How to get URL link on X (Twitter) App
2/ 🛠️ What is a Proof-of-Concept (PoC)?
Onchain security today is fragmented — and dangerously reliant on manual workflows.
@Wise_Token As a decentralized lending protocol and yield aggregator, loans on Wise Lending must first be collateralized by depositing some assets before being allowed to borrow funds. Users are liquidated if repayment does not occur, or collateral value drops below a certain health factor.
@bZxHQ 2/ Fulcrum was launched in June 2019, and its official website is also inaccessible. The project has not been updated since 2020.
2/ The attack on Kyberswap was caused by a precise manipulation of liquidity math in their implementation. This manipulation tricked the pool into falsely believing that it had more liquidity than it possessed.
If you had passed him on the street one day, you’d never realize that you were in the presence of a pro who quit his job to hunt bugs full-time.
The attacker called the function `0x4f1f05bc` on the unverified contract, which lacked access control.
Within 2 hours after the upgrade made to the token contract, the attacker was able to create a malicious contract and interact with the Thoreum contract, ultimately stealing a significant amount of THOREUM ~1047176.6 tokens.
https://twitter.com/davidyat_es/status/1615358602553790467
https://twitter.com/immunefi/status/1615353187262779396A fixed 300 million BLA tokens are assigned to the company (blaFundDeposit address) when the crowdsale contract is deployed.
https://twitter.com/immunefi/status/1480527067951292419With signatures in Ethereum, there may be an issue if a valid signature might be used several times in other places where it’s not intended to be used.
https://twitter.com/immunefi/status/1479041210014736385A digital signature can be created to sign any message.