avatar

onewayfunction

onewayfunction

Security research. MEV consulting. Crypto nerd. Formerly: Flashbots, OpenZeppelin, Augur, OpenBazaar.
Subscribe to onewayfunction
Receive the latest updates directly to your inbox.

Fun with Footguns in BoringSolidity

Publisher
onewayfunction
January 26
I came across a fun footgun in the BoringSolidity contracts library and wanted to share it so future devs (and their users) don’t lose a foot. It is closely related to the vuln that samczsun found in the MISO fundraise. Here it is in a single line:

Principal Freezing and Ransom Attacks with MasterChefV2

Publisher
onewayfunction
January 19
One of the services I've been offering for the past several months is quick (less than 2hr) security checks of yield farming pools. I look for rug-pull potential and security risks in yield farming contracts to help protect would-be farmers and LPs. I basically try to spot trouble with farms before a user puts their funds at risk.