{"id":1312,"date":"2020-12-08T12:39:28","date_gmt":"2020-12-08T12:39:28","guid":{"rendered":"https:\/\/de.fi\/blog\/?p=1312"},"modified":"2023-09-17T10:31:55","modified_gmt":"2023-09-17T10:31:55","slug":"the-bundles-finance-saga-defiyield-info-9a25a8b99140","status":"publish","type":"post","link":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140","title":{"rendered":"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts"},"content":{"rendered":"<p>Importance of the DeFi community being proactive and attentive to yield farming terms proposed by decentralized platforms has been once again confirmed by a recent case on a code insecurity of Bundles Finance.<\/p>\n<blockquote><p>Check out our book about DeFi on <a href=\"https:\/\/www.amazon.com\/dp\/B094X2BJH9\">Amazon!<\/a><\/p><\/blockquote>\n<p><strong>Act #1<\/strong><\/p>\n<p>The story started with a warning published by the De.Fi.info team indicating a high risk of the project\u2019s smart contract code: availability of a drain function was revealed, which could be executed by a EOA owner. This allowed him to drain liquidity pools at any time.<\/p>\n<p><img decoding=\"async\" class=\"legacymediumimages\" src=\"https:\/\/de.fi\/blog\/wp-content\/uploads\/2023\/06\/1qhqZCI3OpoScKA2cO-jmRg.png\" alt=\"[https:\/\/t.me\/de.fi\/18837](https:\/\/t.me\/defiyield_app\/18837)\" \/><\/p>\n<p><strong>Act#2<\/strong><\/p>\n<p>The public facing team of Bundles Finance noticed the warning. They not only reacted to the issue, but also admitted that the code must be corrected. The project\u2019s founder published a video with a detailed explanation on the situation (<a href=\"https:\/\/www.youtube.com\/watch?v=3spqS7TGtK0&amp;feature=youtu.be&amp;t=147\">https:\/\/www.youtube.com\/watch?v=3spqS7TGtK0&amp;feature=youtu.be&amp;t=147<\/a> ). As he informed, the smart contracts were audited by SolidityFinance prior to the platform deployment. But after that, a member of the project\u2019s external development team decided to add the drain function with the purpose of the code security enhancement. The idea was that in case something happens to the smart contract functionality, the funds would not be locked in it and their withdrawal could be managed.<\/p>\n<p>Immediately after De.Fi had published the warning, Bundles Finance replied trying to explain availability of the drain function:<\/p>\n<p><img decoding=\"async\" class=\"legacymediumimages\" src=\"https:\/\/de.fi\/blog\/wp-content\/uploads\/2023\/06\/1zRMgyQNF21J-uHTa246mMQ.png\" alt=\"[https:\/\/t.me\/de.fi\/18865](https:\/\/t.me\/defiyield_app\/18865)\" \/><\/p>\n<p>As the Bundles Finance founder points out in the video, it was a communicational mistake inside the project that the developer, which added the drain function, didn\u2019t draw proper attention of the project managers to the smart contract modification made. The public was first to react.<\/p>\n<p><img decoding=\"async\" class=\"legacymediumimages\" src=\"https:\/\/de.fi\/blog\/wp-content\/uploads\/2023\/06\/0lHxzWsbkgkKrIOT8.png\" alt=\"[https:\/\/twitter.com\/BundlesFinance\/status\/1334949318357217280](https:\/\/twitter.com\/BundlesFinance\/status\/1334949318357217280) [https:\/\/archive.is\/zK1IR](https:\/\/archive.is\/zK1IR)\" \/><\/p>\n<p>Currently, the problem is being solved. Solidity was contacted with a request of the new contracts deployment for Bundles Finance. As a result, funds staked with the insecure smart contract version get withdrawn to the liquidity providers. Staking is paused until the new smart contract code is deployed and can be externally audited.<\/p>\n<p><img decoding=\"async\" class=\"legacymediumimages\" src=\"https:\/\/de.fi\/blog\/wp-content\/uploads\/2023\/06\/12OXehmCNyD0tyTPz_gz6eQ.png\" alt=\"[https:\/\/t.me\/de.fi\/19553](https:\/\/t.me\/defiyield_app\/19553)\" \/><\/p>\n<p><strong>Conclusion<\/strong><\/p>\n<p>My efforts to make the DeFi industry cleaner and more transparent have given great results again. Thousands of dollars could have stayed under the high risk, if De.Fi had not found the smart contract code insecurity element.<\/p>\n<p>How fast yield farming projects react to warnings and code security requests is always instructive for investors in terms whether these platforms can be trusted or not. Bundles Finance is a positive example of the transparent and responsible communication attitude, the community respect and the fast problem solving. In contrast, when executives of DeFi projects systematically postpone answering community questions or give ambiguous and shady replies, it\u2019s a clear warning sign for the investors that they should consider withdrawing their funds from these risky platforms while it\u2019s still possible.<\/p>\n<p>As soon as Bundles Finances deploys the corrected smart contract as promised, I\u2019ll update the community in my posts. Stay tuned.