On April 11, Fuzzland co-founder Chaofan Shou wrote on the X platform that there are security bugs in Bundler3, the front-end component of the lending agreement Morpho, and users are advised to avoid interactive operations through the front-end. Shou emphasized that only the "Multicall" function is affected, and the rest of the functions are safe. If you need to withdraw funds, it is recommended to execute the Withdraw function directly through the contract. At present, user funds themselves are...
4月11日消息,Fuzzland联合创始人Chaofan Shou在X平台发文称,借贷协议Morpho的前端组件Bundler3存在安全漏洞,建议用户避免通过前端进行交互操作。Shou强调,仅“Multicall”功能受影响,其余功能安全,若需提取资金建议直接通过合约执行Withdraw函数操作。目前用户资金本身未受影响。
Chaofan Shou, co-founder of security firm Fuzzland, said on the X platform: "Vestra DAO has just been hacked and is continuing. It has lost $480,000 and may lose more in the future. It is recommended to withdraw the pledge immediately and withdraw the liquidity."
"DEX Clipper has been hacked due to API vulnerabilities (such as private key leakage)," Shoucccc, co-founder of security agency Fuzzland, said in a statement. "The current loss exceeds $500,000, and $6.50 million of funds are at risk. Please withdraw your money immediately."
On July 25th, Fuzzland co-creator Chaofan Shou wrote on X that his team successfully blocked the potential attack against AllianceBlock and avoided losses of more than 2.80 million US dollars. After informing this situation, the AllianceBlock team has promptly fixed the relevant contract vulnerabilities.
On May 15th, blockchain security company FuzzLand intern @tonyke_bot posted on the X platform that team members used $100 to prevent more than $6.50 million of assets on Sonne Finance from being further attacked by hackers. Specifically, Compound-based Sonne has a common Compound V2 vulnerability, which allows attackers to perform loss of precision attacks when there is an uninitialized new pool (soVELO). FuzzLand detected the attack immediately after the hacker's first attack and found that the...
5月15日消息,区块链安全公司FuzzLand实习生@tonyke_bot在X平台发文表示,团队成员用100美元阻止了Sonne Finance上逾650万美元资产被黑客进一步攻击。具体而言,基于Compound的Sonne存在一个常见的Compound V2漏洞,当有未初始化的新池(soVELO)时,攻击者可以进行精度损失攻击。FuzzLand在黑客首次攻击后立即检测到该攻击,并发现攻击者持...