Type: #validation
Project: Level finance
Date: 01/05/23
Blockchain: BSC
Problem: claimMultiple allows claim reward for the same epoch multiple times.
Level finance has a contract which grant users with rewards for swaps and has a referral system.
The Hacker:
1) Creates and sets lot's of referrals.
2) Executes swaps using flashloan in order to receive big reward per epoch.
3) Calls claimMultiple function, where all _epochs array is an array of the same epoch with big reward.
Discoverer: NaN. was hacked
Harm: 1 M $
link
Project: Level finance
Date: 01/05/23
Blockchain: BSC
Problem: claimMultiple allows claim reward for the same epoch multiple times.
Level finance has a contract which grant users with rewards for swaps and has a referral system.
The Hacker:
1) Creates and sets lot's of referrals.
2) Executes swaps using flashloan in order to receive big reward per epoch.
3) Calls claimMultiple function, where all _epochs array is an array of the same epoch with big reward.
Discoverer: NaN. was hacked
Harm: 1 M $
link