Prodigal retweetledi
Prodigal
121 posts

Prodigal
@ProdigalWiz
EVM and Solidity tinkerer.
Immutable Avenue Katılım Temmuz 2020
88 Takip Edilen1.1K Takipçiler
Prodigal retweetledi

@definedfi Introducing @trycodex: The most accurate & reliable API for blockchain data.
Codex delivers real-time, enriched blockchain data for over 4.5 million tokens and 1 billion NFTs on 57 networks.
It already powers a lot of the products you are using every day.
English
Prodigal retweetledi

The @SSS_HQ $SSS LP was just drained on blast because their token contract has a bug where transferring your entire balance to yourself doubles it.
The order of operations decrements the balance for "from" and then sets the balance for "to" - if these are the same address, the "toBalance" does not take into affect the decrement of "amount" and just overwrites the balance with the initial balance + transferred amount.
Attacker was able to get 1310 ETH from the LP by doubling their balance repeatedly and then selling it all
blastscan.io/tx/0x80012bf78…
blastscan.io/tx/0x62e6b906b…
blastscan.io/tx/0xac3400e3d…

English

Thrilled to be part of the journey with @FjordFoundry as they pave the way towards developing fairer and more transparent price discovery mechanisms for early-stage projects.
Fjord Foundry@FjordFoundry
1/ We are pleased to announce the successful closure of Fjord's seed fundraising round, led by @Lemniscap, w/participation from @MechanismCap, @ZeePrimeCap and numerous angels, @dcdao_ @UniswapVillain @Rager @JohnnyZcash @KieranWarwick @fomosaurus
English

Several rugpull attempts are mimicking @Furnace404's upcoming launch. If you read their website source code using Inspect Element, you can see they are using a font called "Highschool Runes". With this information, you can now decode their landing page and come to the conclusion that the countdown goes until the 21st, so anything launching before that is likely a scam.


English

@_0xShunya @minerercx I'm a Solidity dev, not directly connected to the team, just tried to help them figure out the situation. Please refer to the project account for official updates.
English

1/ Yesterday, @minerercx's ERC-X token contract was exploited, resulting in a loss of 156 ETH due to a double-accounting error in its internal transfer function, which allowed an attacker to duplicate their own balance by sending tokens to themselves. pic.twitter.com/j5JsaXsUEp
English

4/ The team also reached out for my assistance to diagnose and rectify the issue, and further bolstering their commitment to security, they've partnered with a professional auditing firm for a thorough review of their novel ERC-X token standard. All their updates are now transparently documented in their GitHub repository (github.com/Miner-Labs/ERC…), signaling a well-prepared relaunch in the days ahead.
English

3/ In response to the attack, the @minerercx team quickly intervened, safeguarding a significant portion of the liquidity pool. This crucial action not only halted the exploit's advancement, but will also now enable now enable them to restart the project.
English
Prodigal retweetledi

Thanks to @threesigmaxyz for completing a security audit of our ONFT smart contracts.
A detailed audit report can be found in the announcement below.
Three Sigma | Web3 Security@threesigmaxyz
The full report detailing key findings is now available! github.com/threesigmaxyz/…
English
Prodigal retweetledi

With the increasing popularity of ERC404 token contracts, we're seeing a rise in opportunistic rug pulls. Be extra vigilant for functions like `emergencyWithdrawNFT` hidden within contract code. These can allow the owner to mint infinite tokens in a discreet manner. As the saying goes, protect yourself at all times.

English

⚠️ 4/ Signing Hex Strings: Rare yet risky, these date back to the early days of platforms like @EtherDelta . Starting with "0x...", they are not standard text, and can interact with your assets in unpredictable ways. MetaMask flags them with a warning message for a good reason.

English

🪂 1/ It's airdrop season, a period when many of us interact with websites to claim tokens, which usually requires signing a message on your web3 wallet such as @MetaMask . But how safe is it?
Let's dive into the world of web3 signatures, uncover the risks, and learn how to spot the safe ones.

English

@0xSleuth_ @crypto_bitlord7 No, the function above permanently excludes the provided address from fees, so it doesn't matter if they receive tokens or not afterwards.
English

@ProdigalWiz @crypto_bitlord7 i mean, he can just send 1 token to those wallets again tho?
English

This is due to how the `transfer` function was implemented (#code" target="_blank" rel="nofollow noopener">etherscan.io/address/0x2428…), where addresses that receive tokens sent by a participant in the angel/private sale, are automatically marked as angel/private sale buyers as well.

👀@UniswapVillain
Angels/Private salers on @crypto_bitlord7 token $MOLLY can send tokens to other users and mark them as an angel/private seller giving them the same sell tax restrictions. One private saler is sending tokens to all top holders giving them all high tax.
English


