fund-theft

4 articles
Sort: New Top Best
clear filter
0
vulnerability

A high-severity vulnerability was discovered in Across V3 cross-chain bridge that allows malicious relayers to steal the full value of certain transactions from users by exploiting the optimistic relay mechanism before UMA's Optimistic Oracle validation.

Across V3 UMA zachobront deadrose
mirror.xyz · Zach Obront · 4 hours ago · details
0
vulnerability

A High Severity vulnerability was discovered in Across V3, a cross-chain optimistic bridge, that could allow malicious relayers to steal the full value of certain transactions from users by exploiting the relayer fulfillment mechanism prior to UMA Optimistic Oracle validation.

Across V3 zachobront deadrose UMA Optimistic Oracle
mirror.xyz · Zach Obront · 4 hours ago · details
0 8/10
bug-bounty

Researcher disclosed two critical bugs in Sei Network's Cosmos blockchain: (1) an ABCI EndBlocker panic triggered via vesting accounts that would halt the chain, and (2) a balance transfer vulnerability in EVM integration allowing arbitrary fund transfers. Both were caught pre-mainnet and awarded $75k and $2M respectively.

Sei Network Sei Foundation Cosmos SDK Geth Trail of Bits Immunefi CVE-2024-XXXXX (implied but not stated)
usmannkhan.com · usmannk · 4 hours ago · details
0
vulnerability

A privilege escalation vulnerability in Tokemak's liquidity controllers allows attackers with ADD_LIQUIDITY_ROLE to steal protocol funds by manipulating pool ratios and exploiting the deploy() function's lack of price validation. The attack creates a malicious liquidity pool with a skewed token ratio, triggers the controller to deposit at the bad ratio, then extracts tokens through swaps, potentially stealing entire reserve amounts of FOX and ALCX tokens.

Tokemak SushiswapControllerV2 UniswapController Chainlink FOX ALCX
trust-security.xyz · Trust · 4 hours ago · details