Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Dolomite Exchange Breach: Hacker Pilfers $1.8M in USDC

Dolomite Exchange Breach: Hacker Pilfers $1.8M in USDC

CryptodailyCryptodaily2024/03/21 14:55
By:Amara Khatri

Table of Contents

  • Exploited Contract and Methodology
  • Mechanism of Attack
  • Mitigation Measures and Recommendations
  • March's String of Exploits

A hacker exploited vulnerabilities in Dolomite's smart contracts, absconding with $1.8 million in USDC, prompting the exchange's development team to issue mitigation measures. 

Exploited Contract and Methodology

A recent report from blockchain security platform CertiK reveals a significant security breach within the Dolomite crypto exchange. An old contract, once utilized by Dolomite, became the gateway for a hacker to abscond with approximately $1.8 million worth of USD Coin (USDC).

Dolomite, a decentralized exchange and money market protocol, initially launched on Ethereum in 2019 before migrating to the Arbitrum network in 2022. Despite transitioning away from Ethereum, users can still access its Ethereum version utilizing developer tools owing to the immutable nature of smart contracts. 

The fact that the hackers were able to gain access to the protocol and steal funds from the auditors despite precautionary measures is being considered a serious security concern. 

Mechanism of Attack

The exploited contract, named 'DolomiteMarginProtocol,' harbored vulnerabilities stemming from permissions granted to the owner, predating its elimination in 2020. The assailant capitalized on a function termed "callFunction," enabling arbitrary calls despite the presence of a "noEntry" modifier designed to thwart reentrancy attacks.

Despite the intended safeguarding through the "noEntry" modifier, the attacker circumvented restrictions by leveraging a function housed in a separate contract, 'SoloMargin,' effectively bypassing security measures. 

This exploit allowed the attacker to siphon funds from users, with all pilfered assets eventually funneled into a certain wallet address and subsequently deposited into Tornado Cash .

Mitigation Measures and Recommendations

To reduce the damage, Dolomite's development team advised users to revoke approvals to the Ethereum Dolomite address starting with 0xe2466, which was implicated in the breach. While users solely interacting with the current version on Arbitrum are deemed unaffected, the team has disabled the compromised contract as an added precaution. Nonetheless, users have been urged to revoke approvals to mitigate potential risks.

March's String of Exploits

This incident adds to a series of breaches occurring in March within the crypto space. Notably, on March 11, the Unizen protocol on Ethereum suffered losses exceeding $2.1 million due to an approval exploit. Similarly, on March 15, Mozaic Finance lost over $2.4 million, which was attributed to a compromised private key.

Ultimately, the attack on Dolomite's smart contracts highlights the ongoing risks decentralized platforms face. Therefore, with the industry fast evolving into a significant contender in the global economy, maintaining a high level of awareness and taking proactive steps is crucial to protecting user funds. 

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. 

Investment Disclaimer
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

New spot margin trading pair — BARD/USDT!

Bitget Announcement2025/09/19 07:28

BTC/ETH VIP Earn Ultimate Carnival is officially here!

Bitget Announcement2025/09/18 07:12

New spot margin trading pair — FLOCK/USDT!

Bitget Announcement2025/09/18 06:55

0GUSDT now launched for pre-market futures trading

Bitget Announcement2025/09/18 05:39