GoPlus: ListaDAO liquidity staking vault attacked, attacker exploited a logical vulnerability to steal funds

robot
Abstract generation in progress

ME News report: On April 16 (UTC+8), GoPlus Security released an analysis stating that the Liquid Staking Vault contract of ListaDAO was attacked due to a business-logic flaw. The attacker triggered the share-amount calculation function of the Dividend contract when transferring specific tokens, thereby affecting the reward-claiming logic of the staking vault and ultimately stealing a large amount of assets from the contract. GoPlus Security reminds that this logic vulnerability exists in both the Liquid Staking Vault and Dividend contracts, and any forked or reused implementation carries a high risk of being exploited. Developers and projects are strongly advised to review and fix the vulnerability accordingly. Smart contract security should not rely on a “one-time audit.” (Source: ChainCatcher)

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned