We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
We found a bug that lets any user grant themselves admin access to live financial assets on Provenance, a Cosmos SDK chain.
82 token accounts were exploitable, representing ~$500K in drainable HASH. Now patched.