Since @TradeOnOrion has upgraded their vulnerable contract, we can provide a detailed explanation of this exploit now. The root cause is the liabilities for a user in not correctly updated when remove liability for this user. https://t.co/qYMtjd89rx
The attacked conducted a Precision Loss Attack on @xBank_Finance
You can find the post-mortem analysis of the exploit in the article below:
https://t.co/r36UGjkNcx
Thank you for your patience & understanding.
@MIM_Spell Although the round up handling in the _repay() function follows the ERC4626 standard, the exploiter actually took advantage of this to profit due to the existence of the replayForAll() function.
The unverified contract 0x82c063afefb226859abd427ae40167cb77174b68 has a vulnerability that anyone can call the redeem() function to burn the $BUI tokens held by this contract and get the corresponding underlying assets.
https://t.co/CvdAmss9kS
Alert! @_LiquidCrypto was hacked on multiply chains.
Revoke your approvals as early as possible. And we will share the root cause when users funds are safe.
https://t.co/E9cLPb6lZB
@RDNTCapital was hacked by the notorious rounding issue on the empty rUSDCn market. It's always suggested to do a guard launch for the new market.
https://t.co/iPgetkLdyu
@RDNTCapital was hacked by the notorious rounding issue on the empty rUSDCn market. It's always suggested to do a guard launch for the new market.
https://t.co/iPgetkLdyu
🚨🚨🚨Compromised Key? Malicious upgrade on BUSDPosiVaultV2 of @PositionEx allows the hacker to steal user assets assigning approval to BUSDPosiVaultV2, leading to the gain of ~$280K for the hacker.
Please revoke you r approvals to 0xf35848441017917a034589bfbec4b3783bb39cb2.