GoPlus: ListaDAO liquidity staking vault attacked, hacker exploits logic vulnerability to steal funds
According to ChainCatcher, GoPlus Security released an analysis stating that the Liquid Staking Vault contract of ListaDAO was attacked due to a business logic flaw. The attacker triggered the share calculation function in the Dividend contract when transferring specific tokens, which affected the reward claiming logic of the staking vault and ultimately resulted in the theft of a large amount of assets from the contract.
GoPlus Security points out that this logic vulnerability exists in both the Liquid Staking Vault and Dividend contracts, and any forked or reused implementations have a high risk of being exploited. Developers and projects are strongly advised to review and fix the vulnerability accordingly. Smart contract security should not rely on a “one-time audit.”
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Waller: The Federal Reserve is observing rising yields and striving to remain uninvolved
Washington: AI Investment Sets Stage for Future Growth
KPMG: The Federal Reserve is expected to raise interest rates in September
