The white hat recovering 2 million is the only good news tonight, but the truncation issue in the mint function's division warrants all protocols to review their code.

View Original
WuSaidBlockchainW
Wu Shuo learned that SlowMist issued a security warning stating that the options protocol Thetanuts Finance was attacked, resulting in a loss of approximately $2.1 million, but about $2 million of related positions were protected by white hat addresses. SlowMist stated that the vulnerability stemmed from an integer division truncation issue in the mint(uint256) function. After the attacker reduced the total treasury supply to nearly zero through claim(uint256), the division result in the deposit calculation formula was truncated to 0, allowing the attacker to infinitely mint shares at zero cost and withdraw funds.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned