Officer's Blog

Posted on Mar 27, 2023Read on Mirror.xyz

Spotter Digest №3

We will gradually expand the capabilities of our Pessimistic Spotter on-chain monitoring & defense service and provide additional details in the subsequent digest piece!

Follow:

https://officercia.mirror.xyz/X6diACabI-hfoyoIuhaPBjADfBx_dYmEE-uoTylVzbU

https://officercia.mirror.xyz/mHwaLUUjxSRODvMfhT9YmEbDsN9z6i87Xb4IPwfCvCs

https://officercia.mirror.xyz/W-SUbkTf18b3RuPL9DykXQmpexWBZxbp4P1xfCfXo4Y


Ndxfi DEGEN token Exploit: Thoughts

As you are probably aware, on March 20th, a series of transactions involving the Ndxfi DEGEN token resulted in an attacker profit of approximately 110 ETH! The initial root cause was the incorrect calculation of the tokenAmountOut value by “calcSingleOutGivenPoolIn()”…

The original attacker submitted to mempool with low gas and was frontrunned by an MEV bot:

There is also a take that it was rather a balancing arbitrage which takes advantage of the fact that weights haven’t been updated for DEGEN for a year than an actual attack. Anyway, this does not change the fact that, among other things, we could protect the project from this as well.

Our Spotter system detected this attack before it actually happened!

The system successfully operated and took action very quickly (it recognized an attack and thus performed the first step — detection), demonstrating once more that it is possible to then pause contracts, launch counterattacks, and take other actions when connecting the experimental part of the Spotter to the supported project…

https://twitter.com/pessimistic_io/status/1637832890162593792?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1637832890162593792%7Ctwgr%5Ef894f66c2fe0a85c66718289c0b792d031779562%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fcdn.embedly.com%2Fwidgets%2Fmedia.html%3Ftype%3Dtext2Fhtmlkey%3Da19fcc184b9711e1b4764040d3dc5c07schema%3Dtwitterurl%3Dhttps3A%2F%2Ftwitter.com%2Fpessimistic_io%2Fstatus%2F1637832890162593792image%3Dhttps3A%2F%2Fi.embed.ly%2F1%2Fimage3Furl3Dhttps253A252F252Fabs.twimg.com252Ferrors252Flogo46x38.png26key3Da19fcc184b9711e1b4764040d3dc5c07

To put it another way, our system operates in an experimental mode, and the test indicated that we would have sufficient time to respond:

There were at least three different approaches that we actually could take in order to counteract this attack, presuming that it would occur to the supported protocol in the same manner that it occurred to Ndxfi (on a public pool):

It is important to mention that currently our system does not counter-attack (and does monitoring only) as we first need to sign a contract with the protocol. Nevertheless, we have confirmed the theoretical possibility of active protection and will continue our research in this direction:

https://twitter.com/urbittesweet/status/1637838867532328962?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1637838867532328962%7Ctwgr%5Ebe83c3cff96a5d39504d662a11c7243e3340b6d2%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fcdn.embedly.com%2Fwidgets%2Fmedia.html%3Ftype%3Dtext2Fhtmlkey%3Da19fcc184b9711e1b4764040d3dc5c07schema%3Dtwitterurl%3Dhttps3A%2F%2Ftwitter.com%2Furbittesweet%2Fstatus%2F16378388675323289623Fs3D20image%3Dhttps3A%2F%2Fi.embed.ly%2F1%2Fimage3Furl3Dhttps253A252F252Fabs.twimg.com252Ferrors252Flogo46x38.png26key3Da19fcc184b9711e1b4764040d3dc5c07


Pessimistic.io News

Some news from our ‘‘parent’’ auditing company that we think is important enough to mention!

https://twitter.com/officer_cia/status/1638183893177081905?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1638190947895746561%7Ctwgr%5E78f155d12d98c4121d728ea72bf390904f8c21fb%7Ctwcon%5Es2_&ref_url=https%3A%2F%2Fcdn.embedly.com%2Fwidgets%2Fmedia.html%3Ftype%3Dtext2Fhtmlkey%3Da19fcc184b9711e1b4764040d3dc5c07schema%3Dtwitterurl%3Dhttps3A%2F%2Ftwitter.com%2FPatrickAlphaC%2Fstatus%2F16381909478957465613Fs3D20image%3Dhttps3A%2F%2Fi.embed.ly%2F1%2Fimage3Furl3Dhttps253A252F252Fabs.twimg.com252Ferrors252Flogo46x38.png26key3Da19fcc184b9711e1b4764040d3dc5c07

  • We are happy to report that Spotter is becoming more and more popular and is getting the attention it deserves:

https://twitter.com/Tettehnetworks/status/1637061876625334272?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1637061876625334272%7Ctwgr%5Ef3754e3443241934d7c71a0692c870178c0d6e71%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fcdn.embedly.com%2Fwidgets%2Fmedia.html%3Ftype%3Dtext2Fhtmlkey%3Da19fcc184b9711e1b4764040d3dc5c07schema%3Dtwitterurl%3Dhttps3A%2F%2Ftwitter.com%2Ftettehnetworks%2Fstatus%2F1637061876625334272image%3Dhttps3A%2F%2Fi.embed.ly%2F1%2Fimage3Furl3Dhttps253A252F252Fabs.twimg.com252Ferrors252Flogo46x38.png26key3Da19fcc184b9711e1b4764040d3dc5c07

https://twitter.com/msbenighted/status/1636626116105388033?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1636626116105388033%7Ctwgr%5E336c693c9848ff218af125837187ea57f19776cf%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fcdn.embedly.com%2Fwidgets%2Fmedia.html%3Ftype%3Dtext2Fhtmlkey%3Da19fcc184b9711e1b4764040d3dc5c07schema%3Dtwitterurl%3Dhttps3A%2F%2Ftwitter.com%2Fmsbenighted%2Fstatus%2F16366261161053880333Fs3D20image%3Dhttps3A%2F%2Fi.embed.ly%2F1%2Fimage3Furl3Dhttps253A252F252Fabs.twimg.com252Ferrors252Flogo46x38.png26key3Da19fcc184b9711e1b4764040d3dc5c07

To make sure you don’t miss anything, subscribe to our blog! All articles are also posted on my (Officer's Notes) personal Mirror blog:

https://officercia.mirror.xyz/Uc1sf64yUCb0uo1DxR_nuif5EmMPs-RAshDyoAGEZZY


Follow:

We also hope for your support because we think this market is crucial, first and foremost for the overall security of our industry!

https://t.me/pessimistic_spotter_public

You can subscribe to our blog to make sure you don’t miss any of the regular news and updates we plan to publish on the project in a special digest!

In the following articles we will gradually expand the functionality of our service and provide an opportunity to test it on your system. We’ll let you know the release date soon, stay tuned! 🙂

https://officercia.mirror.xyz/X6diACabI-hfoyoIuhaPBjADfBx_dYmEE-uoTylVzbU

Thank you very much for your attention!


Support is very important to me, with it I can do what I love — educating users!

If you want to support my work, you can send me a donation to the address:

https://github.com/OffcierCia/support

Stay safe!