DFX Finance
ID: af4766e2-9e7c-532e-8350-9425b8c71d70
STIX ID: report--af4766e2-9e7c-532e-8350-9425b8c71d70
Feed Name: CertiK Blog
On 2022-11-10 DFX Finance's swapping contracts were exploited for roughly $5M when an attacker used flashloans to manipulate the contract's balance checks. By depositing flashloaned tokens during the loan callback, the attacker bypassed repayment verification, obtained LP tokens from deposit(), and then withdrew underlying CAD and USDC assets; transaction links and the attacker contract are provided. The vulnerability is a design flaw allowing flashloaned tokens to be used to 'repay' loans via deposit(), and the report recommends adding reentrancy-style guards; impacted protocols were paused at the time of writing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
