Lack of verification, faulty ERC-4626 implementation
Days in Operation:
100 pts each
Reaper Farm is a Simplified Yield Aggregator. Reaper.Farm is an auto-compounding yield farm which maximizes user's yields by leveraging the power of compound interest. Exponential profit!
The project was hacked as reported by Peckshield Alert. Post mortem revealed that nn the evening of 8/1/2022, a hacker exploited the mis-implementation of the ERC-4626 interface to withdraw user funds into their account. It was a very simple mistake with dire consequences - validation of the receiver account was not accurate, allowing anyone to withdraw anyone else’s funds. User 0x5636e55e4a72299a0f194c001841e2ce75bb527a exploited our multi-strategies’ lack of validation and drained user funds into their wallet. This was done in a rapid series of transactions on the Fantom network, most notable being https://ftmscan.com/tx/0xc929f3b9312ff26be0adb1c3ff832dbdafdcbcaad33d002744effd515e53c9d5.
Funds were bridged via Multichain (AnySwap Fantom Bridge) and converted into approx. $1.6M DAI and 62 ETH and sent to Tornado.Cash.
The exploiter sourced the funds from Tornado.Cash and also exited via Tornado.Cash therefore making this exploit 100% untraceable.
DISCLAIMER: While web3rekt has used the best efforts in aggregating and maintaining this database, this web site makes no representations or warranties with respect to the accuracy or completeness of its information and data herein, and specifically disclaim any implied warranties of merchantability or fitness for any particular purpose.
Under no circumstances, shall web3rekt be liable for any loss of profit or funds, any regulatory or governmental penalties, any legal costs, or any other commercial and non-commercial damages, including but not limited to special, incidental, consequential, or other damages from any or all usage of the data and information derived from this database.