Exploiting a Smart Contract without Security Vulnerabilities: Analysis of True Seigniorage Dollar Attack Event
ID: 697d519e-3844-5ad9-94a3-e4d1e2f16079
STIX ID: report--697d519e-3844-5ad9-94a3-e4d1e2f16079
Feed Name: CertiK Blog
CertiK discovered a governance takeover of the True Seigniorage Dollar (TSD) project in which an attacker purchased TSD to gain voting power, passed a proposal to replace the proxied token implementation with a malicious contract, invoked its initialize() to mint ~11.6B TSD to the attacker, and converted the tokens to BUSD for a profit of approximately $16,600; the report attributes the root cause to DAO governance mechanics (low owner voting weight and proposal/voting rules) rather than a direct smart-contract vulnerability and recommends governance changes to prevent "proposal kidnapping."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
