Muscan
11.6K posts

Muscan
@MichaelMuscan
♱♱ welcome home son ♱♱


🚨 @TheIndexFi $INDEX HOLDERS READ THIS a noticeable % of OUR fees got stolen there was a real on-chain exploit on the old USDGBuyerDistributor on robinhood chain between july 26-28 a linked address cluster used flash-borrowed $INDEX + 3 helper contracts to make the same recipient show up FOUR TIMES in a holder snapshot. result: 4 identical payouts across all 18 stock tokens, cycle after cycle. i traced the 4x pattern across 42 payout cycles. the attacker's cut floated somewhere around 8-11% depending on the cycle. proof: manipulation tx: 0xad42e120117d64e8e4a96ec8f71fea85dc3d098ec60ed14297bfd2739e06f7e0 4x payout: 0x004884cb535842333537d908498ec99db60a9afc5724ce40c1f169b9df99d1ae exploit contract: 0xb7A82CAAE3efCAE9dD808973dEED70A631D5929C deployer wallet: 0x7cf3cb7b7dde0d3a1ad5c4ab29efb8099f0b7aba recipient wallet: 0x24be7bab027f09b124108cc860d814a2e57293bc is it fixed? looks fixed but through migration, not by patching the old contract. old V1 is still on-chain, paused() is still false, but it's not distributing anymore. a new verified USDGBuyerDistributorV2 is live: 0x39adb8acd07427d338b5f1afab436a04abfdb7c4 V2 adds address dedup per snapshot, keeper-only snapshots/distributions, and a live-balance recheck at payout that kills the returned flash-loan weight. so to be clear - this is NOT a warning that the same exploit is still draining V2. but the incident was real, and holders deserve: - a public post-mortem - аull accounting of affected distributions how much was actually extracted - whether any recovery or reimbursement is coming i hate fudding my own bags of $index, but that's the whole point of web3 -- we're supposed to operate out in the open shoutout @Kolot86692580 for the find





Frank Degods been moving a lil different lately

















