. Looks the contract of @SynapLogic was hacked, with a loss around 186k. Vulnerability summary: The implementation contract 0xC859 failed to validate critical parameters in swapExactTokensForETHSupportingFeeOnTransferTokens (0x670a3267). The function is supposed to accept native token payment (msg.value) and mint SYP to the buyer. However, attackers could arbitrarily control the “whitelist” logic via the 3rd input parameter, and specify any whitelist revenue-share address. What's worse, the contract distributes native token revenue shares by ratio but does not check whether the total payout exceeds the actual payment (msg.value). This allows an attacker to set a payout address such that the distributed native tokens are greater than the payment, extracting profit in native token while still receiving freshly minted SYP.


Sector:
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share
Relevant content




