SlowMist Cosine: Pendle's large account was stolen because the contract it created for position entrustment allowed anyone to call

PANews reported on October 2nd that SlowMist Yuxian published a post on the X platform explaining the details of the previous theft of a Pendle VIP holder. It is reported that Pendle officials have confirmed that the protocol has not been attacked. Analysis of the theft of the Pendle VIP holder found that the contract onMorphoFlashLoan created by the VIP holder can be called by anyone. The VIP holder also entrusted his positions to this contract. The hacker called the VIP holder's onMorphoFlashLoan to carry out subsequent attacks on AAVE and Pendle positions. The VIP holder ultimately lost over $1.3 million.

Share to:

Author: PA一线

This content is for informational purposes only and does not constitute investment advice.

Follow PANews official accounts, navigate bull and bear markets together
App内阅读