Force token sees volatile 24 hours following coordinated attack on ForceDAO

Hackers made off with 183 Ether (ETH), worth roughly $386,000 at the time of writing, following a coordinated attack on DeFi platform ForceDAO Sunday. Following an initial sell-off, ForceDAO’s native Force token was in recovery mode on Monday, capping off a highly volatile 24 hours for the newly launched project. 

ForceDAO detailed the Sunday exploit in a series of tweets, taking ownership of the “engineering oversight” that resulted in the attack, which centered around the platform’s xFORCE contract. 

POST-MORTEMTo the Force and DeFi community, we'd like to share a post-mortem on the recent xFORCE exploit.Thanks to everyone technical and non-technical who helped along the way.Especially to the White Hat who helped deter FORCE getting drained.https://t.co/MK2GH69yLd

— Force (@force_dao) April 4, 2021

In a follow-up blog post, Alberto Cevallos explained:

“The exploiters were able to deposit FORCE tokens that would fail the transfer [f]rom call and receive xFORCE tokens, as the xFORCE contract expects a revert from the token but instead receives false.”

He continued:

“A user could then withdraw these newly minted xFORCE tokens for the remaining FORCE tokens in the vault, and liquidate them for ETH on exchanges.”

An additional 14.8 million Force tokens were compromised in the initial attack, though they’ve since been returned to the pool.

Often described as a quantitative hedge fund, Force is both a protocol and decentralized autonomous organization that’s designed to produce higher-yielding DeFi opportunities for its community.

The Force token collapsed more than 99% on Sunday from $2.21 to a low of just $0.02 cents, according to CoinGecko. The token has since recovered 173% in the last 24 hours.

​​Cream Finance DeFi platform loses $19M in a flash loan hack   Aug. 30, 2021
Yearn.Finance puts expanded treasury to use by repaying victims of $11M hack   Feb. 9, 2021
Jump Crypto replenishes funds from $320M Wormhole hack in largest-ever DeFi 'bailout'   Feb. 3, 2022
Rari Fuze hacker offered $10M bounty by Fei Protocol to return $80M loot   May 1, 2022
Lodestar Finance exploited in flash loan attack   Dec. 11, 2022