OpenZeppelin's authorization check has been bypassed, classic defenses have failed, brothers should be extra cautious during audits.

View Original
CoinNetwork
CryptoWorld News reports that the SlowMist Security Team has issued an alert stating that littleboyplus has suffered a vulnerability attack, resulting in a loss of approximately 377,642 USDT, equivalent to about 610.555 BNB. SlowMist stated that the root cause of the vulnerability lies in the update function of the lbphashrate contract, which can be triggered by a zero-amount transferFrom call, bypassing OpenZeppelin's authorization check. The attacker can mint LBP tokens directly to the PancakePair address without trading pair authorization, causing an imbalance between balances and reserves, and then withdraw USDT through PancakePair.swap.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned