Type: #reentrancy
Project: Paribus
Date: 11/04/23
Blockchain: Arbitrum
Problem: State is updated after tokens are sent.
Paribus is a fork of the old version of CompoundV2 protocol with a known reentrancy issue.
The Hacker:
1) Takes flashloan.
2) Opens position, calls redeem.
3) Reenters after funds were sent to him, borrow more tokens and continues to redeem.
Discoverer: NaN, was hacked
Harm: 100 k $
link
Project: Paribus
Date: 11/04/23
Blockchain: Arbitrum
Problem: State is updated after tokens are sent.
Paribus is a fork of the old version of CompoundV2 protocol with a known reentrancy issue.
The Hacker:
1) Takes flashloan.
2) Opens position, calls redeem.
3) Reenters after funds were sent to him, borrow more tokens and continues to redeem.
Discoverer: NaN, was hacked
Harm: 100 k $
link