From 6ae8c950afd2a85d3e2c4713c62b667fefa2acfa Mon Sep 17 00:00:00 2001 From: Feist Josselin Date: Fri, 25 Jun 2021 11:43:06 +0200 Subject: [PATCH 1/4] Update trophies.md --- trophies.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/trophies.md b/trophies.md index 89817f506..e410b40a6 100644 --- a/trophies.md +++ b/trophies.md @@ -46,3 +46,5 @@ please submit a PR with the relevant information. [AlphaHomoraV2](https://certificate.quantstamp.com/full/alpha-homora-v-2) | Dangerous divide before multiply operations | Jan 2021 [Mimo Defi](https://certificate.quantstamp.com/full/ten-x-titan) | Lack of return value check | Jan 2021 [OriginTrail](https://certificate.quantstamp.com/full/origin-trail-starfleet-staking) | Lack of return value check | Feb 2021 +[VoyagerToken](https://certificate.quantstamp.com/full/voyager-token) | Lack of return value check | Apr 2021 + From ffda3cb2fa6e470bceac0ffc8fd11f087c4cf557 Mon Sep 17 00:00:00 2001 From: Feist Josselin Date: Fri, 25 Jun 2021 12:19:41 +0200 Subject: [PATCH 2/4] Update trophies.md --- trophies.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/trophies.md b/trophies.md index e410b40a6..1d5a0fcc7 100644 --- a/trophies.md +++ b/trophies.md @@ -46,5 +46,6 @@ please submit a PR with the relevant information. [AlphaHomoraV2](https://certificate.quantstamp.com/full/alpha-homora-v-2) | Dangerous divide before multiply operations | Jan 2021 [Mimo Defi](https://certificate.quantstamp.com/full/ten-x-titan) | Lack of return value check | Jan 2021 [OriginTrail](https://certificate.quantstamp.com/full/origin-trail-starfleet-staking) | Lack of return value check | Feb 2021 +[charmfinance](https://github.com/charmfinance/cube-protocol/commit/2f1dd9c7bf6ced3c99332bbe0ff50030efece44a) | Lack of return value check | Mar 2021 [VoyagerToken](https://certificate.quantstamp.com/full/voyager-token) | Lack of return value check | Apr 2021 - +[holdmybeer](https://github.com/hodlmybeer/hodl/pull/4) | Reentrancies | Jun 2021 From a2c5714238be910bd9ca2f26eab311acddaa48aa Mon Sep 17 00:00:00 2001 From: Feist Josselin Date: Fri, 25 Jun 2021 16:16:36 +0200 Subject: [PATCH 3/4] Add Slither Rekt to trophies.md --- trophies.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/trophies.md b/trophies.md index 1d5a0fcc7..c67bee009 100644 --- a/trophies.md +++ b/trophies.md @@ -49,3 +49,15 @@ please submit a PR with the relevant information. [charmfinance](https://github.com/charmfinance/cube-protocol/commit/2f1dd9c7bf6ced3c99332bbe0ff50030efece44a) | Lack of return value check | Mar 2021 [VoyagerToken](https://certificate.quantstamp.com/full/voyager-token) | Lack of return value check | Apr 2021 [holdmybeer](https://github.com/hodlmybeer/hodl/pull/4) | Reentrancies | Jun 2021 + +## Slither Rekt +The following lists security incidents that could have been prevented using Slither. + +| Project | Vulnerability | Value loss | Date +|--|--|--| -- | +Dforce | [Reentrancy](https://peckshield.medium.com/uniswap-lendf-me-hacks-root-cause-and-loss-analysis-50f3263dcc09) | $25m (recovered) | Apr 2020 +Lendf.me | [Incorrect self-transfer](https://bzx.network/blog/incident) ([slither-prop](https://github.com/crytic/slither/wiki/Property-generation)) | $8m | Sep 2020 +Akropolis | [Reentrancy](https://blog.peckshield.com/2020/11/13/akropolis/) | $2m | Nov 2020 +OUSD | [Reentrancy](https://blog.originprotocol.com/urgent-ousd-has-hacked-and-there-has-been-a-loss-of-funds-7b8c4a7d534c?gi=fcb8badacf40) | $7m | Nov 2020 +Furucombo | [Arbitrary delegatecall](https://medium.com/furucombo/furucombo-post-mortem-march-2021-ad19afd415e) | $15m | Mar 2021 +ForceDAO | [Lack of return value check](https://blog.forcedao.com/xforce-exploit-post-mortem-7fa9dcba2ac3) | $10m ($9.6m recovered) | Apr 2021 From 8f9898473fddab7c0768b495a1bcc7982ee6e568 Mon Sep 17 00:00:00 2001 From: hacker-DOM Date: Fri, 9 Jul 2021 11:54:14 +0200 Subject: [PATCH 4/4] fix trailing space in L54, L58 --- trophies.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/trophies.md b/trophies.md index c67bee009..642ea5f45 100644 --- a/trophies.md +++ b/trophies.md @@ -51,11 +51,11 @@ please submit a PR with the relevant information. [holdmybeer](https://github.com/hodlmybeer/hodl/pull/4) | Reentrancies | Jun 2021 ## Slither Rekt -The following lists security incidents that could have been prevented using Slither. +The following lists security incidents that could have been prevented using Slither. | Project | Vulnerability | Value loss | Date |--|--|--| -- | -Dforce | [Reentrancy](https://peckshield.medium.com/uniswap-lendf-me-hacks-root-cause-and-loss-analysis-50f3263dcc09) | $25m (recovered) | Apr 2020 +Dforce | [Reentrancy](https://peckshield.medium.com/uniswap-lendf-me-hacks-root-cause-and-loss-analysis-50f3263dcc09) | $25m (recovered) | Apr 2020 Lendf.me | [Incorrect self-transfer](https://bzx.network/blog/incident) ([slither-prop](https://github.com/crytic/slither/wiki/Property-generation)) | $8m | Sep 2020 Akropolis | [Reentrancy](https://blog.peckshield.com/2020/11/13/akropolis/) | $2m | Nov 2020 OUSD | [Reentrancy](https://blog.originprotocol.com/urgent-ousd-has-hacked-and-there-has-been-a-loss-of-funds-7b8c4a7d534c?gi=fcb8badacf40) | $7m | Nov 2020