Phạm Tiến Minh Đức

500 posts

Phạm Tiến Minh Đức

Phạm Tiến Minh Đức

@pmbibe

Việt Nam Katılım Ocak 2015
1.2K Takip Edilen640 Takipçiler
Phạm Tiến Minh Đức
🧵 Summary: Owner = 0x0 enabled signature bypass Invalid signatures (r=0, s=0) bypassed ecrecover Attacker registered fake chains Unlimited token minting occurred Users lost millions Thread ends here. Stay safe! 🛡️
English
0
0
0
50
Phạm Tiến Minh Đức
🚨 We analyzed a CRITICAL vulnerability in $PORT3 A perfect storm of 3 bugs allowed attackers to: ✓ Bypass authorization with EMPTY signatures ✓ Register fake chains ✓ Mint UNLIMITED tokens ✓ Drain bridge liquidity The root cause? Owner = 0x0 What happened 🧵
English
10
0
0
610
Phạm Tiến Minh Đức
With fake chain registered: tokenContracts[23] = 0x4644bbcfd26... // Attacker's contract Now attacker can: Forge Wormhole message from "chain 23" Set emitter = their contract Set amount = UNLIMITED Call bridgeIn() Contract mints tokens ✓ FUNDS DRAINED
English
0
0
0
44
Phạm Tiến Minh Đức
Bug #2 - Empty Signature Acceptance Result: Attacker sends 65 bytes of zeros → Accepted
Phạm Tiến Minh Đức tweet media
English
0
0
0
41
Phạm Tiến Minh Đức
Critical bug: Signature verification doesn't check for zero address Here's the trap: Invalid signatures return 0x0 from ecrecover If authority = 0x0 Then: 0x0 == 0x0 → TRUE ✗ Authorization BYPASSED with invalid signature
Phạm Tiến Minh Đức tweet media
English
0
0
0
63
Phạm Tiến Minh Đức
When a non-owner wants to call sensitive functions, they must provide: ✓ Valid custodian address ✓ Non-expired timestamp ✓ VALID SIGNATURE
English
0
0
0
24
Phạm Tiến Minh Đức
CATERC20 is a cross-chain token bridge using: Wormhole for cross-chain messaging Signature verification for governance registerChains() to whitelist token bridges Problem: The authorization mechanism had a critical flaw.
English
0
0
1
68
Phạm Tiến Minh Đức retweetledi
Ahmed
Ahmed@CryptoBheem·
let’s do a quickie😈 💎 Lifetime Access to @Bheem_Lounge (worth $2,500) Will pick anyone from likes/retweets or comment section randomly Ends in 60 minutes, goodluck😼
English
534
368
1K
46.1K
Phạm Tiến Minh Đức retweetledi
Ahmed
Ahmed@CryptoBheem·
bheem is happy so $1,000 USDT giveaway😗 To top it off, Lifetime Access to @Bheem_Lounge vip (worth $2,000) discord.gg/wAdxTBYbBS Just like this tweet & join above, winner in 24h- glhf🤝
English
340
302
1.4K
34.6K
Phạm Tiến Minh Đức retweetledi
BHEEM
BHEEM@Bheem_Lounge·
Do you want to make consistent profits each month? Participate to win a lifetime subscription to @Bheem_Lounge worth $1500. Still not enough? Win an additional $1000 in USDT by becoming a ByBit user: forms.gle/Ur4Jd6GcEBoZTv… ❤️ & ♻️ to enter !!
BHEEM tweet media
English
106
321
518
42.4K
Phạm Tiến Minh Đức retweetledi
Free Crypto Signals
Free Crypto Signals@cryptoalvin·
#RSS3 (1W) $Rss3 Upward trend in the near term✅ 100% coming 🤝 #web3 #ai
Free Crypto Signals tweet media
English
0
1
4
5.4K