• banditx0x Profile Picture

    Whitehat Bandit @banditx0x

    4 months ago

    One of the most well known bugs is the ERC4626 first depositor inflation attack. It's so common that it would earn $0.00 when reported in a public contest. The bug actually exploits a really cool bug pattern and understanding this pattern can be used to discover unique high and critical exploits. Developers are told to "always round in favor of the protocol". In the case of an ERC4626 contract, this means rounding in favor of the vault. More specifically, it means "rounding against depositors and in favor of pre-existing vault shareholders". In the inflation attack the attacker controls 100% of the vault shares and therefore the rounding-in-favor-of-protocol actually rounds in favor of the attacker. Lesson: "Round in favor of the protocol" is often in fact against one user set and in favor of the others. The Wise Lending hack is an advanced application of this concept:

    danielvf Profile Picture

    Daniel Von Fange @danielvf

    2 years ago

    One of the most well known bugs is the ERC4626 first depositor inflation attack. It's so common that it would earn $0.00 when reported in a public contest. The bug actually exploits a really cool bug pattern and understanding this pattern can be used to discover unique high and critical exploits. Developers are told to "always round in favor of the protocol". In the case of an ERC4626 contract, this means rounding in favor of the vault. More specifically, it means "rounding against depositors and in favor of pre-existing vault shareholders". In the inflation attack the attacker controls 100% of the vault shares and therefore the rounding-in-favor-of-protocol actually rounds in favor of the attacker. Lesson: "Round in favor of the protocol" is often in fact against one user set and in favor of the others. The Wise Lending hack is an advanced application of this concept:

    banditx0x tweet picture

    24 105 603 108K 586
    Download Image

    2 6 87 7K 104
  • unsafe_call Profile Picture

    unsafe_call @unsafe_call

    4 months ago

    @banditx0x What surprises me is most people only think from the most common vector of being the first depositor and don’t realize there are many other ways you can create the conditions for share inflation without having such a strict initial condition

    1 0 6 315 1
  • yongsxyz Profile Picture

    yongsxyz @yongsxyz

    4 months ago

    @banditx0x $0.00 🤣

    0 0 0 24 0
  • Download Image
    • Privacy
    • Term and Conditions
    • About
    • Contact Us
    • TwStalker is not affiliated with X™. All Rights Reserved. 2024 www.instalker.org

    twitter web viewer x profile viewer bayigram.com instagram takipçi satın al instagram takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al sosyalgram takipçi satın al instagram ücretsiz takipçi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al metin2 metin2 wiki metin2 ep metin2 dragon coins metin2 forum metin2 board popigram instagram takipçi satın al takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al buyfans buy instagram followers buy instagram likes buy instagram views buy tiktok followers buy tiktok likes buy tiktok views buy twitter followers buy telegram members Buy Youtube Subscribers Buy Youtube Views Buy Youtube Likes forstalk postegro web postegro x profile viewer