immunefi

2 articles
Sort: New Top Best
clear filter
0 9/10
vulnerability

A vulnerability in Tranchess's ShareStaking contract allows attackers to drain user funds by exploiting a skipped `_checkpoint()` call during rebalance events, causing a mismatch between token total supplies and actual contract balances. The attack leverages the contract's gas optimization technique to manipulate `spareAmount` calculations and steal staked tokens.

Tranchess ShareStaking FundV3 Immunefi Queen Bishop Rook floranguyen0
github.com · Flora · 4 hours ago · details
0
bug-bounty

A security researcher disclosed critical vulnerabilities in Moonbeam and Aurora Engine smart contracts, earning record bug bounties ($1M from Moonbeam, $6M from Aurora) by identifying delegatecall misuse and design flaws that put over $100M in DeFi assets at risk.

Moonbeam Aurora Engine NEAR Protocol Moonwell Immunefi WETH pwning.eth
pwning.mirror.xyz · pwning.eth · 4 hours ago · details