攻破 Aave 的可升级性
blog.trailofbits.com | 漏洞 | #smart-contracts | #defi | #vulnerability-disclosure | #blockchain | #aave | #delegatecall | #upgradeability
摘要
Trail of Bits 在 Aave 线上合约中发现严重漏洞:LendingPool 代理的公开初始化函数可被用于任意 delegatecall。负责任披露后不到一小时 Aave 即完成缓解,该漏洞曾逃过五家安全公司的审查。
- 发布时间
- 收录时间
Skip to content