Learn more about the @MultichainOrg vulnerability @dedaub disclosed on my latest ep of The Dark Forest: $1B Multichain Vulnerability & PoC Explained https://t.co/zN6z1zsrlq
Congrats to the @dedaub team for responsibly disclosing a critical vulnerability in @harvest_finance that was quickly fixed.
@dedaub gets $200k for their find: $100k from Harvest, $100k from @ArmorFi via the Armor Alliance Bug Bounty Matching Program.
https://t.co/Dtnmahndhr
Quick look:
- Punk was put up to sale by contract A
- Contract B takes out a massive flashloan and buys punk from contract A
- When contract A receives ETH from B it immediately sent all of it back to B
- Contract B then used the ETH to repay their flashloan
DaoMaker was exploited for ~$4m. They left the `init` function unprotected. The attacker re-initialized the contract with malicious data and then called `emergencyExit` to get away with the funds.
The source code is not public and some messaging by DaoMaker is questionable 🧵👇
@DeFiDude Thanks for sharing Smart Contract Audits, Dude!👋
We try to stay in touch with everyone and keep everything as current as possible.
We should also note that an audit request submited via SCA usually receives 7-10 different audit offers from verified companies.✅
We are glad to welcome @PeppersecCOM to our network of verified auditors on https://t.co/DPD8mk6QPX! Their motto is "Sleep well with Audits by PepperSec". You can check out their profile page right here: https://t.co/qdrCIUCJuR