Tinyman opened about the latest attack that started on January 1st. A few “unauthorized users” breached some of the protocol’s pools after compromising a previously unknown vulnerability on its smart contracts.
Tinyman Compromised
According to the official blog post, the attack resulted in a drain of certain ASAs in the first hours. This, in turn, induced massive volatility. Tinyman revealed that the hack activated their wallet addresses and deposited a seed fund for the breach. To execute the attack, the perpetrators essentially targeted the pools and started to swap a portion of their funds and minted Pool Tokens.
It was an unknown bug in the burning of Pool Tokens that the perpetrators reportedly exploited and managed to acquire “two of the same Assets instead of two different Assets.”
According to the platform, this was favorable for the perpetrators as the “gobtc asset” was significantly more valuable than Algorand’s native token ALGO. They immediately swapped agai
We współpracy z: https://cryptopotato.com/3-million-lost-as-an-algorand-based-decentralized-trading-platform-exploited/