4 ms·
This was a rug-pull, not a hack. The actual hacks you'll see today are significantly different from those of last summer so there's been some measurable progres
by rodiger 6y ago
This was a rug-pull, not a hack. The actual hacks you'll see today are significantly different from those of last summer so there's been some measurable progress.
- hiq 6y ago> This was a rug-pull, not a hack. Who the attacker is does not matter. This comment seems to describe the vulnerability (intentionally implemented, but again, it doesn't matter) as a homoglyph attack: https://news.ycombinator.com/item?id=26358767 https://news.ycombinator.com/item?id=26358767 Homoglyph attacks are not new. Even for Solidity, they are at least 4 years old: https://github.com/Arachnid/uscc/tree/master/submissions-2017/marcogiglio https://github.com/Arachnid/uscc/tree/master/submissions-201... > // The e in the 'refunds' string is the unicode char U+0435, also known as Cyrillic small ie > uint weiAmount = balances['rеfunds'][msg.sender]; (from the README) > The actual hacks you'll see today are significantly different from those of last summer so there's been some measurable progress. They might or might not be different, the fact remains that they have gained little in sophistication, which would be a more relevant measure of progress. As I mentioned in another comment, this is not the kind of flaw that would have passed a diligent 3rd party audit, and yet the thieves got $31M from it.