. @makinafi suffered an exploit on Ethereum, resulting in a loss of 5,107,871 USDC. The root cause was that `DUSDUSDC.getSharePrice()` incorrectly relied on the pool's spot price when calculating the LP asset value (i.e., the function `Frax Finance: MIM-3LP3CRV-f Token.calc_withdraw_one_coin()` to obtain the price). This allowed the attacker to manipulate the pool's price, artificially inflating the LP's value and thus conducting an arbitrage attack. Found by #PhalconSecurity, Analyzed via #PhalconExplorer.

Sector:
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share
Relevant content




