bug-bounty498
google351
xss301
microsoft293
facebook262
rce211
exploit199
malware170
apple162
cve136
account-takeover115
bragging-post102
privilege-escalation95
csrf90
phishing86
browser75
writeup74
authentication-bypass69
supply-chain67
dos66
stored-xss65
reflected-xss57
ssrf56
reverse-engineering55
access-control52
react52
input-validation49
cross-site-scripting48
cloudflare47
aws47
web-security46
docker46
lfi46
smart-contract45
sql-injection45
ethereum44
web-application44
node43
ctf43
defi43
oauth43
web343
pentest40
race-condition39
open-source38
cloud37
idor37
burp-suite36
info-disclosure36
vulnerability-disclosure35
0
7/10
bug-bounty
A critical logic error in Belt Finance's strategy contract allowed attackers to manipulate the balanceSnapshot variable by sending tokens directly to the contract, causing the protocol to mint excessive strategy shares and enabling drainage of ~$60M in BNB. The bug involved incorrect double-counting of withdrawals when funds could be satisfied from the contract's direct balance without liquidating yield-generating assets.
logic-error
smart-contract
yield-farm
share-minting
balance-manipulation
withdrawal-logic
bsc
binance-smart-chain
defi
bug-bounty
bragging-post
Belt Finance
Immunefi
Alexander Schlindwein
Armor
Fei Protocol
Binance Smart Chain
Alpaca