SushiSwap, the DeFi peer and rival protocol of Uniswap, joins the ranks of DeFi attack victims and exploits that are becoming increasingly popular within this growing industry. 

There is no doubt that decentralized finance ecosystems, also known as DeFi, are becoming the preferred target of hackers and malicious actors to carry out their attacks and steal users' deposited funds. 

Sushi Swap, the decentralized finance protocol that is equal to Uniswap, is the latest victim of DeFi hackers, suffering a recent attack where it lost around $15.000 USD. The loss of user funds did not transcend to larger numbers thanks to the fact that protocol observers and the anonymous lead developer and "chef" of SushiSwap, 0xMaki, they noticed the attack in time and managed to thwart it. 

As 0xMaki reports on his Twitter account, he initially didn’t notice the attack, but then he realized that something unusual was going on, so he informed two other SushiSwap developers, who began reviewing the transactions until they noticed the exploit. An unusual user had made a micro transaction about 2 or 3 days earlier, stealing the commission income of the protocol participants, so the amount involved in the theft was not that high. 

One of the developers who detected the attack explained that the hacker used “really weird logic to extract the underlying tokens from the bounty contract.” 0xMaki informed the crypto community that details on how this attack happened will be revealed soon in a full report, in the meantime users can access SushiSwap’s Discord channel, #sushinomics, to learn more details about the exploit. 

It may interest you: SushiSwap, the DeFi trend of the moment, has a new administration

Guaranteed theft and reward for the exploit

Sushibar funds affected by the exploit, estimated to be between $10.000 and $15.000 USD, will be covered by SushiSwap's insurance fund, allowing affected users to recover their earnings. 

Even though the exploit was detected and the developers managed to patch the vulnerability quickly, they also recognized the hacker’s skill, so they decided to send him a message to “thank him” for the attack, which allowed them to notice the vulnerability in SushiSwap. The developers informed the hacker that they would give him a reward, from their bug detection program, for discovering the flaw. 

0xMaki assured that this is not a hack of SushiSwap, but rather the detection of a vulnerability in the protocol, so the attacker deserves the reward offered. 

Security in SushiSwap

SushiSwap is a DeFi protocol AMM (Automated Market Maker) which is presumed to maintain constant audits to verify the security conditions of its platform. Recently, in September, the blockchain security company, Quantstamp, carried out an audit of the protocol finding at least 10 security vulnerabilities, not critical or high risk, but which were nonetheless informed immediately to the protocol developers group to warn their users and work on solutions to correct them. 

Thus, despite the formal audits that DeFi protocols may carry out, it is evident that there are still security flaws or errors that can be discovered by a malicious actor to steal funds. 

At the time of this edition, the SushSwap SUSHI token has a value of $1,59 USD, showing a growth of more than 12% in the last 24 hours, and 163% in the last 30 days. 

Continue reading: DeFi hacks continue to increase, risking investor and user funds