The biggest Web3 CTF is over:
🥇 @ChainLight_io
🥈 A-Team
🥉 @Web3Kimchi
The Remedy CTF 2025 was @hexens's first-ever competition.
Check out all the highlights 🧵
I hacked a MEV bot and you can do it too!
...and a new powerful EVM tool reveal, https://t.co/YKYUiePNHt, brought to you by https://t.co/xtFlWwixdx 🧵
1/9
As a security researcher, it is important to identify the vulnerability's severity,
Especially when you audit on Sherlock, which only accepts H/M.
Even though it's well-known, many Watsons submit low/info findings, so I recommend you go through each platform's rules👇
A 🧵 on how yesterday's @MIM_Spell attack worked. The protocol did everything right. They rounded in the protocol's favour whenever they should but one additional function, meant to only reduce the user's funds, ended up enabling the attack. How?
Radiant Capital @RDNTCapital was under a flash loan attack with a loss of $4.5M.
Attacker:
https://t.co/fc2NZfneXN
The attacker manipulated the index parameter (which later served as a denominator) to become extremely large. The contract has a rounding issue in its calculations, which led to a cumulative precision error.
Since the index parameter was dramatically inflated, this precision error was also magnified, ultimately allowing the attacker to profit through repeated deposit() and withdraw() operations.
Here's a thread of all our critical finding breakdowns thus far.
We make these breakdowns because we believe in elevating the standard for web3 security education
Roadmaps, find-the-bugs, or the 100th explanation of reentrancy won't get us where we need to be
Let's get it 🫡🧵
For those looking to learn Ethereum and the EVM in depth, I have compiled a glossary of symbols (mathematical ones or not) mentioned in the Yellow Paper with what they refer to 📒👇🏻
Hoping it makes your reading easier.
https://t.co/eG9cQxill1
#Ethereum#YellowPaper#EVM
🔥DeFiHackLabs monthly recap. We released 15 PoCs in June.
👍@kam8617 contributed to 7 of them.
Contributors: @gbaleeeee@eugenioclrc Cosinhs
👉https://t.co/CcKAqxGI6z
#web3sec
ICYMI, yesterday, the #Arbitrum- based @jimbosprotocol fell victim to a $7.5 mil Flash Loan attack.
The underlying token, Jimbo (JIMBO), faced a substantial decline in its price (~40%).
We've conducted a detailed analysis of the attack.
Read more: https://t.co/6XDz1xnZp0
DEI exploit explained
1) identify an address with a huge amount of DEI
2) approve to this address
3) call burnFrom with amount = 0 and this address
4) During the burnFrom it grants approves all tokens from the address to your own
5) call transferFrom
…..