makerdao

1 article
sort: new top best
clear filter
0 8/10
vulnerability

Critical vulnerability in Oasis Earn platform allowing arbitrary code execution via delegatecall by exploiting hidden assumptions about execution context. The vulnerability chains operation verification bypass with code-reuse attacks against ServiceRegistry to achieve selfdestruct of the OperationExecutor contract, awarded $20K bounty.

Oasis MakerDAO Immunefi DSProxy Lido stETH Uniswap Etherscan
trust-security.xyz · Trust · 17 hours ago · details