๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
๊ฐ€์ž… April 2018
406 ํŒ”๋กœ์ž‰ ์ค‘    88.6K ํŒฌ
๐ŸšจSlowMist TI Alert๐Ÿšจ ๐Ÿ’ธ Loss: 62.5 BNB & 1,195,918.92 JOE ๐Ÿ” Root Cause: Single-function reentrancy in `_removeLiquidityViaContract` โ€“ BNB sent via low-level `call` before updating `lpInfo[user].lpAmount`, allowing recursive calls. ๐Ÿ“Œ Attacker EOA: 0xaa761779945dcc5f26064fc6dcb36ffab6ac7610 ๐Ÿ“Œ Attacker Contract: 0x31f81fcd91025728f24bd6f0e4efb156e345a4cf ๐Ÿ“Œ Vulnerable Proxy: 0xef0f12d08d66e76e1866e60f30a0daa578e00c04 ๐Ÿ“Œ Vulnerable Implementation: 0xb12ce0a21f67a9fc3c8ad1c7dbc4b017b7e67319 Attackers exploited the delayed state write to repeatedly withdraw liquidity, netting 62.5 BNB and ~1.196M JOE via 25 reentrancy loops. Powered by #SlowMist#.AI
๋” ๋ณด๊ธฐ