3 ms·
This is the most useful explanation I've found about the vulnerability so far: https://blog.zeppelin.solutions/on-the-parity-wallet-multisig-hack-405a8c12e8f7 h
by pietrofmaggi 9y ago
This is the most useful explanation I've found about the vulnerability so far: https://blog.zeppelin.solutions/on-the-parity-wallet-multisig-hack-405a8c12e8f7 https://blog.zeppelin.solutions/on-the-parity-wallet-multisi...
The explanation is a bit scary about what actually ended up in parity code:
The wallet contract forwards all unmatched function calls to the library using delegate call... This causes all public functions from the library to be callable by anyone, including initWallet, which can change the contract’s owners.
Edit: formatting