Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CRITICAL] Possible Bug Stealing Money #98

Open
Wabinab opened this issue Oct 9, 2023 · 1 comment
Open

[CRITICAL] Possible Bug Stealing Money #98

Wabinab opened this issue Oct 9, 2023 · 1 comment

Comments

@Wabinab
Copy link

Wabinab commented Oct 9, 2023

Refer to this example.

If you checked the example, there was an assertion raised; however, the assertion wasn't handled such that it result in a successful transaction.

The issue was submitted on ImmuneFi, with steps to reproduce, with ID 24033. Please check.

Unfortunately, I couldn't find the exact file of ft_transfer_call or ft_on_transfer that calls the swap function (that most probably doesn't handled the exception properly) by searching this repo; nor could I provide a solution for the issue.

@reticenceji
Copy link

Hey bro, it seems that there is no problem in contract. And the transaction you given doesn't steal any money from ref protocol.
Based on your blog, it seems that you ignore your wNEAR turn to NEAR, which makes you think you get money from the air.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants