Post Mortem: Safemoon

리서치 사고 분석
Post Mortem: Safemoon

Project name: Safemoon

Project type: Token

Date of exploit: Mar 28th, 2023

Asset loss: $8.9M

Vulnerability: Access control

Date of audit report publishing: May 3rd, 2021

Conclusion: Out of Audit Scope

Details of the Exploit

Background

Safemoon is a token project where fees will be taken and added as liquidity in the token transfer process.

Nature of the Vulnerability

  • The public burn function allows anyone to burn tokens in any account.

CertiK Audit Overview

Screenshot 2024-01-11 at 8.37.00 PM

Conclusion

On Mar 28th, 2023, the Safemoon token contract was attacked, leading to a loss of $8.9M. The attacker took advantage of the public burn function and drained funds from the LP pool.

The vulnerability lies in the public burn function in the newly upgraded token contract, which CertiK has not audited.

관련 블로그

Post Mortem: Thoreum Finance

Post Mortem: Thoreum Finance

On Jan 18, 2023, Thoreum Finance's token contract v4 was exploited, leading to a loss of around 2,260 WBNB. The attacker took advantage of the flawed implementation in the token contract's transfer function and manipulated its balance.

Post Mortem:  TerraPort Finance

Post Mortem: TerraPort Finance

On April 10th, 2023, the Terraport project team was alarmed breach detected with the Terraport Liquidity wallet. The total loss is around $4M.

Post Mortem: Telcoin

Post Mortem: Telcoin

​​On Dec 26th, 2023, Telcoin experienced a loss of ~$1.25M attack. The vulnerable contract is due to a vulnerability in the proxy implementation of wallet contracts, which is a different application from what CertiK has audited.