staking-pool

1 article
Sort: New Top Best
clear filter
0 9/10
vulnerability

A reentrancy vulnerability in TectonicStakingPoolV3 allows attackers to mint xTonic tokens for free by injecting a malicious token into swap paths during performConversionForTokens() calls, enabling theft of over $2.5M with minimal capital ($23K TONIC). The attack exploits unwhitelisted intermediate swap path tokens to gain execution control and stake during balance calculations.

TectonicStakingPoolV3 0xE165132FdA537FA89Ca1B52A647240c2B84c8F89 TONIC xTonic WCRO VVS AttackerStaker AttackerToken
gist.github.com · 0xDjango · 4 hours ago · details