Missing Return Statement in DIP Token Code Drained $111,098 in USDC, Slowmist Reports

CAKE-3.27%
According to Slowmist, a missing return statement in the DIP token's transfer() function drained $111,098 in USDC through Pancakeswap. The flaw caused transfers to execute twice on the router, allowing attackers to repeatedly withdraw from the liquidity pool using skim() and sync() calls, with no flash loans or stolen keys required.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments