How CertiK's Formal Verification Engine Could Have Detected ICX's EnableTokenTransfer Issue
ID: 3cceb52e-f0e7-52ce-8b86-3218a0beb70f
STIX ID: report--3cceb52e-f0e7-52ce-8b86-3218a0beb70f
Feed Name: CertiK Blog
On Jun 16th 2018 a logic bug was reported in ICON's ICX token contract: a require statement used 'msg.sender != walletAddress' instead of 'msg.sender == walletAddress', which allowed anyone other than the owner to enable or disable token transfers. Attackers exploited this to disable ICX transfers and halt thousands of transactions; while tokens were not stolen, the incident disrupted functionality and prompted mitigation and public statements from the ICON team and offers of formal verification from CertiK.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
