Péter Újvári 🚀

304 posts

Péter Újvári 🚀 banner
Péter Újvári 🚀

Péter Újvári 🚀

@ptr_ujvr

I like coding, cryptography, DeFi, space and powerlifting - dev at @NFTfi

Copenhagen Katılım Eylül 2016
1.9K Takip Edilen218 Takipçiler
Péter Szijjártó
Péter Szijjártó@FM_Szijjarto·
With today’s US decision to suspend sanctions on Russian oil shipments, Russian oil can once again reach global markets by sea, increasing supply and bringing prices down. Europe, however, will not see these benefits, as Russian oil is banned from the European market and Brussels continues to make decisions according to the demands of @ZelenskyyUa. The EU should follow the American example and suspend sanctions on Russian oil. Allowing these supplies back onto the European market would help curb price increases, but unfortunately Brussels has not yet taken this step. As a result, fuel prices are rising across Europe, with gasoline and diesel becoming more expensive across the continent. We call on Brussels to waive sanctions on Russian oil. The EU’s decisions should not be driven by pressure from @ZelenskyyUa!
English
367
362
2.3K
276K
segwitnitwit ⛲️
segwitnitwit ⛲️@segwitnitwit·
@ptr_ujvr curious, what tool are you using to look through the smart contract execution like that?
English
1
0
1
19
Péter Újvári 🚀
Péter Újvári 🚀@ptr_ujvr·
Since I couldn’t find a good summary, here’s my writeup of yesterday’s Gondi exploit. A bit about me: I’m a smart contract dev at NFTfi, and I’ve spent time analyzing Gondi’s contracts. I also built an adaptor to refinance Gondi loans to NFTfi in the past.
Péter Újvári 🚀 tweet media
English
1
4
14
437
Péter Újvári 🚀
Péter Újvári 🚀@ptr_ujvr·
ps. - an interesting tangent: the attacker tried to steal ~38 Good Vibes Club tokens in addition, but a whitelist check in the token contract stopped that, this is a contract feature that I personally dislike, but was beneficial here
Péter Újvári 🚀 tweet media
English
2
1
5
126
Péter Újvári 🚀 retweetledi
Péter Újvári 🚀
Péter Újvári 🚀@ptr_ujvr·
tl;dr 2 - new _givebackNFT(...) used ownerOf(tokenId) as the from address - that let approved NFTs be pulled from users’ wallets, not MultiSourceLoan escrow - attacker batched multiple thefts in single txs via multicall
English
1
1
4
88
Péter Újvári 🚀 retweetledi
Péter Újvári 🚀
Péter Újvári 🚀@ptr_ujvr·
tl;dr 1 - combo of multiple issues, not one isolated bug - executeSell(...) mixed redundant / inconsistently validated NFT identifiers - attacker could push execution to the final giveback stage - users had approved PurchaseBundler for legitimate flows
English
1
1
3
70
GONDI
GONDI@gondixyz·
⚠️ UPDATE: Gondi Security Incident We have new information on the exploit. What we now know: • The exploit appears to affect NFTs that are NOT currently in active loans • It is tied to an approval vulnerability on the affected contracts (Purchase Bundler) • NFTs held as collateral in active loans do not appear to be at risk at this time What you should do right now: → Do NOT repay your loans until we confirm it is safe to do so → Revoke approvals for the affected contract immediately via revoke.cash → Do not initiate any new activity on the platform Affected contracts: (All Purchase Bundler) 0xc10472ac1bf9f2e58ff2c83596b4535334c90814 (Ethereum Mainnet) 0x1fba531724ea2493a15bf5c4ea05f6ab5c0fcd62 0x53ceda4c47585df08201955820e23bb261489140 0x3b59bffe109e0f33f20887343759a98b48ecdf5f 0xfd31a0cd628f0bab2cc174c3abd6bfc2d01aca61 0xfaaff69da43b8195e5b0945c4fea4476e4264157 (HypeEvm) If you have a loan that is about to expire and need to take action, please do NOT interact with the platform directly. Instead, open a support ticket in our Discord and the team will assist you personally. We will post another update as soon as we can confirm it is safe to resume normal activity. Thank you for your patience — we are working as fast as possible.
English
36
89
258
89.3K
nix.eth
nix.eth@nix_eth·
I had my auditing agent run the Gondi contract, and it found the vulnerability in 15 minutes. Every team needs to be doing this, because attackers already are. The exploited contract was deployed 17 days ago.
nix.eth tweet medianix.eth tweet media
English
32
6
97
12.4K
Crynet
Crynet@crynetio·
🔐 NFT Lending Platform Gondi Reports $230K Exploit, Says System Now Secure Gondi, an NFT lending protocol, confirmed a $230K exploit affecting only its Sell & Repay smart contract. According to Cointelegraph, the platform stated it is now secure and that buying, selling, trading, and listing NFTs can continue safely.
English
1
0
1
45
Max | Crypto
Max | Crypto@taylorbieber668·
🚨 BREAKING: $ETH NFT platform Gondi hacked for $230k. Here's what most people are missing: on-chain data suggests deeper $SOL ecosystem involvement. The exploit will impact $ETH liquidity #CryptoNews #DeFi
Max | Crypto tweet media
English
3
2
8
48
DigitalOil
DigitalOil@0xDigitalOil·
On the Gondi exploit
DigitalOil tweet media
Français
1
0
5
501