🏆Another win for Mjolnir: our autonomous agentic pentesting agent just earned $2,000 bounty from
Yearn.fi!
The bug: reflected XSS through the /api/vault/meta endpoint on the
Yearn.fi frontend.
Because wallets are often already connected on the webapp, the impact could have been severe; including potential loss of funds.
Frontend security in crypto is not optional.
Thanks to
@yearnfi for a smooth dialogue and quick mitigation! Issue has been fixed, ref:
github.com/yearn/yearn.fi/co…