0xChew
@0xchew
I was the auditor that identified and reported a vulnerability in thirdweb's contracts. Now that the issue is public, I can talk about how it was discovered and how it all went down.
2 replies
5 recasts
19 reactions
0xChew
@0xchew
This is practically a new attack vector. I came across the vuln while auditing another project; one of @Iosiro_security’s internal reports listed this critical issue for their own client.
1 reply
0 recast
1 reaction
horsefacts
@horsefacts.eth
Great find and thank you to you and everyone involved in the mitigation. I'm curious how many contracts in the wild actually used both 2771 and multicall vs how many were incidentally affected by inheriting unused code.
0 reply
0 recast
1 reaction