Low | Medium | High | Critical | Total | |
---|---|---|---|---|---|
Not fixed | 6 | 1 | 1 | - | 8 |
Fixed | 2 | 4 | 3 | - | 9 |
Total | 8 | 5 | 4 | 0 | 17 |
Click to show description
Quick Summary The Thoreum Finance protocol was exploited due to the private key leaking. Estimated losses are about $580,000 USD. Details of the Exploit The Thoreum Finance protocol was exploited, most likely it was an access control issue. Thus, the explorer had the ability to redeploy the proxy contract implementation with malicious logic inside. Approximately 500,000 THOREUM tokens were minted and swapped to WBNB. After that funds were transferred through tornado cash mixer. Block Data Reference Attacker address: https://bscscan.com/address/0x1ae2dc57399b2f4597366c5bf4fe39859c006f99 Attack tx: https://bscscan.com/tx/0x5058c820fa0bb0daff2bd1b30151cf84c618dffe123546223b7089c8c2e18331 Tornado cash transfers: https://bscscan.com/txs?a=0x1285fe345523f00ab1a66acd18d9e23d18d2e35c
# | Name | Auditor | Date | Chains | Issues |
---|---|---|---|---|---|
1 | Audit Report | Paladin | 2021/06/20 | BNB Chain | No active critical issues |