Project | Vulnerability Cause | Vulnerability Occurred in | DefiLlama Inclusion | Hacker's Profit | GAS Source | Fund Destination |
---|---|---|---|---|---|---|
unibot | ❗️ sink unrestricted access, closed-source code, requires reverse engineering | Trading | 👌 | 640k USD | FixedFloat | tornado.cash |
Astrid | sink withdraw parameter not strictly validated | Withdrawal | 👌 | 4w USD (20% bonus) | EXch | Unchanged |
Maestro | sink fallback (unrestricted access) | Invocation | 👌, contract not found | 280 ETH | railgun | railgun |
OpenLeverage | sink initialize (unrestricted access, closed-source code) | Initialization | 👌 | 8K USD | tornado.cash | tornado.cash |
OpenDAO-kTAF | ❗️sink price depends on current state | Lending | 👌, contract not found | 8k USD | kucoin | Unchanged |
MicDao | ❗️ sink price manipulation | Exchange | Cannot | 13k USD | FixedFloat | Wallet |
Beluga | ❗️ sink price manipulation | Exchange | 👌 | 175k USD | Cross-chain bridge | Wallet |
WiseLending | ❗️ sink rate manipulation, precision difference based on current donation fund total | Donation | 👌 | 260k USD | tornado.cash | Unchanged |
Platypus | ❗️ price manipulation | Exchange | 👌 | 2m USD | Cross-chain bridge | Multisig address, possibly exchange |
BH | sink upgrade unrestricted access | Update | Cannot | 1.2m USD | tornado.cash | tornado.cash |
pSeudoEth | ❗️ price manipulation | Exchange | Cannot | 3k USD | Orbiter Finance | Wallet |
StarsArena | ❗️sink SellShares function reentrancy | Exchange | 👌 | 3m USD | Cross-cross-chain bridge | Multiple wallets |
DePayRouter | sink route function unauthorized access | Configure routing | Cannot | 827 USD | Wallet | Wallet |
FireBirdPair | 🤔 sink incorrect slippage protection | Exchange | 👌 | 8k USD | Wallet | Wallet |
DexRouter | ❗️sink (unrestricted access update unrestricted access | Update | Cannot | 20 BNB | tornado.cash | tornado.cash |
babydoge2 | 🤔 deflation? Slippage? | Exchange | 👌 | 441 BNB | tornado.cash | tornado.cash |
babydoge | 🤔 sink, deflationary token + 0 fee privilege, market manipulation? | Exchange | 👌 | 237 BNB | FixedFloat | FixedFloat |
XSDWETHpool | swapXSDForETH function reentrancy, impact analysis of deflation | Exchange | Cannot | 56 BNB | Wallet | tornado.cash |
Kub_Split | setPair parameter not validated, false trading excessive reward | Trading | Cannot | 22k BUSD | Wallet | Wallet |
CEXISWAP | ❗️sink unrestricted access to init, requires reverse engineering | Initialization | Cannot | 30k USDT | railgun | railgun |
uniclyNFT | Deposit function triggers onercERC1155Received and then reentrancy | Withdrawal | 👌 | 0.4 ETH | FixedFloat | Wallet |
Note:
[1] "❗️" indicates a common attack method. Some core methods: (1) Unauthorized privileged function discovered based on reverse engineering. (2) Profit from slippage loss of deflationary tokens. (3) Price manipulation based on flashloan.
[2] "🤔" indicates that the summary is based on speculation and has not been confirmed.