create account

MakerDAO bug could’ve let hackers steal Ethereum powering its DAI stablecoin by transisto

View this thread on: hive.blogpeakd.comecency.com
· @transisto ·
MakerDAO bug could’ve let hackers steal Ethereum powering its DAI stablecoin
https://thenextweb.com/hardfork/2019/10/03/makerdao-security-vulnerability-ethereum-dai-stablecoin-collapse-theft-cryptocurrency/

>“The cost of performing the attack is almost zero — just the minimal denomination of each type of gem stolen plus gas,” wrote the researcher who discovered the flaw.

> MakerDAO’s smart contract had almost zero access control
A HackerOne disclosure report reveals the attack was to be possible due to a complete lack of access control in a MakerDAO smart contract — specifically, the contract that was to allow the system to auction collateral in exchange for DAI cryptocurrency when loans are liquidated.

> “A lack of validation in the method flip.kick allows an attacker to create an auction with a fake bid value,” reads the disclosure. “Since the end contract trusts that value, it can be exploited to issue any amount of free Dai during liquidation. That Dai can then be immediately used to obtain all collateral stored in the end contract.”
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
👎  
properties (23)
authortransisto
permlinkmakerdao-bug-could-ve-let-hackers-steal-ethereum-powering-its-dai-stablecoin
categorycrypto
json_metadata{"tags":["crypto","eth","fail"],"links":["https://thenextweb.com/hardfork/2019/10/03/makerdao-security-vulnerability-ethereum-dai-stablecoin-collapse-theft-cryptocurrency/"],"app":"steemit/0.1","format":"markdown"}
created2019-10-03 16:05:12
last_update2019-10-03 16:05:12
depth0
children0
last_payout2019-10-10 16:05:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length979
author_reputation330,357,940,720,833
root_title"MakerDAO bug could’ve let hackers steal Ethereum powering its DAI stablecoin"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id91,193,657
net_rshares-22,758,634,177,415
author_curate_reward""
vote details (62)