arbitrum

2 articles
sort: new top best
clear filter
0 8/10
vulnerability

A critical vulnerability in Arbitrum's DelayedInbox bridge contract allowed attackers to reinitialize the contract and set a malicious bridge address due to an uninitialized storage slot combined with a gas optimization that removed a redundancy check, enabling theft of all deposited ETH.

Arbitrum Nitro DelayedInbox.sol TransparentUpgradeableProxy Optimism 0xriptide ImmuneFi
medium.com · riptide · 17 hours ago · details
0 7/10
bug-bounty

A critical logic error in Yield Protocol's strategy contract allowed attackers to drain pool tokens by inflating the balance calculation through direct token transfers; the vulnerability was responsibly disclosed by whitehat Paludo0x, who received a $95,000 USDC bounty after the $950k at-risk vulnerability was patched by modifying the burn function to use cached pool values instead of live balance checks.

Yield Protocol Immunefi Paludo0x YieldSpace Pool fyToken Foundry
medium.com · Paludo0x · 17 hours ago · details