backgroundbackground

How a Hacker Lost $2.7M While Stealing from a Venus Whale

On September 2, a Venus protocol whale user fell victim to a phishing attack that granted the hacker borrowing and redeeming rights, putting approximately $13M of the user’s assets at risk. However, after the hack, the stolen assets remain within the Venus protocol. With the quick response and actions taken by the Venus team, the stolen funds were recovered, and the hacker ended up losing $2.7M.

Daniel Tan
11 months ago
Analysis

Introducing Verite: The Next-Generation Smart Contract Fuzzer for Uncovering Profitable Vulnerabilities

Enter Verite—the world’s first profit-centric smart contract fuzzing framework. By simulating attacker logic and automating profit maximization, Verite transforms security from reactive detection to proactive defense, bridging the gap between vulnerability discovery and real-world exploitation.

MetaTrust Labs
over 1 year ago
Educational

AI Saves the World: AegisAI Transforms Web3 Security Through AI-Powered Bug Detection

AegisAI stands as a beacon of hope in the ongoing battle against cybersecurity threats.

MetaTrust Labs
over 2 years ago
Educational

Friendly Summary of "SolSEE: A Source-Level Symbolic Execution Engine for Solidity"

The founding team of MetaTrust has conducted research and published a paper to introduces SolSEE. What's SolSEE All About?

MetaTrust Labs
over 2 years ago
Educational

When Hacking Goes Haywire, Raft's 1570 ETH Loss Takes a Cosmic Detour to the Black Hole

2023-11-11 02:59:23 a.m., our MetaScout detected that the stablecoin protocol on #Ethereum, Raft, was under a flash loan attack. It resulted in ~6.7m stablecoin $R being minted and the protocol lost $3.6M. The root cause is the precision calculation issue when minting share tokens, which is used by the hacker to get extra share tokens. MetaTrust Labs conducted in-depth research and analysis on the exploit, revealing how the hacker exploits vulnerability.

Daniel Tan
almost 3 years ago
Analysis

Curve Cracked: How $52M Vanished in a Vyper Vulnerability

The reentrancy attack on Curve Finance serves as a regrettable security incident and a thought-provoking lesson.

MetaTrust Labs
about 3 years ago
Report

Security Analysis Report: Centralization Risk in iziFinance Smart Contract

In this analysis, we will examine one of the core contracts of iZiFinance and identify a simple way to reduce gas consumption by eliminating a redundant expression.

MetaTrust Labs
about 3 years ago
Analysis

Unraveling the $UN Attack: A Flash Loan Exploits Flaw in Token Contract

$UN on BSC was attacked by the flash loan with a loss of $26,000

Daniel Tan
about 3 years ago
Analysis