Seneca Protocol hack highlights dangers of Ethereum’s token approval mechanism
A bug in crypto lending platform Seneca Protocol was exploited on Wednesday to steal funds directly from users’ wallets. Losses so far exceed $3 million on the Ethereum and Arbitrum networks. Seneca is a decentralized finance (DeFi) project that allows users to borrow the stablecoin senUSD against yield-bearing assets such as deposit tokens and liquid staking tokens (LSTs). The suspicious transactions were brought to the attention of the crypto community by pseudonymous X (formerly Twitter) user Spreek. Looks like Seneca Protocol has a critical approval exploit (open external call). $3m+ lost so far across eth/arb pic.twitter.com/MkbNShtPUm — Spreek (Denver 28th-5th) (@spreekaway) February 28, 2024 Read more: Ethereum liquid staking braces for April 12 withdrawals Crypto security researcher Daniel Von Fange identified the bug in Seneca’s code, adding that he was removed from the project’s Discord where the team was deleting references to the exploit . Another user, goin...