Logic of the attack:
1) Attacked used own address as a subject during the BuyShares() call.
2) During the fallback changed the weights in 0x5632b2e4 function
3) Sold the shares and received manipulated AVAX amount.
@starsarenacom was exploited for 2.8$M today. The exploit was possible due to public 0x5632b2e4 function which allows to set weights that are used during the price calculation.
The project wasn't audited before launch ⚠️
#web3#audit#security#hack
We are delighted to announce the launch of our brand-new website. It's been a labor of love, and we're excited to bring you an enhanced online experience that reflects our dedication to excellence in web3 security Visit our new website at https://t.co/7LAc4w44OF #web3#audit
Both pre and post-deployment audits are crucial. Post-deployment contracts, if not handled carefully, can lead to severe vulnerabilities due to misconfigurations. At DamageLab, we're here to consult on your project throughout its entire lifecycle. Stay vigilant!
#Web3#audit
We've discovered a bug in the @Bankroll_Status staking contract that enables anyone to transfer users' funds on their behalf. We recommend that $VLT token holders revoke their approvals.
contract: 0x84A4eCCB81A1Fd0867C7682E2c85FFeF4538A2F4
#web3#security#vulnerability
🕵️♂️ Don't get us wrong, tools like Slither and Mythril are valuable! But here at DamageLab we dedicate 90% of our time to MANUAL REVIEW. Why? Because every line of code needs a human touch, an experienced eye, and a thorough understanding.
#web3#security
DamageLab - Your Web3 Security Vanguard!
We're not just another security firm; we're rewriting the rules of defense in the world of Web3 contracts.
🔓 Embrace a NEW perspective on security! Focused on OFFENSIVE approaches to safeguard your assets!
#DamageLab