shield Business Logic Flaw · $6.4K loss

NCD Hack: How $6.4K Was Lost in a Business Logic Flaw (2024)

On June 2024, NCD was exploited in a business logic flaw, resulting in approximately $6.4K in losses. That makes the NCD exploit the 404th largest DeFi incident out of 690 documented in our archive.

Attack Mechanics: How the NCD Business Logic Flaw Played Out

Exploit Class Applied to NCD

The NCD incident on June 4, 2024 is classified as a Business Logic Flaw. A business-logic bug in the contract — such as an incorrect formula or missing state update — lets the attacker withdraw more than their share. In the full archive, NCD is 1 of 144 documented business logic flaw incidents.

NCD in Context

At $6.4K, the NCD exploit is a minor (<$1M) event compared to the largest same-class incident in our archive — – EulerFinance (2023) at $200M.

Prior Business Logic Flaw Before NCD

The nearest business logic flaw incident before NCD was Liquiditytokens, 4 days earlier on May 31, 2024 ($200K lost). The same exploit class surfaced again within the business logic flaw attack surface.

Impact & Recovery for NCD

NCD Loss Figure

The NCD exploit caused $6,400 in losses — a minor (<$1M) incident and the 123rd largest of 188 documented in 2024.

Where NCD Sits Among Business Logic Flaw Attacks

Ranked by loss size, NCD is the 92nd largest of 144 business logic flaw incidents documented. That puts the NCD loss below the class average of $6.08M.

Timeline Since the NCD Incident

The NCD exploit occurred 1.9 years ago (679 days). The contract, its fork-block, and the attack transaction remain on-chain and forensically reproducible.

Primary Reference for NCD

Public post-mortem / on-chain analysis for the NCD incident: view source.

FAQ

How much did NCD lose?

The NCD exploit in June 2024 resulted in $6,400 in losses — the 123rd largest of 188 DeFi incidents that year.

When did the NCD hack happen?

The NCD exploit was recorded on June 4, 2024 — 679 days ago.

What type of exploit hit NCD?

The NCD incident is classified as a Business Logic Flaw. A business-logic bug in the contract — such as an incorrect formula or missing state update — lets the attacker withdraw more than their share.

How common is the Business Logic Flaw pattern seen at NCD?

Our archive contains 144 documented business logic flaw incidents. The NCD incident is one of them.

How does NCD compare to the largest Business Logic Flaw attack?

The largest business logic flaw incident in our archive is – EulerFinance (2023) at $200M. The NCD loss is $6.4K.

What is the significance of the 'Lachesis' consensus algorithm in Fantom's performance?

Lachesis enables faster consensus without the energy-intensive processes typical of PoW or round-based PoS schemes.

What challenge does the document highlight about cryptocurrency market efficiency?

The challenge is determining whether market efficiency varies with technology or capitalization, impacting predictability.