扫码下载
BTC $78,438.10 +3.58%
ETH $2,391.56 +3.18%
BNB $641.46 +1.82%
XRP $1.44 +0.87%
SOL $87.15 +1.86%
TRX $0.3293 -1.54%
DOGE $0.0963 +1.85%
ADA $0.2514 +1.38%
BCH $462.34 +3.98%
LINK $9.38 +0.04%
HYPE $40.93 +3.97%
AAVE $94.05 +2.89%
SUI $0.9537 +1.36%
XLM $0.1787 +0.69%
ZEC $317.41 +2.00%
BTC $78,438.10 +3.58%
ETH $2,391.56 +3.18%
BNB $641.46 +1.82%
XRP $1.44 +0.87%
SOL $87.15 +1.86%
TRX $0.3293 -1.54%
DOGE $0.0963 +1.85%
ADA $0.2514 +1.38%
BCH $462.34 +3.98%
LINK $9.38 +0.04%
HYPE $40.93 +3.97%
AAVE $94.05 +2.89%
SUI $0.9537 +1.36%
XLM $0.1787 +0.69%
ZEC $317.41 +2.00%

Sorbetto Fragola因LP代币转移缺乏适当费用核算遭到攻击,损失近2070万美元

2021-08-04 13:15:42
收藏

链捕手消息,8月4日,Peckshield发推表示,跨链收益率提升平台Popsicle Finance下Sorbetto Fragola产品遭到攻击,导致了约2070万美元的损失,包括2.6K WETH,5.4M USDC,5M USDT,160K DAI,10K UNI,和96 WBTC。据悉,此次攻击是由于LP代币转移时缺乏适当的费用核算导致的。

具体来说,攻击者创建了三个合约A、B和C,并以A.deposit()、A.transfer(B)、B.collectFees()、B.transfer(C)、C.collectFees()的顺序重复了八个池。在该漏洞中,黑客首先从Aave上闪贷了30M USDT, 13K WETH, 1.4KBTC, 30M USDC, 3M DAI和200K UNI,随后并攻击了八个PLP池。

目前,攻击的部分利润(4,100ETH,约1000万美元)被立即存入TornadoCash,而剩余的2560WETH,96WBTC和159,928DAI仍在攻击者的账户中,即0xf9E3D08196F76f5078882d98941b71C0884BEa52。(Twitter

关联标签
关联标签
app_icon
ChainCatcher 与创新者共建Web3世界