EthSecurity
5.22K subscribers
112 photos
20 files
762 links
Download Telegram
DefiPlaza hacked for 200 $K. original attack front-runned by MEV bot. Root cause was miscalculation in OutputAmount . @EthSecurity1
๐Ÿ”ฅ7
Forwarded from pcaversaccio
Please don't interact with the Compound Finance website for now. It seems to be hijacked.
๐Ÿ‘7
Minterest hacked $1.4M loss.

Attackers can lend tokens inside flashloan callbacks and then redeem more tokens after the flashloan.

https://mantlescan.xyz/tx/0xb3c4c313a8d3e2843c9e6e313b199d7339211cdc70c2eca9f4d88b1e155fd6bd

@EthSecurity1
โค4
Please revoke approval to 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae (LI.FI: LiFi Diamond) asap!
@EthSecurity1
โšก4
๐Ÿฆ„5โšก1๐Ÿ”ฅ1
A critical vulnerability was identified and reported by a whitehat. in the Raydium protocol .A bounty of $505,000 https://medium.com/immunefi/raydium-tick-manipulation-bugfix-review-c6aae4527ed6 @EthSecurity1
๐Ÿ”ฅ8๐ŸŽ‰2
a is a uint8, and 16777215 is a constant of type uint24 as uint24 is the smallest type that can fit this value. When these are added together, the Solidity compiler implicitly casts a to uint24 thus performing uint24 + uint24. The cast is happening regardless of the declared type of output as that cast will occur *after* the addition operation. @EthSecurity1 #overflow
๐Ÿ‘5โค3
after exploit protocol in scroll, they halted chain. Do not hold your assets on L2, they can steal your funds. @EthSecurity1
๐Ÿซก6๐Ÿค”5
Singapore court ruling fans suspicions the $125m Multichain hack was an inside job @EthSecurity1
โšก2๐Ÿ˜2๐Ÿ”ฅ1
Spectra was hacked, $550K loss

The root cause is an arbitrary call in their router contract. @EthSecurity1
๐Ÿ˜ข6๐Ÿ˜2๐Ÿ‘1๐Ÿ’ฏ1
Lowest-paying findings on Code4rena, Sherlock https://0xvolodya.hashnode.dev/lowest-paying-findings-on-code4rena-sherlock Mempool Masterclass - Mempool Monitoring https://www.youtube.com/watch?v=TQqCCuh7x_E @EthSecurity1
๐Ÿ‘3๐Ÿคฏ1