GoPlus: ListaDAO's liquidity staking vault was attacked, and the attacker exploited a logical vulnerability to steal funds
GoPlus Security released an analysis stating that the Liquid Staking Vault contract of ListaDAO was attacked due to a business logic flaw. The attacker triggered the share calculation function of the Dividend contract when transferring specific tokens, which affected the reward distribution logic of the staking vault, ultimately stealing a large amount of assets from the contract.
GoPlus Security reminds that this logical vulnerability exists in both the Liquid Staking Vault and Dividend contracts, and any fork or reused implementation carries a high risk of being exploited. Developers and projects are strongly advised to conduct reviews and fix the vulnerabilities accordingly. Smart contract security should not rely on "one-time audits."
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Projects for Modernizing Kindergartens and Purchasing Trolleybuses Completed in Ternopil

Neros Completes $250 Million Financing, Valuation Reaches $2.5 Billion

GoPlus: ClawHub has a vulnerability that allows for download count forgery, and popular skills may contain malicious code

GoPlus discloses a new type of Android malware PromptSpy, which utilizes AI large models to achieve remote control of devices

GoPlus Releases SafuSkill, Building a Security-First AI Agent Skills Marketplace

GoPlus launches AgentGuard, allowing users to securely access and use OpenClaw with peace of mind.

GoPlus Launches EIP-7702 Attack Defense Solution, Providing Comprehensive Protection for User Fund Security

Unveiling the Movement Liquidity Provider Sell-Off Scandal: Secret Contracts, Shadow Advisors, and Hidden Intermediaries

Unveiling the Movement Liquidity Provider Sell-Off Scandal: Secret Contracts, Shadow Advisors, and Hidden Intermediaries

Key Market Intelligence on March 4th, how much did you miss?

Bybit Hosts Web3 Roast: Are AI Memes a Flash in the Pan or the Future Trend?

The Quantum Issue: To Freeze Coins Or Not

Bank Lends Without Collateral but Refuses Bitcoin as Collateral, Explanation Lies in Capital Rule

Bitcoin cannot activate any soft forks for now, Drivechain creator says

Avalanche: From Digital Identity in the UAE to Finance in South Korea

Cardano fees covered just 0.7% of staking rewards as transactions fall 72%

Treasuries are the biggest risk to markets, say managers

CoinEx Closure: Users Have Until December 22 to Withdraw Their Cryptos

AI Pause Would Help Dominant Firms, Not Safety, Think Tank Warns

Digital Renminbi: Rethinking Currency Value from Payment Innovation

All bank deposits in Venezuela now generate interest

Fraudsters Target Businesses in Venezuela with Fake USDT Tokens

Hunter Biden Blames Market Makers for Only Investing $5,000 in Liquidity Despite Market Cap Surging to $100 Billion

Celsius sues BitMEX for $495 million just 11 days before exchange shutdown

Two Prime launches $10M-backed Bitcoin yield vault

Why Do You Have to Wait a Month to Participate in Ethereum's Native Staking?

Kraken parent plans regulated Hyperliquid perps

Phemex CEO Federico Variola: The AI Wave Has Drained Significant Cryptocurrency Funds and Enhanced Hacking Capabilities

Researchers Uncover Scheme of Fake Crypto Requests in Revolut








