@blockaid_@StakeDAOHQ The attacker then sent a forged LayerZero message (via the malicious peer) that the Arbitrum OFT accepted as valid, triggering an unauthorized mint of 5.446 trillion vsdCRV from the zero address (bypassing normal supply caps and mint controls through the cross-chain path.
@blockaid_@StakeDAOHQ This was an OApp peer manipulation attack using a malicious contract as the trusted peer on one side of the LayerZero pathway to call setPeer on the vsdCRV OFT contract on Arbitrum, pointing the trusted peer to the malicious Ethereum contract instead of the legitimate one.
@elonmusk@grok@xai Only if we can feed our mcp server from here, then it should be better than @cursor_ai , I use @xai only for high level understanding.