reentrancy

3 articles
Sort: New Top Best
clear filter
0 7/10
vulnerability

Threshold Network's L2WormholeGateway contract contained a critical vulnerability allowing attackers to mint unlimited canonical L2 tBTC by exploiting the depositWormholeTbtc function through reentrancy via a malicious ERC20 token's transfer callback. The vulnerability was discovered via Immunefi bug bounty, patched by removing the vulnerable function and adding reentrancy protection, with no funds lost.

Threshold Network tBTC Immunefi Wormhole L2WormholeGateway Arbitrum Base Optimism Polygon Bitcoin
blog.threshold.network · unknown · 4 hours ago · details
0 9/10
vulnerability

A reentrancy vulnerability in TectonicStakingPoolV3 allows attackers to mint xTonic tokens for free by injecting a malicious token into swap paths during performConversionForTokens() calls, enabling theft of over $2.5M with minimal capital ($23K TONIC). The attack exploits unwhitelisted intermediate swap path tokens to gain execution control and stake during balance calculations.

TectonicStakingPoolV3 0xE165132FdA537FA89Ca1B52A647240c2B84c8F89 TONIC xTonic WCRO VVS AttackerStaker AttackerToken
gist.github.com · 0xDjango · 4 hours ago · details
0
vulnerability

ANKR's distributeRewards() function on BSC receives 12,300 gas per call instead of the intended 10,000 due to the protocol's 2,300 free gas stipend for value transfers, increasing gas costs and slightly elevating reentrancy attack risk, though the gas amount remains below typical exploit thresholds.

ANKR BSC 0x66BEA595AEFD5a65799a920974b377Ed20071118
trust-security.xyz · Trust · 4 hours ago · details