OpenZeppelin, a security audit company for Coinbase, identified $15B rugpull vulnerabilities in Convex Finance, whose anonymous developers later resolved the risk. The surprising discovery occurred during a security review of the Convex Finance protocol.
A Bug Only Exploitable From the Inside
The Security Research Team from OpenZeppelin found in late 2021 that a significant bug in the protocol could have led to putting the $15B worth of locked assets at risk. The investigation revealed that “if two of the three signers of the Convex multisig executed a specific series of steps, users would be able to access all the LP tokens staked in the target pool and thus conduct a rugpull – stealing all the assets from the pool.”
Documentation from Convex at that time stated that such a disaster occurring to its LP pools would not be possible. However, the security team later identified ways of exploiting the vulnerabilities – which fortunately were patched by Convex on 14th December 2021.
We współpracy z: https://cryptopotato.com/openzeppelin-found-potential-15b-rugpull-in-convex-finance/