How to get URL link on X (Twitter) App
The attackers upgraded the multisig to a malicious version that allowed them to drain the multisig.
Oh but it is secured by ID verification!
First, let's understand how a normal sandwich attack works.
The exploit could've been theoretically used to drain all assets on BSC totaling over ten billion dollars but the hacker only took 2,000,000 BNB ($570m) for practical reasons.
Details aren't public yet but here's my guess of what happened -
Hundred Finance is a fork of Compound and apparently compound does not follow the recommended checks-effects-interactions pattern even though it refers to it.
Wormhole allows users to bridge assets across blockchains. A user can deposit an asset on one chain (source) and claim it on another (target).
When a swap happens, the price of the token sent by the user drops, and the price of the token received by the user increases. This is known as price impact.
Unlike what Visor claims, It was absolutely a bug in the smart contract. https://twitter.com/VisorFinance/status/1464574917056385025
https://twitter.com/euler_mab/status/1459314402059034634The safe price is assumed to be 1.35. However, in a protocol like AAVE with 85% liquidation threshold, the safe price is 1/0.85 = 1.17
6. Account A now has $500m crYUSD
About 240k COMP tokens (~$70m) have been given away already and another 40k (~$13m) will likely be given away soon. If you had supplied tokens before today, go try your luck.
DaoMaker claimed that they had audits from 3 firms but looking at learn.daomaker.com/audits, 2 of the audits seem to be for unrelated contracts while the third one from @certik_io points to a dead link.https://twitter.com/TheDaoMaker/status/1433994186446020609