搜索
快讯
2024-05-14 11:30:00
Planet Evening News
1. Binance spot will add FRONT/USDC, PEOPLE/TRY, TRB/USDC trading pairs and trading robot services; 2. Bloomberg analyst: Ethereum spot ETF is not expected to be approved before the end of 2025; 3. Vitalik proposed a new proposal for Ethereum, aiming to make multi-dimensional Gas pricing more concrete; 4. Abraxas Capital withdrew 20,881 ETH from Compound and Bitfinex and pledged it on ether.fi; 5. DWF Labs co-founder: Prepare to take legal action against the mastermind behind the public opinion attack against DWF Labs; 6. Binance contract joint margin model will stop supporting TUSD and XRP; 7. Starknet provides multiple grant plans to help ecosystem builders, with a total of US$26 million in funds; 8. Equalizer: Users can currently use the backup website, please do not use cross-chain services, test websites and v4 websites; 9. Standard Chartered Hong Kong and others have passed the Hong Kong Monetary Authority's regulatory sandbox to complete the tokenized deposit proof-of-concept test; 10. The notional value of Ethereum call options expiring at the end of June on Deribit exceeds US$1.8 billion, and the exercise price is concentrated above US$3,600; 11. CoinShares' Q1 asset management scale reached US$6 billion; 12. Binance Futures Copy Trading has added ARKMUSDT, BOMEUSDT and other U-based perpetual contracts; 13. GameStop's pre-market gains in US stocks expanded to 48.18%; 14. Base announced the ninth batch of 2024 Builder Grants projects, including Anomalys, Bons, etc.; 15. Equalizer hackers have stolen 2,353 EQUAL, 2,500 spLP and other tokens.
2022-06-07 15:40:40
Security Team: The FlashLoanProvider contract of Equalizer Finance is incompatible with the Vault contract, leading to flash loan attacks
星球日报讯 据慢雾区消息,6月7日,<span class="font">Equalizer</span> Finance遭受闪电贷攻击。慢雾<span class="font">安全</span>团队将攻击原理分享如下: 1. Equalizer Finance存在FlashLoanProvider与Vault合约,FlashLoanProvider合约提供闪电贷服务,用户通过调用flashLoan函数即可通过FlashLoanProvider合约从Vault合约中借取资金,Vault合约的资金来源于用户提供的流动性。 2. 用户可以通过Vault合约的provideLiquidity/removeLiquidity函数进行流动性提供/移除,流动性提供获得的凭证与流动性移除获得的资金都受Vault合约中的流动性余额与流动性凭证总供应量的比值影响。 3. 以W<span class="font">BNB</span> Vault为例攻击者首先从PancekeSwap闪电贷借出WBNB 4. 通过FlashLoanProvider合约进行二次WBNB闪电贷操作,FlashLoanProvider会先将WBNB Vault合约中WBNB流动性转给攻击者,随后进行闪电贷回调。 5. 攻击者在二次闪电贷回调中,向WBNB Vault提供流动性,由于此时WBNB Vault中的流动性已经借出一部分给攻击者,因此流动性余额少于预期,则攻击者所能获取的流动性凭证将多于预期。 6. 攻击者先归还二次闪电贷,然后从WBNB Vault中移除流动性,此时由于WBNB Vault中的流动性已恢复正常,因此攻击者使用添加流动性获得凭证所取出的流动性数量将多于预期。 7. 攻击者通过以上方式攻击了在各个链上的Vault合约,耗尽了Equalizer Finance的流动性。 此次攻击的主要原因在于Equalizer Finance协议的FlashLoanProvider合约与Vault合约不兼容。
查看更多