GoPlus: ListaDAO liquidity staking vault was attacked, and the attacker exploited a logical vulnerability to steal funds

robot
Abstract generation in progress

Mars Finance reports that GoPlus Security released an analysis stating that the ListaDAO liquidity staking vault contract was attacked due to a flaw in its business logic. The attacker triggered the Dividend contract’s share calculation function when transferring specific tokens, thereby affecting the reward claiming logic of the staking vault, ultimately stealing a large amount of assets from the contract. GoPlus Security warns that this logical vulnerability exists in both the Liquid Staking Vault and Dividend contracts, and any forked or reused implementation carries a high risk of exploitation. Developers and projects are strongly advised to review and fix the vulnerabilities accordingly. Smart contract security should not rely on a “one-time audit.”

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin