Discover and read the best of Twitter Threads about #QBridge

Most recents (1)

#CommunityAlert 🚨

@QubitFin's bridge contract, QBridge, has experience an exploit and minted 77,162 $qXETH worth $80M

QBridge contract on #ETH 👇
etherscan.io/address/0x9930…

Use caution if interacting!

Incident Analysis coming soon
@QubitFin Incident Analysis

The hacker called `deposit()` in the QBridge #eth contract w/o really making any deposit and emitted the Deposit event

The exploit was caused by `tokenAddress.safeTransferFrom` in QBridgeHandler.sol which didn't revert the tx when the tokenAddress is the 0x0.
2. The Ethereum QBridge captured the Deposit event and minted $qXETH for the hacker on #BSC.

The QBridge treats the Deposit event as an event of depositing #ETH because the `deposit` and `depositETH` methods in the #QBridge contract emit the same event.
Read 6 tweets

Related hashtags

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!