๐จ
$SSS Incident & $4.5M "Bug Bounty"
๐ TL;DR:
@ThrusterFi users, breathe easy - you're unaffected. But the
@SSS_HQ token contract's tax system? Exploited.
Attackers doubled their balance by self-transacting, walking away with $4.5M in
$SSS sales.
๐ผ How It Happened:
1. Double Trouble: Sending
$SSS to your own address? Balance doubled.
2. Rinse & Repeat: 25x calls to SSS.transfer(address(this), SSS.balanceOf(address(this))
3. Drain the Pool: Swapped 9 times, emptying the liquidity pool (LP), $4.5M in the "pocket:
๐ Technical Breakdown:
โก๏ธ L122: Recipient's balance gets a boost by adding the post-tax amount. The sender's balance hasn't been touched yet.
โก๏ธ L124 vs. L125: First, they deducted from the sender. Then, they updated the recipient's balance without considering the deduction if the sender is the recipient. Swapping L124 with L122 would solve the issue.
๐ Transaction:
app.dedaub.com/blast/tx/0x80โฆ
โก๏ธ High market cap projects, take note. This highlights the critical importance of thorough audits by reputable companies.
โน๏ธ It's not just about security; it's about safeguarding your community's trust and investment.
Notes: Thanks to Fab from
@Rareboard team for the explanation of the transaction.
Also, for the safety of
@Blast_L2 users: LP/Tocken Locker from
@BlastVerseIO going live approximately next week.
#Blast_L2 #SSS #Alert #Blast #SuperSushiSamurai