After patching a critical vulnerability in its newly launched Augustus v6 smart contract last week, decentralized finance aggregator ParaSwap is redistributing crypto back to its users.
The ParaSwap Augustus v6 contract went live on March 18, aiming to improve swapping efficiency and reduce gas fees. There was, however, a critical vulnerability in the contract that allowed hackers to drain funds when approved.
ParaSwap returned some of the funds
On March 24, the DeFi platform team posted on X that they returned all assets to wallets that were successfully recovered by white hat hackers and have also revoked permissions to AugustusV6.
ParaSwap reports that 213 addresses have not yet revoked allowances to the flawed contract. The team is asking all users to revoke permissions to the contract as soon as possible.
In most cases, revoking a smart contract involves disabling or terminating its functionality on a blockchain and preventing it from accessing the user’s wallet.
ParaSwap disclosed last week that it discovered a vulnerability in a newly launched smart contract, but prevented a large loss of assets. After discovering the vulnerability on March 20, ParaSwap paused the v6 application programming interface (API) and secured potential victims’ funds through a white hat hack.
Initiated investigation for the rest
Additionally, the team reported that it had submitted a comprehensive report to the appropriate authorities, beginning the investigation into the stolen funds.
In partnership with blockchain analytics and security firms Chainalysis and TRM Labs, ParaSwap is “actively engaged in identifying hacker addresses and tracing the movement of the funds.”
Using on-chain messaging, the team contacted the identified hacker addresses and requested that the stolen funds be returned.
If the hacker does not respond by March 27, “we will assume you appropriated the funds with unlawful intent, and we will pursue all criminal, legal, and administrative avenues,” to recover them, it added.
However, the amount was tiny at that time with the first investigation suggesting that only $24,000 was stolen before the vulnerability was noticed and stopped.
ParaSwap uncovered the flaw in its newly released Augustus v6 smart contract on March 20, just days when the smart contract was deployed on March 18 that aimed to make swaps better and reduce transfer fees.
The platform stopped the application programming interface (API) at this particular point in time and later allocated the money through a white hat hack.
