WATCHPUG

53 posts

WATCHPUG banner
WATCHPUG

WATCHPUG

@WatchPug_

WATCHPUG is a security team that offers in-depth auditing for Solidity smart contracts.

EVM Katılım Mayıs 2021
205 Takip Edilen2.2K Takipçiler
Mudit Gupta
Mudit Gupta@Mudit__Gupta·
1) Create a $2 million audit content on @code4rena with one bug in the code 2) Report the bug with your alt account 3) Only accept your alt report as valid, mark rest as duplicate 4) Pay your alt the full bounty 5) Your alt becomes the top in the leaderboard 6) Profit??????
Mudit Gupta tweet media
English
28
5
173
0
WATCHPUG
WATCHPUG@WatchPug_·
The E in Solidity stands for easy.
English
6
62
82
0
WATCHPUG
WATCHPUG@WatchPug_·
Dear @paraswap, could you please display the full address in the warning box? So that 0xWho can reverse resolve the address to a readable name, which I rely on it to confirm the address.
WATCHPUG tweet media
English
2
1
8
0
WATCHPUG
WATCHPUG@WatchPug_·
@banteg @0xFrame True. It probably should try reverse resolve to a name using the local address book first, which is more practical. Perhaps it could also display how many times the user has interacted with the contract in the past.
English
0
0
1
0
banteg
banteg@banteg·
@WatchPug_ @0xFrame a forward ens record (name → address) is not sufficient to implement this. you can only set a reverse record (address → name) from the address itself. so the contract must have this functionality, which most contracts obviously lack.
English
2
0
8
0
WATCHPUG retweetledi
Curve Finance
Curve Finance@CurveFinance·
This happened in etherscan.io/tx/0x958236266…: the problem was them rolling a vulnerable LP token price oracle (sers, we have the correct one also!). Conclusion: if ever in the future you feel like rolling your price oracle for our pools - ask us to check please
Inverse@InverseFinance

Inverse has temporarily paused borrows following an incident this morning where DOLA was removed from our money market, Frontier. We are investigating the incident however no user funds were taken or were at risk. We are investigating and will provide more details soon.

English
2
20
86
0
WATCHPUG
WATCHPUG@WatchPug_·
the attacker then sold the DOLA tokens for usdt and then sold usdt for wbtc and repaid the flashloan, netted ~$1.3m of profit. btw, Curve also earned ~$3m fees out of these large vol trades.
English
1
0
2
0
WATCHPUG
WATCHPUG@WatchPug_·
.@InverseFinance now believes the crv3c is worth much more than it's actual value, so the attacker can borrow out 10m DOLA with only $4.7m worth of collateral. that's ~$5m of bad debt to the protocol.
English
1
0
2
0
WATCHPUG
WATCHPUG@WatchPug_·
oracle manipulation is easy when you are using balanceOf
English
1
8
33
0
WATCHPUG
WATCHPUG@WatchPug_·
currently building a chrome ext which will show you a tooltip with a human readable name (from your address book) whenever you select an address. it supports ENS reverse resolution; tells if it's a contract or EOA, + the ether balance. this chrome ext is gonna be called: 0xWho?
WATCHPUG tweet media
English
3
0
9
0
WATCHPUG retweetledi
InsureDAO
InsureDAO@insuredao·
We are honored to introduce the new ReportingDAO member, .@WatchPug_, a team of web3 security professionals! In combination with WATHPUG, InsureDAO will be able to elevate security, privacy, and usability even more!! link.medium.com/VpyPPrsUBnb #InsureDAO #DeFi
English
1
5
24
0
MoneyManDoug
MoneyManDoug@TWlTTERGM·
@WatchPug_ i have been warned of a vulnerability that affects multiple protocols on Fantom please PM me.
English
1
0
0
0
WATCHPUG
WATCHPUG@WatchPug_·
⚠️ Oct 20, 9 AM UTC, an attacker exploited PancakeHunny and stole 2.3M The root cause: inappropriate usage of a low liquidity pool makes it vulnerable to price manipulation to create artificial profits Read more: watchpug.medium.com/pancakehunny-f…
English
1
2
7
0