On August 14th, a hacker used a loophole in the iBTC/aUSD circulation pool to forge 1.2 billion aUSD without collateral. The incident knocked the dollar-pegged stable currency down to a penny, and in response, the Acala team froze the faulty forged tokens by putting the network into maintenance mode.
The move also suspends other features like swaps, xcm (cross-chain communication on Polkadot) and oracles` pallet prices until [further notice"
We have identified this issue as a misprovisioning of the iBTC/aUSD pool (which went live earlier today) resulting in a large pool of aUSD
1/ Wrong minting.
While putting the network into maintenance mode and freezing funds in hackers` wallets may be an attempt to protect users and the network from further damage, advocates of decentralization have expressed displeasure.
Acala is a cross-chain decentralized finance (DeFi) center based on the aUSD stablecoin issued on the Polkadot (DOT) blockchain. aUSD is a stable digital currency that Acala claims is censorship resistant. iBTC This is a packaged BTC (BTC) suitable for DeFi protocols.
Because the protocol froze funds so quickly, community members noticed Acala`s irony about aUSD. Twitter client Gr33nHatt3R.dot noted on Aug. 14 that the decision "decentralized finance must be governed."
[Is this really DeFi if Acala centrally controls decisions?"
A member of the project`s Discord channel, usafmike, suggested rolling back the chain to completely reverse the coin mint, but suffered losses. Another member of skylordafk.dot said such an action would be a challenge to [set a harmful example."
As of this writing, the network is still in maintenance mode to prevent full token transfers, but the team has determined that the bug has been patched. The wrong forged aUSD wallets have been identified, 99% of them are still used on Acala, and if the community votes to do so, they may be withdrawn by the community.
Related: Binance Recovers Most of Stolen Funds from CurveFinance
The Acala breach was the second largest in a week, as CurveFinance (CRV) was hacked on its front end on Aug. 9, instructing customers to allow malicious contracts. Acala's problem is the same as Curve's as users interacting directly with the smart contract did not experience any issues, and the latter's pool was not corrupted.
aUSD This is the latest stablecoin to lose its peg over the past few months, starting in May with TerraUSD (UST) which started to gain notoriety before being renamed TerraClassicUSD (USTC). Other notable depegs include Tether (USDT) and Dei (DEI).
