An attacker done a flash loan attack on an Avalanche stableswap platform, stealing loads of million dollars-payment of crypto.

A Feb. 16 alert from blockchain security firm Certik disclosed that Platypus DeFi, a stablecoin swapping platform built on the Avalanche blockchain, misplaced $8.5 million in an exploit.

Platypus DeFi acknowledged the exploit on Twitter, announcing that the hacker took advantage of its stablecoin’s solvency check mechanism. The protocol’s U.S.-dollar pegged stablecoin Platypus USD (USP) misplaced greater than 50% of its payment after the exploit. USP became procuring and selling at spherical $0.47 on the time of writing.

The Platypus DeFi team also appears to be like to get tried to talk with the hacker, in step with a message encoded in a transaction on the Avalanche blockchain.

“We are able to give you a in reality beneficiant bounty (% of stolen funds) to your efforts to to find this narrate. Whenever you happen to are appearing as white hat, please web in touch with us,” be taught the message, viewable on Avalanche blockchain explorer Snowtrace.

Users get also reported that deposits and withdrawals on the predominant pool on the stableswap platform were fleet suspended.

On-chain sleuth ZachXBT great that the hacker’s pockets address has already been blacklisted by Tether.

An just diagnosis of the attack from on-chain analyst Daniel Von Fange found that the attacker mild an “emergency withdraw” aim on the dapper contract to realize the exploit.

“It is a substandard seek for USP auditors, who can get to unruffled get caught this fairly trivial malicious program,” tweeted web3 investor “@demirelo” on Twitter.

While the hacker made extra than one contracts to invent the exploit, the broad majority of stolen funds became done by this major attack contract, which would not appear to get a mechanism to withdraw them from this jam.

“appears to be like there is a fairly honest likelihood the attacker’s funds are trapped with out a sign of ending with out a system for him to withdraw successfully from his attack contract,” tweeted Twitter user “@spreekaway.”