简体中文
繁體中文
English
Pусский
日本語
ภาษาไทย
Tiếng Việt
Bahasa Indonesia
Español
हिन्दी
Filippiiniläinen
Français
Deutsch
Português
Türkçe
한국어
العربية
Solana Cashio Hack Loots $52.8M: Investigations Reveal Surprising Facts
Abstract:Crypto trading platform Bybit said that the hack drained $52.8 million worth of stablecoins including USDC, USDT and UST from Cashio and Saber.

Key Insights:
Solanas Cashio hack drained $52.8 million from the protocol.
To prevent, protocols should be properly and thoroughly audited.
Hacker left a message to return funds for accounts below 100K and donate the rest to charity.
Cashio (CASH), a native stablecoin of Solana, recently lost millions after hackers exploited an “infinite mint glitch.” The attackers drained a staggering $52.8 million from the protocol, following which the CASH stablecoin collapsed from $1 to $0.00005, which left the entire decentralized finance (DeFi) ecosystem appalled.
Initially, it was reported that Cashios protocol exploited cryptos equaling about $28 million. According to a security researcher Samczsun, the project lost around $50 million (based on quick skimming).

With these estimates aside, crypto trading platform Bybit came up with a fresh investigation on the hack, discovering precisely $52.8 million of stolen funds.
“The exploited amount also far exceeded what most other publications reported. To elucidate, most publications who reported on this exploit seem to think that $28 million was drained from this hack,” the Bybit readings noted.
As a quick recap, CASH, the dollar-pegged stablecoin, is minted by depositing stable pair liquidity provider tokens (LP tokens), in this case, USDT and USDC pair in a 50:50 ratio on Solanas decentralized exchange – Saber.
What Actually Happened? A to Z of the Hack
FXEmpire spoke to a team from Bybit comprising Derek Lim, head of crypto insights, Gabriel Foo, senior research analyst and Fathur Rahman, COO of SolanaFM, on the alarming exploit. Per their findings, the hacker first managed to mint “two billion CASH tokens” by using the perpetrators unknown tokens. But, how is this possible?
Furthermore, the hacker burnt part of the newly minted CASH tokens (2 billion) for the Saber USDT-USDC LP tokens. The hacker then swapped the LP pair tokens for $16.4 million USDC and $10.8 million USDT.
The Bybit investigations further found that the remaining CASH tokens were swapped out for $8.6 million UST and $17 million USDC through Saber. Finally, the hacker swapped $15.3 million in USDC and USDT after draining $52.8 million.
The hacker used the Jupiter liquidity aggregator on Solana to transfer the funds in 3 transactions to an Ethereum address through the Wormhole Bridge.
How To Prevent such Hacks? Possible Solutions
This isnt the first time a DeFi protocol has been looted for millions; however, this is the first of its kind “infinite mint” glitch. Every time after an attack, HODLers are warned to keep their tokens safe.
To prevent such acts, the team suggested the protocols to ensure that they have been properly and thoroughly audited. He said that DApps should adopt certain Tradfi structures and those of the big tech companies. Talking to FXEmpire,
“In other words, a more stringent auditing process should be initiated.”
This can be achieved by mandatory tests on the devnet for internal checks, during the development phase of any DApps. Furthermore, once the team is ready to stage the product after all internal checks, audit companies and tech alfa groups must step in to clear any bugs, edge cases, etc.
When the beta version is ready, more experts should be brought in to do a final check before the apps roll-out. Team consisting Foo and Rahman added,

Disclaimer:
The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
Read more

ACY SECURITIES Review: Do Traders Face Withdrawal Discrepancies, Forced Liquidation and Poor Support
Does ACY SECURITIES wipe out your trading gains in the name of scalping arbitrage? Do you find their demand for inventory fees illegitimate? Do you sense a Ponzi scam-like investment when trading through the broker? Have you faced a forced liquidation of your forex positions by ACY SECURITIES? There have been a plethora of forex trading complaints against the broker. Read on as we share the ACY SECURITIES review in this article.

Long Position vs Short Position in Forex Trading: Know the Differences
When investing through forex, you often come across terms such as long position and short position. You may wonder what these two mean and how they impact your trading experience. So, the key lies in understanding the very crux of this forex trading aspect, as one wrong step can put you behind in your trading journey. Keeping these things in mind, we have prepared a guide to long position vs short position forex trading. Keep reading!

In-Depth Review of Stonefort Securities Trading Conditions and Execution – What Traders Should Know
This in-depth review dissects Stonefort Securities trading conditions and execution, leveraging primary data from the global broker inquiry app WikiFX and corroborating it with public user feedback. We will analyze the broker's regulatory standing, cost profile, execution quality, and overall operational reliability to provide a clear verdict on whether it is a trustworthy partner for long-term trading.

In-Depth Review of MH Markets Regulation and Compliance Profile – What Traders Should Really Know
This in-depth analysis provides a data-driven examination of the MH Markets regulation and compliance profile. Drawing primarily on verified data from the global broker inquiry app WikiFX, supplemented by public records, we will dissect the broker's multi-jurisdictional licensing, evaluate the real-world protections offered to traders, and interpret the warnings and ratings that define its standing in the competitive forex and CFD landscape.
