whitehack

1 article
sort: new top best
clear filter
0 7/10
vulnerability

An unprotected init() function in 88mph's CRV:RENWBTC, CRV:STETH, and yaLink pools lacked onlyOwner and initializer modifiers, allowing anyone to call it multiple times and take ownership of NFT contracts to mint/burn user deposits. The vulnerability was worth approximately $6.5M in potential theft and was responsibly disclosed and patched via whitehack.

88mph Immunefi Ashiq Amien iosiro Duncan Townsend CVE-2021-41119
medium.com · Ashiq Amien · 20 hours ago · details