yield-farm

1 article
sort: new top best
clear filter
0 7/10
bug-bounty

A critical logic error in Belt Finance's strategy contract allowed attackers to manipulate the balanceSnapshot variable by sending tokens directly to the contract, causing the protocol to mint excessive strategy shares and enabling drainage of ~$60M in BNB. The bug involved incorrect double-counting of withdrawals when funds could be satisfied from the contract's direct balance without liquidating yield-generating assets.

Belt Finance Immunefi Alexander Schlindwein Armor Fei Protocol Binance Smart Chain Alpaca
medium.com · Bobface · 23 hours ago · details