A DeFi protocol called Cashio was attacked by an “infinite glitch” exploit around 9:00 a.m. (UTC).
An unofficial post mortem was written by Samczsun, a research partner from Paradigm. “Another day, another Solana fake account exploit,” Samczsun. “This time, [Cashio App] lost around $50M . How did this happen? In order to mint new CASH, you need to deposit some collateral,” the researcher remarked.
“This cross-program invocation will transfer tokens from your account to the protocol’s account, but only if the two accounts hold the same type of token,” the research partner from Paradigm continued. “Otherwise, the token program will reject the transfer. Here, the protocol validates that the crate_collateral_tokens account hold the right type of token by comparing it with the collateral account. It also verifies the collateral account shares the same token type as the saber_swap.
United States Latest News, United States Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
Stablecoin Cashio on Solana exploited for $28 million in 'infinite mint glitch'A stablecoin called Cashio on the Solana blockchain has been exploited and lost practically all of its value.
Read more »
Stablecoin Cashio on Solana exploited for $28 million in 'infinite mint glitch'A stablecoin called Cashio on the Solana blockchain has been exploited and lost practically all of its value.
Read more »
Solana-Based App Lost $50 Million Due to Fake Account Exploit, Here's HowThanks to samczsun we know how hackers exploited CashioApp and stole approximately $50 million
Read more »
Solana-based Secretum Now Integrated by Alfprotocol: DetailsSolana-based appsecretum is now integrated by AlfProtocol for secure messaging; joint $SER and $ALF giveaway announced Solana
Read more »
Mango DAO Embraces SOL, Rejects BTC With $1M Treasury InvestmentDon’t tell saylor: The DAO behind Solana DeFi hub mangomarkets rejected a plan to invest part of its $USDC treasury in $BTC, choosing $SOL exposure instead. realDannyNelson reports
Read more »