YOLO Games (Bazaar) Incident Analysis
ID: 1cafca70-ac10-5941-95fd-ba0e20a92227
STIX ID: report--1cafca70-ac10-5941-95fd-ba0e20a92227
Feed Name: CertiK Blog
Threat Score
A critical input-validation bug in the Bazaar LBP contract's exitPool() allowed anyone to withdraw assets by passing the BazaarLBPFactoryBlast address as the sender; a whitehat exploited this to remove 392.37 ETH and 880,539,680 rYOLO, returned ~353 ETH (90%) as a negotiated bounty, and the project issued refunds and halted the LBP sale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
