A vulnerable bot was allowing anyone to steal its owner's funds. We neutralized it, and the technical elements showcase an interesting Solidity anti-pattern.
A vulnerable bot was allowing anyone to steal its owner's funds. We neutralized it, and the technical elements showcase an interesting Solidity anti-pattern.
Attack vectors (and their combinations) over xSushi-like staking, ERC777 tokens
Issuing warnings to 100 vulnerable accounts via Etherscan chat
Multi-hundred million attack prevented