Thread Reader
Share this page!
×
Post
Share
Email
Enter URL or ID to Unroll
×
Unroll Thread
You can paste full URL like: https://x.com/threadreaderapp/status/1644127596119195649
or just the ID like: 1644127596119195649
How to get URL link on X (Twitter) App
On the Twitter thread, click on
or
icon on the bottom
Click again on
or
Share Via icon
Click on
Copy Link to Tweet
Paste it above and click "Unroll Thread"!
More info at
Twitter Help
kemmio
@k3mmio
Сo-Founder & CTO @hexensio @xyz_remedy | CTF @ MSLC | blockchain/web/pwn
Subscribe
Save as PDF
Dec 18, 2021
•
4 tweets
•
2 min read
Grim Finance(
grim.finance
) got hacked 2 hours ago
Estimated loss: $40mln
One of the attacking transactions:
ftmscan.com/tx/0x19315e5b1…
Attack Analysis:
#FTM
#ETH
#BSC
#GrimFinance
#GrimExploit
1/4
1)
Grab a Flashloan for XXX & YYY tokens (WBTC-FTM e.g.)
2)
Add liquidity on SpiritSwap
3)
Mint SPIRIT-LPs
4)
call depositFor() in GrimBoostVault with token==ATTACKER, user==ATTACKER
5)Leverage token.safeTransferFrom for re-entrancy
6)
goto
(4)
2/4