BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Analysis of DODO attack incidents: Lifting a "rock" and hitting your own foot?

Beosin
特邀专栏作者
This article is about 874 words, reading the full article takes about 2 minutes
The main reason for the attack of this incident is that the init function of the contract is not restricted, which makes the attacker have the right to call.
AI Summary
Expand
The main reason for the attack of this incident is that the init function of the contract is not restricted, which makes the attacker have the right to call.

1. Event overview

secondary title

On March 9, 2021, Beijing time, according to the public opinion monitoring of [Beosin-Eagle Eye], the wCRES/USDT fund pool on the decentralized exchange DODO seems to have been hacked , Wrapped CRES (wCRES) worth nearly $980,000 and USDT worth nearly $1.14 million were transferred. According to DODO's official reply, the team is currently investigating.

https://www.odaily.com/newsflashes/235047.html

The original link is as follows:

The security team of Chengdu Beosin immediately launched a security emergency response to the incident, and sorted out the detailed analysis of the incident for reference. In fact, the incident itself is not complicated, and its attack process is also very simple. However, because the incident involved hot topics such as "flash loans" and "reentrancy attacks", Chengdu Lianan believes that it is necessary to speak out about the incident.

2. Event analysis

2. Event analysis

The main reason for the attack of this incident is that the init function of the contract is not restricted, so that the attacker has the right to call, as shown in Figure 2:

△Figure 2

image description

△Figure 3

secondary title

3. Security Recommendations

The security team of Chengdu Beosin believes that this incident is not complicated, but it is worth sounding the alarm and attracting the attention of the majority of project parties. Specifically, DODO’s flash loan function has re-entry checks, but since the init function does not add re-entry checks, similar re-entry attacks have occurred.

DODO
Safety
invest
Welcome to Join Odaily Official Community