The problem with having no duplicate check is an attacker can create a short position, and after 14 days, they could call their position ID multiple times in a list. This would let them steal funds from the lock contract over and over at little cost and zero risk. (4/12)
-
-
Two days on, I'd like to correct some claims going around: - I don't believe this was an inside job. No compelling evidence of that yet. - I'm not a 'genius' and I didn't find this all by myself. Story embellished for narrative; the credit goes to my amazing anon research team.
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Fatman what is going to happen to us with wluna?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
not reporting this in the proper channels is something I would pursue
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
But there is no mirror developer team
-
Yeah, but “What if I told you that Mirror Protocol, up until 18 days ago, was susceptible to the one of the most profitable exploits of all time, allowing an attacker to generate $4.3m from $10k in a single transaction? Here's how I discovered this - by pure serendipity.

”? - Show replies
New conversation -
-
-
So crypto has exploits and researchers find them to make the project more secure. People act like this is a surprise
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Wow ,well done FatMan .amazing how could you be able to digging into Terra and expose their loopholes
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks for your hard work on this. We need people like you to perfect crypto.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