<\/p>\n<p>Check out other articles from the Saga series:<\/p>\n<ul>\n<li><a href=\"https:\/\/de.fi\/blog\/how-deus-finance-fixed-its-code-following-a-defiyield-info-report-51775ef59a5b\">The Deus Finance Saga<\/a><\/li>\n<li><a href=\"https:\/\/de.fi\/blog\/report-the-alpha-lab-infinite-minting-saga-team-controls-96-of-the-tokens-8a7d107c740\">The Alpha Lab Infinite Minting Saga<\/a><\/li>\n<li><a href=\"https:\/\/de.fi\/blog\/the-yffs-saga-how-a-yield-farming-project-was-compelled-to-fix-its-code-6c5ee77816bb\">The YFFS Saga<\/a><\/li>\n<\/ul>\n<h2 id=\"check-our-guides-\">Check our guides:<\/h2>\n<p><a href=\"https:\/\/de.fi\/blog\/the-ultimate-yield-farming-guide-for-solana-network-infographics-985936db4392\">Solana Network Ultimate Yield Farming Guide [Infographics]<\/a><br \/>\n<a href=\"https:\/\/de.fi\/blog\/ultimate-yield-farming-guide-for-fantom-network-5c5dea0c719a\">Fantom Network Ultimate Yield Farming Guide [Infographics]<\/a><br \/>\n<a href=\"https:\/\/de.fi\/blog\/the-ultimate-guide-for-yield-farming-with-huobi-eco-chain-cde009ed3457\">Huobi ECO Chain Ultimate Guide for Yield Farming<\/a><br \/>\n<a href=\"https:\/\/de.fi\/blog\/the-ultimate-guide-for-yield-farming-with-polygon-network-373b77ccb1cf\">Polygon Network Ultimate Guide for Yield Farming<\/a><br \/>\n<a href=\"https:\/\/de.fi\/blog\/the-ultimate-guide-for-yield-farming-with-binance-chain-dbc23beb6df4\">Binance Chain Ultimate Guide for Yield Farming<\/a><\/p>\n<p>And join us on <a href=\"https:\/\/twitter.com\/DeDotFI\">twitter <\/a>and <a href=\"https:\/\/t.me\/DeDotFi\">telegram!<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Importance of the DeFi community being proactive and attentive to yield farming terms proposed by decentralized platforms has been once again confirmed by a recent case on a code insecurity of Bundles Finance.<\/p>\n","protected":false},"author":2,"featured_media":5545,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[55],"class_list":["post-1312","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defi","tag-defi_vs_scams"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.10 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts\" \/>\n<meta property=\"og:description\" content=\"Importance of the DeFi community being proactive and attentive to yield farming terms proposed by decentralized platforms has been once again confirmed by a recent case on a code insecurity of Bundles Finance.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140\" \/>\n<meta property=\"og:site_name\" content=\"De.Fi Blog\" \/>\n<meta property=\"article:published_time\" content=\"2020-12-08T12:39:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-09-17T10:31:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/de.fi\/blog\/wp-content\/uploads\/2020\/12\/Group-2-1-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2264\" \/>\n\t<meta property=\"og:image:height\" content=\"1184\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"De.Fi Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@dedotfi\" \/>\n<meta name=\"twitter:site\" content=\"@dedotfi\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"De.Fi Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140#article\",\"isPartOf\":{\"@id\":\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140\"},\"author\":{\"name\":\"De.Fi Security\",\"@id\":\"https:\/\/de.fi\/blog\/#\/schema\/person\/bc7c94cb5e037c8978c6059885825591\"},\"headline\":\"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts\",\"datePublished\":\"2020-12-08T12:39:28+00:00\",\"dateModified\":\"2023-09-17T10:31:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140\"},\"wordCount\":569,\"publisher\":{\"@id\":\"https:\/\/de.fi\/blog\/#organization\"},\"keywords\":[\"De.Fi vs Scams\"],\"articleSection\":[\"De.Fi\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140\",\"url\":\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140\",\"name\":\"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts\",\"isPartOf\":{\"@id\":\"https:\/\/de.fi\/blog\/#website\"},\"datePublished\":\"2020-12-08T12:39:28+00:00\",\"dateModified\":\"2023-09-17T10:31:55+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/de.fi\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/de.fi\/blog\/#website\",\"url\":\"https:\/\/de.fi\/blog\/\",\"name\":\"De.Fi Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/de.fi\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/de.fi\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/de.fi\/blog\/#organization\",\"name\":\"De.Fi\",\"url\":\"https:\/\/de.fi\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/de.fi\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/de.fi\/blog\/wp-content\/uploads\/2023\/06\/spaces_XOyvZ43P03BZ8mN6KNWT_icon_1hV2Waqet2YS2jtkV0f3_Logo.webp\",\"contentUrl\":\"https:\/\/de.fi\/blog\/wp-content\/uploads\/2023\/06\/spaces_XOyvZ43P03BZ8mN6KNWT_icon_1hV2Waqet2YS2jtkV0f3_Logo.webp\",\"width\":223,\"height\":234,\"caption\":\"De.Fi\"},\"image\":{\"@id\":\"https:\/\/de.fi\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/twitter.com\/dedotfi\",\"https:\/\/t.me\/dedotfi\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/de.fi\/blog\/#\/schema\/person\/bc7c94cb5e037c8978c6059885825591\",\"name\":\"De.Fi Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/de.fi\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6f2f941b8d00bf81e01f135977bd5284977931ec40bfd2c06000150d2a6d661d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6f2f941b8d00bf81e01f135977bd5284977931ec40bfd2c06000150d2a6d661d?s=96&d=mm&r=g\",\"caption\":\"De.Fi