Levana, a swap protocol in the Osmosis blockchain ecosystem, suffered a hack resulting in a loss of over $1.1 million. According to a report released by the team, the attack occurred over a period of 13 days. The attackers drained 10% of the liquidity pools between December 13 and December 26.
Details of the Attack on Levana
The hackers took advantage of a congestion attack in the Osmosis ecosystem, which prevented Levana users from interacting with the markets. This situation was due to a bug in Osmosis’s price market code, combined with a price stagnation code in Levana protocol’s integration with the Pyth oracle, allowing attackers to manipulate prices and drain the pools. The Levana team commented on the issue:
“A bug in the Osmosis fee market code meant that the transaction fees provided during peak times were often insufficient for making transactions or for ongoing bot maintenance activities.”
The team clarified that there was no security vulnerability with the Pyth oracle and that it behaved exactly as expected. Levana is working on a fix that will be used to upgrade the price code in the ecosystems where the protocol is offered. The ecosystems in question are Osmosis, Sei, and Injective networks.
Levana Team Announces Airdrop
Levana added to their statements that despite the attack, existing positions and profits within the protocol were not affected. However, new positions and changes to existing positions have been temporarily suspended until an update planned for the following week. Levana aims to compensate affected liquidity providers with an airdrop event and by refunding the protocol fees collected during the attack.
Although Blockchain technology offers significant advantages to users, security vulnerabilities in this area are causing many investors to suffer serious losses. The hack attacks that occur also make it mandatory for governments to regulate the blockchain field, while causing fear and concern among users. The blockchain field, which attracted great interest in 2021, especially due to security concerns, is not yet seeing the same interest.