지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

Post Mortem: Safemoon

보고서 ·사고 분석 ·
Post Mortem: Safemoon

Project name: Safemoon

Project type: Token

Date of exploit: Mar 28th, 2023

Asset loss: $8.9M

Vulnerability: Access control

Date of audit report publishing: May 3rd, 2021

Conclusion: Out of Audit Scope

Details of the Exploit

Background

Safemoon is a token project where fees will be taken and added as liquidity in the token transfer process.

Nature of the Vulnerability

  • The public burn function allows anyone to burn tokens in any account.

CertiK Audit Overview

Screenshot 2024-01-11 at 8.37.00 PM

Conclusion

On Mar 28th, 2023, the Safemoon token contract was attacked, leading to a loss of $8.9M. The attacker took advantage of the public burn function and drained funds from the LP pool.

The vulnerability lies in the public burn function in the newly upgraded token contract, which CertiK has not audited.

관련 블로그

Post Mortem: Hector Network

Post Mortem: Hector Network

In light of the $2.7 million withdrawal incident from Hector Network's contract, we have gathered all the relevant information and are committed to maintaining transparency with the public.

Post Mortem: Fintoch

Post Mortem: Fintoch

On May 5th, 2023, the Fintoch was rugpulled, leading to a loss of ~$31.6M.

Post Mortem: Sushiswap

Post Mortem: Sushiswap

On April 9th, 2023, the RouteProcessor2 in Sushiswap was exploited due to missing validation on the input with processRoute function. The total loss is around $ 3.3 M.