permit-function

1 article
sort: new top best
clear filter
0 6/10
bug-bounty

A critical vulnerability in Zapper's "Zap Out" contracts allowed attackers to inject arbitrary call data into permit functions, enabling the theft of LP tokens from any user who had approved the contract. The vulnerability was patched within 24 hours of disclosure, with a $25,000 bounty awarded to the whitehat researcher.

Zapper Immunefi Lucash-dev Uniswap Sushiswap
medium.com · Lucash-dev · 6 hours ago · details