Security\"},\"url\":\"https:\/\/de.fi\/blog\/author\/defisecurity\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140","og_locale":"en_US","og_type":"article","og_title":"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts","og_description":"Importance of the DeFi community being proactive and attentive to yield farming terms proposed by decentralized platforms has been once again confirmed by a recent case on a code insecurity of Bundles Finance.","og_url":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140","og_site_name":"De.Fi Blog","article_published_time":"2020-12-08T12:39:28+00:00","article_modified_time":"2023-09-17T10:31:55+00:00","og_image":[{"width":2264,"height":1184,"url":"https:\/\/de.fi\/blog\/wp-content\/uploads\/2020\/12\/Group-2-1-1.png","type":"image\/png"}],"author":"De.Fi Security","twitter_card":"summary_large_image","twitter_creator":"@dedotfi","twitter_site":"@dedotfi","twitter_misc":{"Written by":"De.Fi Security","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140#article","isPartOf":{"@id":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140"},"author":{"name":"De.Fi Security","@id":"https:\/\/de.fi\/blog\/#\/schema\/person\/bc7c94cb5e037c8978c6059885825591"},"headline":"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts","datePublished":"2020-12-08T12:39:28+00:00","dateModified":"2023-09-17T10:31:55+00:00","mainEntityOfPage":{"@id":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140"},"wordCount":569,"publisher":{"@id":"https:\/\/de.fi\/blog\/#organization"},"keywords":["De.Fi vs Scams"],"articleSection":["De.Fi"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140","url":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140","name":"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts","isPartOf":{"@id":"https:\/\/de.fi\/blog\/#website"},"datePublished":"2020-12-08T12:39:28+00:00","dateModified":"2023-09-17T10:31:55+00:00","breadcrumb":{"@id":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/de.fi\/blog\/the-bundles-finance-saga-defiyield-info-9a25a8b99140#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/de.fi\/blog\/"},{"@type":"ListItem","position":2,"name":"The Bundles Finance Saga: De.Fi stimulates the DeFi platform to increase security of its smart contracts"}]},{"@type":"WebSite","@id":"https:\/\/de.fi\/blog\/#website","url":"https:\/\/de.fi\/blog\/","name":"De.Fi Blog","description":"","publisher":{"@id":"https:\/\/de.fi\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/de.fi\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/de.fi\/blog\/#organization","name":"De.Fi","url":"https:\/\/de.fi\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/de.fi\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/de.fi\/blog\/wp-content\/uploads\/2023\/06\/spaces_XOyvZ43P03BZ8mN6KNWT_icon_1hV2Waqet2YS2jtkV0f3_Logo.webp","contentUrl":"https:\/\/de.fi\/blog\/wp-content\/uploads\/2023\/06\/spaces_XOyvZ43P03BZ8mN6KNWT_icon_1hV2Waqet2YS2jtkV0f3_Logo.webp","width":223,"height":234,"caption":"De.Fi"},"image":{"@id":"https:\/\/de.fi\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/twitter.com\/dedotfi","https:\/\/t.me\/dedotfi"]},{"@type":"Person","@id":"https:\/\/de.fi\/blog\/#\/schema\/person\/bc7c94cb5e037c8978c6059885825591","name":"De.Fi Security","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/de.fi\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6f2f941b8d00bf81e01f135977bd5284977931ec40bfd2c06000150d2a6d661d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6f2f941b8d00bf81e01f135977bd5284977931ec40bfd2c06000150d2a6d661d?s=96&d=mm&r=g","caption":"De.Fi Security"},"url":"https:\/\/de.fi\/blog\/author\/defisecurity"}]}},"_links":{"self":[{"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/posts\/1312","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/comments?post=1312"}],"version-history":[{"count":6,"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/posts\/1312\/revisions"}],"predecessor-version":[{"id":5137,"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/posts\/1312\/revisions\/5137"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/media\/5545"}],"wp:attachment":[{"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/media?parent=1312"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/categories?post=1312"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/de.fi\/blog\/wp-json\/wp\/v2\/tags?post=1312"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}