We reported a critical loss of funds bug to @Thorchain (32M TVL, 150M FDV)
They silently patched it and told us their bug bounty program is permanently retired.
We have more Thorchain chain halt DoS vulns. We intend to release them (open disclosure) in the coming few days
We reported a critical loss of funds bug to @Thorchain (32M TVL, 150M FDV)
They silently patched it and told us their bug bounty program is permanently retired.
We have more Thorchain chain halt DoS vulns. We intend to release them (open disclosure) in the coming few days
🧵[1/6]
Last week I privately disclosed a valid vulnerability affecting Alephium’s Wormhole bridge integration.
The issue was confirmed by the team. It allowed a permissionless attacker to drain the entire balance of a live mainnet contract.