propaganda speech from the Russian leader.

CoinDesk - Unknown
4
CoinDesk - Unknown
Morgan Creek Is Trying to Counter FTX’s BlockFi Bailout, Leaked Call Shows

FTX’s $250 million credit facility offer – if inked as initially proposed – stood to effectively wipe out all BlockFi shareholders, including Morgan Creek Digital, the firm told its investors.

CoinDesk - Unknown