1 min read
Add as a preferred source on Google

BitBay Vault Exploit Results in About 14,838.47 Dai Loss

A flaw in the withdrawal function transferred the contract’s entire token balance when liquidity reached zero.

Mentioned assets
Open vault door beside scattered coins on a concrete floor / TokenPost.ai
Open vault door beside scattered coins on a concrete floor / TokenPost.ai

An exploit affecting BitBay’s Vault resulted in the loss of about 14,838.47 Dai (DAI).

The vulnerability involved the Vault’s _withdraw() function. When liquidity reached zero, the function transferred the contract’s entire token balance instead of limiting the payout to the user’s proportional share.

The attacker first used reposition() to reduce liquidity to zero. The attacker then redeemed one minimum share unit and withdrew about 14,838.47 DAI.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…