HomeAboutWhat is web3?FAQLicenseTwitterMastodonBlueskyInstagramThreadsRSSLeaderboardGlossaryContributeNewsletterStore

Archived tweet

Back

Tweet thread by PeckShield:

Today's hack on 
@RDNTCapital
  results in the loss of 1.9k eth (~$4.5m). 

The root cause is not new:  It basically exploits a time window when a new market is activated in a lending market (forked from the popular Compound/Aave). The exploitation also relies on a known rounding issue in current Compound/Aave codebase.

Specifically, today's actor https://arbiscan.io/address/0x826d5f4d8084980366f975e10db6c4cf1f9dde6d… sniped the new USDC market deployment and exploited it *6 seconds* after the activation. 
Tweeted at 6:57 PM · Jan 2, 2024

The solution is simple: when a new market is being added, make sure it is activated with CF 0% !!! 
Tweeted at 16h

Tweet #1

Image #1:

Image

Links:

  • https://arbiscan.io/address/0x826d5f4d8084980366f975e10db6c4cf1f9dde6d

Text is licensed under a Creative Commons Attribution 3.0 Unported License. All attribution can be found on the attribution page.

Source code | Contribute