sa1nt
50 posts

sa1nt
@0xsa1nt
Newcomer web3 security researcher. Innovation requires sacrifice. Just not mine.

After careful consideration, we’ve made the decision to wind down @code4rena. This community has meant a great deal to everyone who has been part of building it, and sharing this news is not easy.







🚨JUST IN: ~$1.3M drained from @giddydefi-related vaults interacting with @yieldbasis (YB core contracts safe). Root cause appears to be incomplete EIP-712 signature coverage. Attacker allegedly reused a valid signature, changed unsigned fields, and drained vault assets.






🚨@KelpDAO is potentially exploited for over $290M in rsETH. WETH on AaveV3 Core is also affected; withdraw now if you have any such positions. rsETH is accepted as collateral on AaveV3 Core, where it's been used to borrow WETH.











