Low | Medium | High | Critical | Total | |
---|---|---|---|---|---|
Not fixed | 2 | 1 | 1 | - | 4 |
Fixed | 7 | 1 | 1 | - | 9 |
Total | 9 | 2 | 2 | 0 | 13 |
Click to show description
Quick Summary On August 13, 2024, Vow, a decentralized discount voucher issuer, suffered an exploit leading to a potential collapse of its native token VOW, with losses amounting to $1.2 million. Details of the Exploit The vulnerability occurred during the testing of a rate setter function, which altered the amount of vUSD received per VOW token from 1 to 100. The testing period lasted only 15 to 30 seconds, but within that time, a bot managed to acquire 20 million VOW tokens valued at $6.6 million. The bot then swapped these tokens on Uniswap V2 for 452 ETH, equivalent to $1.23 million. In response, Vow increased the token's burn rate to 50% to reduce the circulating supply back to normal levels. Block Data Reference Exploiter: https://etherscan.io/address/0x48de6bf9e301946b0a32b053804c61dc5f00c0c3 Example of exploit tx: https://etherscan.io/tx/0x4b439b82c8878644cd809cfafa6e5c056518a54ea4df098eb1fed9d1cce5ca5f
# | Name | Auditor | Date | Chains | Issues |
---|---|---|---|---|---|
1 | [SCA] Vow / Vowcurrency | Hacken | 2024/09/20 | Ethereum | No active critical issues |