Are users responsible for project losses? Stablecoin USD + 30% off overnight

On the evening of July 25, EraLend, the lending protocol with the highest TVL on zkSync, was suddenly hacked. By manipulating the price of the oracle machine, the hacker obtained approximately US$2.76 million in funds from EraLend's USDC pool, and other fund pools were not affected. After the incident, EraLend suspended the borrowing (Borrow) of all pools, as well as the deposit (Supply) function of the USDC pool and SyncSwap LP pool.

In this attack, it wasn't just EraLend users who were victimized, it set off a chain reaction. Holders of the stablecoin USD++ also suffered losses.

Who is USD+?

USD+ is a stable currency product issued by overnight.fi that is deployed on multiple chains such as OP, Arb, and zkSync. Unlike common stablecoins that rely on fiat currency reserves, this product is not directly linked to fiat currency, but is linked to USDC 1: 1.

Is the user responsible for the project loss? Stablecoin USD+ 30% off overnight

(USD+ asset reserve)

Another attractive feature of USD+ is that the stable currency can be held to earn income. The project party invests reserve assets in multiple DeFi agreements. Therefore, this product can understand money market funds in the DeFi world. USD+ can generate a yield of 1% to 5%, and the profits will be distributed daily.

According to the introduction of the official document, the benefits of using USD+ are as follows: it can avoid in-depth market research and frequent transactions, participate in the use of many DeFi protocols, and obtain income without pledge. In addition, the official also made a special statement in the document: "Please note that you will bear the risk of all agreements in the USD+ collateral."

If everything works well (as expected by the project party), then users can own a stablecoin asset that is fully executed on the chain, decentralized, and holds interest. It all sounds pretty good. However, the sky failed, and the security incident of EraLend made USD+ go in another direction.

The city gate catches fire, which affects the fish in the pond

Why do users who hold USD+ get benefits? Because the project's reserve assets include a large number of DeFi assets. Unfortunately, that also includes EraLend deposits.

Is the user responsible for the project loss? Stablecoin USD+ 30% off overnight

According to the official statement, USD+ reserve assets are deposited into EraLend and used as collateral to borrow ETH. Combining the two into USDC/ETH LP, and earning income on mute.io. After the incident, about 283 ETH and 520,000 USDC have been withdrawn from the LP pair.

Is the user responsible for the project loss? Stablecoin USD+ 30% off overnight

(Operation records on the chain)

According to the official statement, since the LP of the project team has lent a large amount of ETH, the net asset exposure on EraLend is not large (the official term is "exposure has been offset"). But the project still faced a loss of some stablecoins.

So far, Overnight officials have not disclosed the specific losses in this security incident on social media. But it can be estimated based on the exposure held by Overnight, Overnight.fi holds $786,162 in EraLend and borrows about 283.0596 ETH ($524,509). This results in a potential maximum loss of $261,652. About 261,000 US dollars, the current supply of USD+ is 3,330,769 pieces, so the potential loss is about 7.86% of the market value.

How does rebase take away user assets?

After the loss, the handling of the Overnight team caused dissatisfaction among all users.

Is the user responsible for the project loss? Stablecoin USD+ 30% off overnight

The team stated that it will "rebase" USD+ to restore its currency price stability. However, there is no detailed explanation on how to rebase.

Through multi-party user comments and community operations, we finally learned that the so-called rebase means recasting the current USD+ into a smaller amount of USD+ according to the reserve value. That is, let users pay to make up for the loss of this incident.

SyncSwap, another DEX project that is also part of the SyncSwap ecosystem, explained it thoughtfully for the majority of users. The USD+ team will take snapshots of USD+ holders and liquidity providers to be used to compensate users for affected funds in the future, but only those who withdraw will be included in the snapshot. If the user makes a withdrawal, it will be "rebase", that is, the balance will be directly reduced. **

Twitter user @Jue 0123 withdrew his USD+. But he was surprised to find that 326 USD+ can only be exchanged for 267 USDC.

Is the user responsible for the project loss? Stablecoin USD+ 30% off overnight

Under the official Twitter, users complained about this. Say bluntly, "You stole my money!"

Is the user responsible for the project loss? Stablecoin USD+ 30% off overnight

Team Operation: Irresponsible, Delete Announcement

In addition to the poor handling of asset losses, the public relations attitude towards this incident is equally bad.

After announcing the rebase, Overnight's official Twitter began to enter the "watering" mode, sending out multiple tweets frantically. At present, it is difficult to swipe tweets related to security incidents within a few screens before the official tweet.

In addition, the official stated that "you can find more detailed information on our Discord." However, the official Discord announcement disclosing this security progress can no longer be opened.

Is the user responsible for the project loss? Stablecoin USD+ 30% off overnight

On Overnight's official website, we can see three products of Overnight from obvious positions: USD+, ETS, USD+ insurance.

Is the user responsible for the project loss? Stablecoin USD+ 30% off overnight

USD+ clearly states that the product is protected by insurance, and "any loss will be compensated from the insurance fund". The USD+ insurance indicates that the product collects a part of the USD+ income as the premium, and the loss of USD+ is first paid by the insurance fund.

In fact, not only the security mechanism design of USD+ has completely failed. Its insurance mechanism did not have any effect, and a series of follow-up processing operations was even more surprising.

What's even more outrageous is that the official website of Overnight.fi announced the information of nine team members, and claimed that they have Internet employment experience such as Google and Facebook. Odaily Planet Daily searched according to the Linkedin (Linkedin) link published on the official website, and found none of the above-mentioned 9 people. The whole project can be described as suspicious.

In the chain world, Code is law, but no unilateral commitment by any project party is trustworthy.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)