Build secure Uniswap V4 Hooks in AVS
In recent months, both Uniswap V4 and EigenLayer’s Actively Validated Services (AVS) have gained significant attention – not without reason. Uniswap V4 introduced a […]
We are constantly learning new things, and believe that knowledge should be shared.
In recent months, both Uniswap V4 and EigenLayer’s Actively Validated Services (AVS) have gained significant attention – not without reason. Uniswap V4 introduced a […]
Loss of capital of users who withdraw stETH. Their LST rewards will be miscalculated. Vulnerability Details The general questions section in the readme.md states […]
Holders of wBETH and other tokens that will be accepted by Renzo can compensate for their losses resulting from price drop (e.g. slashing) using […]
Full withdrawals do not decrease user voting power when the Locking contract is stopped. Vulnerability Details Under specific conditions, the owner may stop the […]
This vulnerability allows anyone to make a cross-chain calls with multiple compose messages, and execute the messages (all except the first one) as the […]
The user can use a nested MSG_REMOTE_TRANSFER message in a valid MSG_REMOTE_TRANSFER to execute back the remote transfer as the owner of tokens (stealing […]
The executeModule function allows anyone to execute any module with any params. That allows attacker to execute operations on behalf of other users. Vulnerability […]
The function executes modules depending on the _msgType parameter and some of them do not accept the _srcChainSender parameter. Vulnerability Details The _toeComposeReceiver function is called […]
Learn how to effectively protect your X account. Do not let hackers take control. Why is it worth taking care of it? Security is […]
The threat scenario covered in this article is “attacker calls hooks directly on the hook contract”. The example illustrating such a vulnerability was based on […]
Let us help
Get throughly tested by the creators of Smart Contract Security Verification Standard