【DeFi Protocol 79thVault Suffers a Security Attack, On-Chain Lending Makes a Comeback Amid Composite Risks】
According to reports from multiple media outlets, on October 8, the decentralized finance (DeFi) protocol 79thVault suffered a security attack, with losses of approximately $12.5 million. Monitoring by blockchain security firms PeckShield and CertiK indicates that the attacker used privileged functions to sell tokens, then exchanged the assets for BNB and transferred them to an external address. At present, the project team has publicly offered a 10% bug bounty to the attacker’s address in an attempt to recover the assets, but most of the stolen funds remain stuck in addresses controlled by the attacker.
This security incident has once again sparked market scrutiny of permission management and code vulnerabilities in DeFi protocols. In protocol operations, the purpose of setting privileged functions is usually to handle emergencies or conduct routine maintenance. However, if strict governance constraints such as multisignature controls or time locks are lacking, once a private key is leaked or permissions are abused, it can easily evolve into a catastrophic security event.
Meanwhile, industry data shows that the crypto lending market has been rebounding since July, but the on-chain security environment has not improved accordingly. Analysts point out that as on-chain lending expands in scale, it is facing new challenges brought by the evolution of AI-assisted attack tools, as well as risk contagion among multiple interconnected protocols. This coexistence of renewed capital inflows and ongoing security threats places higher demands on risk-control capabilities across all types of protocols.
Given the increasingly complex landscape of on-chain security, how to build a more resilient defensive system while pursuing capital efficiency and functional innovation has become an urgent issue for the industry to solve. In the backdrop of ever-updating automated attack methods, is relying solely on post-incident bounty recovery or passive defense enough to protect users’ assets?
According to reports from multiple media outlets, on October 8, the decentralized finance (DeFi) protocol 79thVault suffered a security attack, with losses of approximately $12.5 million. Monitoring by blockchain security firms PeckShield and CertiK indicates that the attacker used privileged functions to sell tokens, then exchanged the assets for BNB and transferred them to an external address. At present, the project team has publicly offered a 10% bug bounty to the attacker’s address in an attempt to recover the assets, but most of the stolen funds remain stuck in addresses controlled by the attacker.
This security incident has once again sparked market scrutiny of permission management and code vulnerabilities in DeFi protocols. In protocol operations, the purpose of setting privileged functions is usually to handle emergencies or conduct routine maintenance. However, if strict governance constraints such as multisignature controls or time locks are lacking, once a private key is leaked or permissions are abused, it can easily evolve into a catastrophic security event.
Meanwhile, industry data shows that the crypto lending market has been rebounding since July, but the on-chain security environment has not improved accordingly. Analysts point out that as on-chain lending expands in scale, it is facing new challenges brought by the evolution of AI-assisted attack tools, as well as risk contagion among multiple interconnected protocols. This coexistence of renewed capital inflows and ongoing security threats places higher demands on risk-control capabilities across all types of protocols.
Given the increasingly complex landscape of on-chain security, how to build a more resilient defensive system while pursuing capital efficiency and functional innovation has become an urgent issue for the industry to solve. In the backdrop of ever-updating automated attack methods, is relying solely on post-incident bounty recovery or passive defense enough to protect users’ assets?