BonqDAO report of the attack on the Bonq protocol on February 1, 2023
The description of the attackOn Feb 1st, 2023 at around 6:30 pm UTC, an unknown attacker was able to mint 100 million BEUR in tx 0x31957ecc43774d19f54d9968e95c69c882468b46860f921668f2c55fadd51b19 by manipulating the price of ALBT in Bonq troves. They were able to do so because of a bug in the TellorPriceFeed contract deployed by BonqDAO which reads the price of WALBT from the Tellor oracle. The bug in question was due to the fact that the PriceFeed uses the function getCurrentValue instead of...

Bonq 2.0 recovery/reboot proposal for BonqDAO
Last update: Feb 25, 2023Bonq 1.0On Dec 15, 2022, BonqDAO launched on Polygon as a zero-interest lending protocol with a native stable coin -BEUR. Over the next 6 weeks, things were looking good. BEUR was stable, the protocol generated cashbacks for BNQ (a native utility token on the Bonq protocol) stakers, and over 80% of BNQ in circulation were staked. On Jan 31, 2023, BonqDAO was listed in top 20 by TVL on Polygon on DeFi Llama. This proved that the initial mechanism design and the user in...

Whitelisting Criteria for New Tokens and the Risk Model Methodology
This document outlines the Bonq DAO Whitelisting methodology, its main categories, and factors that impact the process. Bonq DAO relies on these underlying factors to assess a web3 project /protocol’s creditworthiness and decides if a token can get whitelisted as a collateral for the Bonq liquidity platform.Mandatory Whitelisting Requirements:Trading and MarketCapThe token must be actively trading and have a live on-chain USD or EUR price feedMinimum of 6 months of trading historyListed on at...
With Bonq, businesses and individuals can access liquidity of their crypto assets without giving up ownership and completely interest-free!
BonqDAO report of the attack on the Bonq protocol on February 1, 2023
The description of the attackOn Feb 1st, 2023 at around 6:30 pm UTC, an unknown attacker was able to mint 100 million BEUR in tx 0x31957ecc43774d19f54d9968e95c69c882468b46860f921668f2c55fadd51b19 by manipulating the price of ALBT in Bonq troves. They were able to do so because of a bug in the TellorPriceFeed contract deployed by BonqDAO which reads the price of WALBT from the Tellor oracle. The bug in question was due to the fact that the PriceFeed uses the function getCurrentValue instead of...

Bonq 2.0 recovery/reboot proposal for BonqDAO
Last update: Feb 25, 2023Bonq 1.0On Dec 15, 2022, BonqDAO launched on Polygon as a zero-interest lending protocol with a native stable coin -BEUR. Over the next 6 weeks, things were looking good. BEUR was stable, the protocol generated cashbacks for BNQ (a native utility token on the Bonq protocol) stakers, and over 80% of BNQ in circulation were staked. On Jan 31, 2023, BonqDAO was listed in top 20 by TVL on Polygon on DeFi Llama. This proved that the initial mechanism design and the user in...

Whitelisting Criteria for New Tokens and the Risk Model Methodology
This document outlines the Bonq DAO Whitelisting methodology, its main categories, and factors that impact the process. Bonq DAO relies on these underlying factors to assess a web3 project /protocol’s creditworthiness and decides if a token can get whitelisted as a collateral for the Bonq liquidity platform.Mandatory Whitelisting Requirements:Trading and MarketCapThe token must be actively trading and have a live on-chain USD or EUR price feedMinimum of 6 months of trading historyListed on at...
With Bonq, businesses and individuals can access liquidity of their crypto assets without giving up ownership and completely interest-free!

Subscribe to Bonq DAO

Subscribe to Bonq DAO


Share Dialog
Share Dialog
<100 subscribers
<100 subscribers
Dear Bonq Community and Partners,
The Bonq protocol was exploited on February 1st, 2023 around 6:30 pm CET. An unknown attacker was able to mint 100Mio BEUR by manipulating the price feed of ALBT. They were able to do so because the implementation of the price feed contract which reads the price of ALBT from the Tellor Oracle contained a bug.
BonqDAO is responsible for the implementation of the price feed. AllianceBlock was not involved and/or responsible for implementing the price feed into the Bonq protocol.
The hacker used part of the 100Mio BEUR in 3 ways:
They staked a large portion in the StabilityPool before setting the price very low, causing all of the WALBT troves to be liquidated
They swapped BEUR for USDC, DAI, WALBT, WETH and WMATIC in the UniswapV3 liquidity pools to get all the liquidity that was provided
They triggered redemptions, allowing them to partially drain the collateral which was backing the BEUR debts in the troves
Currently, more than 98MIL BEUR are still on the attacker’s account on Polygon with no liquidity to exit.
We are assessing the damages and working through the next steps for BonqDAO. We will explore every option that is available before arriving at the conclusion of what’s the best path forward.
BonqDAO team
Dear Bonq Community and Partners,
The Bonq protocol was exploited on February 1st, 2023 around 6:30 pm CET. An unknown attacker was able to mint 100Mio BEUR by manipulating the price feed of ALBT. They were able to do so because the implementation of the price feed contract which reads the price of ALBT from the Tellor Oracle contained a bug.
BonqDAO is responsible for the implementation of the price feed. AllianceBlock was not involved and/or responsible for implementing the price feed into the Bonq protocol.
The hacker used part of the 100Mio BEUR in 3 ways:
They staked a large portion in the StabilityPool before setting the price very low, causing all of the WALBT troves to be liquidated
They swapped BEUR for USDC, DAI, WALBT, WETH and WMATIC in the UniswapV3 liquidity pools to get all the liquidity that was provided
They triggered redemptions, allowing them to partially drain the collateral which was backing the BEUR debts in the troves
Currently, more than 98MIL BEUR are still on the attacker’s account on Polygon with no liquidity to exit.
We are assessing the damages and working through the next steps for BonqDAO. We will explore every option that is available before arriving at the conclusion of what’s the best path forward.
BonqDAO team
No activity yet