Git Product home page Git Product logo

defihacks's Introduction

DefiHack Examples

project(twitter) | date | value | analysis | transaction | poc | notes


Access Control

Arbitrary External Call Vulnerability

Business logic flaw

Input Validation

Price Manipulation

Reentrancy

Reflection token


Access Control

Arbitrary External Call Vulnerability

Business Logic Flaw

Input Validation

Price Manipulation

Reentrancy

Reflection token

K-value error

ExchangeRate Manipulation & ERC4626 Inflation Attack

Misconfiguration

Unrestricted Approval

public burn

Yield Protocol Flaw

Flashloan + scaledBalanceOf Manipulation

Integer overflow

Storage Collision

Balance Recalculation Bug

Price Oracle Manipulation

Flashloan Price Oracle Manipulation

Incorrect Parameter Setting

Insufficient Validation + FlashLoan

Malicious Unlimted Minting

Predicting Random Numbers

FlashLoan Attack

Business Logic Flaw & Access Control

Protocol Token Incompatible

Lack of Permission Check

Verify FlashLoan Callback

Price-caching Design Defect

Incorrect Reward Calculation

Liquidity Migration Exploit

Transfer Logic Flaw

Incorrect signature verification

MEVBOT a47b

Public FunctionCall

Malicious Proposal Mint & Transfer Ownership

Incorrect Owner Address Validation

Incorrect Reward Calculation

MEV-Badc0de

MevBot Private Tx

Pair Manipulation

Predicting Random Numbers

Incorrect Logic Check

Skim token balance

Incorrect acceptable merkle-root checks

Lack of access control mechanism

Incorrect recipient balance check, did not check sender!=recipient in transfer

Storage Collision & Malicious Proposal

Flashloans & Price Manipulation (FlashLoan price manipulation)

Optimism NFT Marketplace

Infinite Number of Loans

Private key compromised

Flashloan & Price Oracle Manipulation

Signature replay

Skim token balance

Flashloan

Malicious Proposal & Price Oracle Manipulation

Swap Metapool Attack

Denial of Service

Reward distribution flaw

DAO + Flashloan

Access control & Price Oracle Manipulation

Creat Future

Flashloan + token migrate flaw

Ronin Network - Bridge

Custom Approval Logic

Auctus

CompoundTUSD SweepTokenBypass

Bridges

Underflow

Business logic in mint()

Zero Fee

DAO

Bridge

Bridge address(0).safeTransferFrom() does not revert

Insufficient Token Validation

Price Manipulation

SushiSwap Miso

Nimbus Platform

NowSwap Platform

Deflationary token incompatible

Bridge, getting around modifier through cross-chain message

(I) Lost keys and minting (II) Vulnerable emergencyWithdraw

Bridge, logic flaw

Deflationary token uncompatible

Doesn’t burn shares

Mathematical flaw + Reentrancy

Incorrect calculation

Wrong balance check

Wrong visibility in function

Fee Machenism Exploitation

wrong implemention

Lack Slippage Protection

notes:

  • In most cases, Flashloan are not the root cause of attacks; they are merely a lending method. If an attack cannot be executed without the step of a Flashloan, only then it can been classified as a Flashloan attack.

defihacks's People

Contributors

cryptothink629 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.