Drips Network, a decentralized tipping protocol, lost about 24,900 DAI in an attack tracked by SlowMist. The security firm said the issue stemmed from an integer type conversion flaw in the DaiDripsHub contract’s give(address,uint128) function. According to SlowMist, the function converted a uint128 amount into int128 without checking whether the input exceeded the maximum int128 value. By passing in a specially crafted number outside the int128 range, the attacker caused the converted amount to become negative. That flipped the direction of the transfer, allowing the reserve contract to execute an abnormal withdrawal to the attacker’s account. SlowMist said the exploit ultimately drained the reserve funds.
Drips Network, a decentralized tipping protocol, was exploited and lost about 24,900 DAI, according to monitoring by SlowMist.
SlowMist said the root cause was an integer type conversion flaw in the DaiDripsHub contract’s give(address,uint128) function. The function converted a uint128 amount into int128 without checking whether the input exceeded the maximum value allowed for int128.
By submitting a specific value outside the int128 range, the attacker made the converted amount turn negative. That reversed the transfer direction, which led the reserve contract to send an abnormal withdrawal to the attacker’s account. SlowMist said the reserve funds were eventually drained.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.