transferfrom

1 article
sort: new top best
clear filter
0 7/10
bug-bounty

A critical ERC-20 token implementation bug in Redacted Cartel's wxBTRFLY contract allowed attackers to reassign user allowances to themselves via a faulty transferFrom function, risking $6 million in funds. The vulnerability was fixed by replacing the custom implementation with OpenZeppelin's battle-tested ERC-20, and the researcher received a $560,000 bounty.

Redacted Cartel Immunefi Tommaso Pifferi OpenZeppelin wxBTRFLY xBTRFLY ERC-20 ERC-721
medium.com · Tommaso Pifferi · 20 hours ago · details