Last night a vulnerability was discovered and patched within 24 minutes.
All funds are safe. No action is required by users.
We have published a detailed write-up here:
https://github.com/iearn-finance/yearn-security/blob/master/disclosures/2020-09-25.md …
h/t @samczsun @AndreCronjeTech @lehnberg @bluekirbyfi
-
-
Great write-up folks! It’s not clear how long this was happening before the alarm was raised. Any scope for alerting on anomalies like this? It was fortunate that discord users called it out, but we shouldn’t rely on that.
1 réponse 0 Retweet 1 j'aime -
En réponse à @SomerEsat @samczsun et
When the monitoring system is finished, alerting would be trivial to add.
1 réponse 0 Retweet 4 j'aime
Perfect. You guys are awesome. <3
15:19 - 25 sept. 2020
0 réponse
0 Retweet
0 j'aime
Le chargement semble prendre du temps.
Twitter est peut-être en surcapacité ou rencontre momentanément un incident. Réessayez ou rendez-vous sur la page Twitter Status pour plus d'informations.