OceanAltOceanAlt

Security incident · 2020-04-19

dForce Lending

According to the public DefiLlama incident dataset, dForce Lending (Ethereum) suffered a security incident on 2020-04-19, with about $25.0M reported lost.

Date2020-04-19
Reported loss$25.0M
ChainEthereum
Target typeDeFi Protocol
Technique classReentrancy
TechniqueReentrancy
Bridge incidentNo
Within 2020#3 by loss that year, 0.6% of all reported losses that year

How this kind of attack works

The contract sent funds before updating balances, and the attacker re-entered during the transfer to withdraw repeatedly.

Would a pre-payment check have helped

Needs other controls

Reentrancy is a classic contract bug, unrelated to the counterparty; code audits address it.

Other incidents with the same technique

Sources

This page restates public reports and is not OceanAlt's judgment of any party. To report an error, email business@oceanalt.com; we review within 48 hours.

← Back to incidents