SlowMist issued a security alert saying MCN Labs was attacked through a vulnerability in its LPBonus contract, with losses estimated at about $92,600. According to the security firm, the flaw came from the use of inconsistent reserve values in the contract’s reward calculation logic. By manipulating reserves, the attacker enabled a newly registered LP holder to claim 1,442,165.713011 FIST, even though the actual increase in rewards during the period was only 940,041.612768 FIST. SlowMist also disclosed the attacker address, 0xb6fff29dd2b5423a159e50877fc4af7a54e76f7a, and the victim contract address, 0x52272524a22f941f5489c1233732797314bb054b. The alert was attributed to @SlowMist_Team.
Techub News reported that blockchain security firm SlowMist issued a security alert saying MCN Labs was attacked because of a vulnerability in its LPBonus contract, with losses of about $92,600.
SlowMist said the root cause was that the LPBonus contract used inconsistent reserve values in its reward calculation. The attacker manipulated reserves, allowing a newly registered LP holder to claim 1,442,165.713011 FIST, while the actual reward increase during the same period was only 940,041.612768 FIST.
SlowMist identified the attacker address as 0xb6fff29dd2b5423a159e50877fc4af7a54e76f7a. The victim contract address was listed as 0x52272524a22f941f5489c1233732797314bb054b. The alert was published by @SlowMist_Team.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.