How to Chain 2FA Bypasses in Crypto P2P System and Steal Users’ USDT
hackenproof.com | blog | #bug-bounty | #web3 | #appsec | #vulnerability-research | #writeup | #session-security | #2fa-bypass | #logic-flaw | #p2p
Summary
A bug bounty write-up on chaining two logic flaws in a crypto P2P platform — frontend-only 2FA and weak session isolation — to control victims' wallets and steal USDT.
- Published
- Collected
Skip to content