New Free Dao Incident Analysis
ID: ef9d5fcd-f7bc-5c87-84fa-d4e72f3dfdf2
STIX ID: report--ef9d5fcd-f7bc-5c87-84fa-d4e72f3dfdf2
Feed Name: CertiK Blog
CertiK detected and analyzed a flashloan exploit on the Binance Smart Chain targeting New Free DAO (NFD) on 2022-09-08; the attacker exploited an unverified rewards contract that lacked guardrails against flashloans, stealing roughly $1.25M (4,481 BNB) and leaving significant funds (~2,081 BNB and ~557k USDT) in the attacker wallet while performing swaps and partial laundering (including Tornado Cash). The report decompiles the vulnerable bytecode, outlines the attack flow and transactions, provides links to exploit TXs and the attacker address, and highlights the risk of unverified contracts and the need for audits and flashloan protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
