The @NotionalFinance attack repported by @SpecterAnalyst appears to be caused by an integer overflow.
The ERC1155 implementation allows minting a pair of positions (one long one short) when calling "safeTransferFrom" where from does not have enough position to be transferred.
The attacker minted 1 unit of position first: 1 long goes to a helper contract A and 1 short goes to the main contract.
Then mint another 2^128-1 uint of position: 2^128-1 short to main contract and 2^128-1 long to helper contract B.
These sum up to cause overflow in the main contract, allowing the attacker to end massive long position with no debt in helper contract B. It is then used as collateral to drain the tokens.
The attacker pocketed ~$1.7M in DAI and USDC and deposited to tornado cash.
Thank you, Mr. Musk, @elonmusk for gifting me 4,000 followers. Your reply to my tweet yesterday fell on my birthday. I’m extremely thankful to you. May everything go smoothly and may you be happy every day.
中文版:马斯克先生,我想给你生孩子~