ChainCatcher reported that according to Cointelegraph, according to multiple security experts, the Web3 lending application and yield aggregator Wise Lending had 170 ETH stolen in a vulnerability on January 12, worth about $440,000. Blockchain security researcher Spreek speculated that the vulnerability may be related to a new Pendle Finance derivative token.
Blockchain data shows that the attacker used an unverified address ending in d82c to steal funds. Multiple tokens were transferred to the contract, including $9,000 worth of USDC, $2,000 worth of USDT, $5,000 worth of Dai, 18.51 WETH, and a large number of Pendle Finance-related tokens. As part of the exploit, the attacker borrowed 1,110 stETH from the Aave lending protocol, equivalent to about $2.9 million.