
Following $SPELL exploited funds, will share more as it progresses, currently just consolidated most
INTΞRN
5.1K posts

@thyintern
Professional Sleuth 🕵️ Yield Optimizer ✍️ NFA DYOR 🔮

Following $SPELL exploited funds, will share more as it progresses, currently just consolidated most







As always, SplitNOW has maintained 100% uptime amidst the ongoing global Cloudflare outage. However, some of our partner exchanges are temporarily offline. If a partner is ever unable to process your swap, our fail-safe system automatically re-routes you to the next best rate.




SplitNOW Points Season 1 is live now 🪼 Points are our way of rewarding our loyal users for their early support of the Next Big Thing™. SplitNOW is the final and best solution for exchange aggregation and onchain privacy amidst increasing financial surveillance. We provide open access to over 50+ trusted exchanges (with many more coming soon!), a wide array of supplementary tooling, and a free whitelabel API accessible to everyone. Points will be distributed for the remainder of the season relative to user activity metrics like volume, number of order legs, range of exchanges used, and more. Additionally, users can achieve VIP tiers based on their lifetime volume, which awards them reduced fees and multipliers on point accrual. No account is required to use SplitNOW, but to start earning points, sign up in 2 clicks here: splitnow.io/auth/register gSplit.



$MIM @MIM_Spell exploited for ~$1.7M. (Explainer QRTd). Team has repurchased this amount so no impact on users at time of writing. The exploiter funded the attack wallet with 3x 0.1 $ETH txs using tornado cash, and is currently washing 10 ETH clips out of the 1.7M out through tornado. Wallet below: etherscan.io/address/0x1aaa…

It seems abracdebra @MIM_Spell is hacked again. This time a more obvious vulnerability. where a "else" branch clears the status variables and set "needSolvencyCheck" to false the default value. (P1) The attacker did 2 actions in one transaction: "5" (borrow) and "0" (nothing but set check to false). (P2) They have paused all their contracts now. Disclaimer: This is my priliminary analysis and I may make mistakes. NFA.