critical-severity

2 articles
Sort: New Top Best
clear filter
0 8/10
vulnerability

A critical smart contract vulnerability in VeChainThor's VTHO (gas token) accrual mechanism allows attackers to artificially mint unbounded VTHO by exploiting incomplete energy settlement in the self-destruct logic when combined with flash loans. The flaw occurs because the OnSuicideContract function fails to update accrued VTHO when the transfer amount is zero, enabling repeated exploitation.

VeChainThor VeChain VTHO (VeThor Token) VET (VeChain Token) Immunefi @nnez OnSuicideContract CalcEnergy
immunefi.com · nnez · 4 hours ago · details
0
bug-bounty

A critical vulnerability was discovered in Oasis Earn service that allows attackers to selfdestruct the OperationExecutor contract through a delegatecall code-reuse attack, exploiting the assumption that executeOp() runs only in user's DSProxy context. The researcher earned a $20K bounty by chaining arbitrary calldata execution with hardcoded service registry mappings to achieve contract destruction.

Oasis MakerDAO Immunefi Lido Uniswap Etherscan
trust-security.xyz · Trust · 4 hours ago · details