JUST IN: Attacker creates 1 billion Polkadot tokens on Ethereum, ends up stealing only $250,000.


A forged cross chain message bypassed proof of state validation in the bridge contract, granting administrative control over the bridged DOT token and allowing the attacker to mint and sell the entire supply for $237,000.
The vulnerability, which did not affect the Polkadot mainnet or native DOT, exploited a faulty cross chain message validation path to gain administrative control of the bridged token contract.
DOT-4.66%
ETH1%
post-image
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin