web3_4d's profile picture. Blockchain security researcher in Positive Technologies

Andrey

@web3_4d

Blockchain security researcher in Positive Technologies

Andrey reposted

💰 New article by our researcher Andrey Bachurin: "Binance Smart Chain Token Bridge Hack" The article explains the technical details of one of the largest cryptocurrency hacks ever. Read the blog post: swarm.ptsecurity.com/binance-smart-…


A clear example of how errors in the logic of the contract allow to steal funds. It looks like a loophole in a legal contract, only the scale is larger.

2/ The protocol has a flawed migrate() that is exploited to transfer real UniswapV2 liquidity to an attacker-controlled new V3 pair with skewed price, resulting in huge leftover as the refund for profit. Also, the authorized sender check is bypassed by locking any tokens.

peckshield's tweet image. 2/ The protocol has a flawed migrate() that is exploited to transfer real UniswapV2 liquidity to an attacker-controlled new V3 pair with skewed price, resulting in huge leftover as the refund for profit. Also, the authorized sender check is bypassed by locking any tokens.


Loading...

Something went wrong.


Something went wrong.