GoPlus: ListaDAO liquidity staking vault attacked, hacker exploits logic vulnerability to steal funds
According to ChainCatcher, GoPlus Security released an analysis stating that the Liquid Staking Vault contract of ListaDAO was attacked due to a business logic flaw. The attacker triggered the share calculation function in the Dividend contract when transferring specific tokens, which affected the reward claiming logic of the staking vault and ultimately resulted in the theft of a large amount of assets from the contract.
GoPlus Security points out that this logic vulnerability exists in both the Liquid Staking Vault and Dividend contracts, and any forked or reused implementations have a high risk of being exploited. Developers and projects are strongly advised to review and fix the vulnerability accordingly. Smart contract security should not rely on a “one-time audit.”
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
InnovAge Prices Secondary Offering of 10 Million Shares
TUI managing body member Helmut Reiner Sebastian Ebel buys shares for EUR 32,650
Angi Names Michael Steib as CEO
JPMorgan: HBM specification downgrade does not change the tight supply, demand CAGR remains at 63% from 2026 to 2028
JPMorgan recently released an industry report on the HBM storage sector, addressing market concerns about the downgrade of HBM specifications and providing updates on industry supply and demand, downstream demand, technological iteration, manufacturer competition, and investment assessments.
