@dev_chinmayf It is a technique to interact with the liquidity pair contract directly to swap instead of using the router. in this way, you can get the output token first and then transfer the input token. It is just like flash loan, thays why we call it flashswap
Keen to dig into asset management accounting, or maybe issuance and redemption logic? 🔎
Get amongst all of the above (and more!) in @EthosReserve's audit, with $144,750 USDC in the reward pool for Wardens who can find vulns.
Start hunting now: https://t.co/vHvf056IVi
@immunefi 1. there must a checker to check if it is a zero-address after create2.
2. If I find a hash collision, I can deploy again by passing 2 different testPool addresses with same hash value to re deploy the contract deployed by create2. This will influence the exsisting contracts.
@immunefi Hey, create2 is not safe in use because the deployer can call SELFDESTRUCT and deploy again the pool to replace the former pool with another but malicious contract to steal fund.
@SolidlyDEX @MonolithETH_ I used to discuss with @VelodromeFi about making a solidsex like project for them. But looking this, the veNFT shouldn't be released with any liquid token. However, still believe in solidly and you can solve it and become more solid!
@dedaub I thought these should be eliminated by processes like dead code elimination... No wonder deplying some contracts with inheriting many standard contracts costs toooo much gas.
wstETH/ETH Curve gauge vaults on Arbitrum & Optimism were exploited a few hours ago, and we immediately paused the dForce Vaults - other parts of the protocol remain intact and user funds are SAFE with dForce Lending.
We will come back with a detailed report and remedies soon.
@bytes032 language of course solidity. I do love using ganache + remix if I am developing some small projects. Its sooo convenient and just write test contracts in solidity. for complex ones, I prefer hardhat. and for self audting, just use slither.