Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»HACKING NEWS»Junami Hack Postmortem: What Happened?
HACKING NEWS

Junami Hack Postmortem: What Happened?

By Crypto FlexsNovember 26, 20232 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Junami Hack Postmortem: What Happened?
Share
Facebook Twitter LinkedIn Pinterest Email

There are already a lot of Zunami hack posthumous articles that are almost identical. Here is our opinion.

Exploit Causes

The exploit consisted of two hacks, both of which: Price caching vulnerability The first target was Zunami ETH (zETH) and the second target was Zunami Stable (UZD). The first attack was drained. Only 26 WETH, the second is a whopping 1178 WETH.

The root cause was price manipulation using . MIMCurveStakeDao The strategy is to then cache the inflated price for an entire block of UZD (suitable for flash lending) and then reverse the previous operation to profit from the inflated price.

price caching

UZD’s Liquidity Pool (LP) price caching was partially implemented in version 1.0. thanked By Ackee Blockchain. However, it is not used globally and functions as follows: balanceOf Instead of caching, we were making multiple costly calls (calculating LP prices in our strategy).

Caching has been expanded with the following features: totalSupply, balanceOf and allowance later UZD version 1.1. Caching has been adjusted in the following way:

source

This allowed inflated prices to be called in other contracts. balanceOf function.

Version 1.1 was released without an audit. It was later audited by HashEx for the release of v1.2 on October 29, 2023. audit reportNo attack vectors using cached functions were found.

MIMCurveStakeDao Strategy

This strategy was introduced in commit. 6df0ae5. Since the calculation is based on the price and balance of the strategy, an attacker can change the LP price calculation by donating SDT tokens to the strategy. This strategy was audited by HashEx before release (see this). audit report) However, no exploitability was found.

attack

The attack occurred on August 13 and can be viewed here. https://explorer.phalcon.xyz/tx/eth/0x0788ba222970c7c68a738b0e08fb197e669e61f9b226ceec4cab9b85abe8cceb

Or you can check: PoC (Good job DeFiHackLabs!)

We hope this postmortem will be helpful and contribute to making web3 a safer place free of hacking and exploits.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cryptocurrency Inheritance Update: March 2026

April 9, 2026

Videos and Podcasts | Vault12

April 3, 2026

Vault12 Guard 2.8 provides real-time portfolio balance for cryptocurrency inheritance

March 18, 2026
Add A Comment

Comments are closed.

Recent Posts

BitMart x $EAT Trade-to-Feed Competition Pays 4.4 Million USDT to Traders in May 2026

April 30, 2026

Crypto billionaire Justin Sun files suit against Trump-linked World Liberty Financial over ‘wrongly’ frozen tokens

April 30, 2026

VerifyVASP Acquires Sygna, Consolidating The Global Travel Rule Network

April 29, 2026

Dogecoin Price Analysis: Is $DOGE’s $0.10 Level a Smart Entry or a Market Trap?

April 29, 2026

How to Connect OpenClaw with Binance for Live AI Trading (2026)

April 28, 2026

BitMart X $EAT Trade-to-Feed Competition To Pay Out $4.4M USDT To Traders In May 2026

April 28, 2026

ORBS) Reports Total Holdings Of Approximately $333 Million, Includes OpenAI, Beast Industries, More Than 11,000 ETH And Over 283 Million WLD Tokens

April 28, 2026

Core Scientific moves forward with 1.5GW AI data center campus in Texas

April 28, 2026

AxeCasino To Attend IGB L!VE 2026 Following Front-End Update Focused On Usability And Cross-Device Performance

April 28, 2026

Ondo Finance adds proxy voting for holders of $700 million worth of tokenized shares.

April 28, 2026

Bitcoin is at risk of liquidation of $1.4 billion if BTC rises to $80,000.

April 28, 2026

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

BitMart x $EAT Trade-to-Feed Competition Pays 4.4 Million USDT to Traders in May 2026

April 30, 2026

Crypto billionaire Justin Sun files suit against Trump-linked World Liberty Financial over ‘wrongly’ frozen tokens

April 30, 2026

VerifyVASP Acquires Sygna, Consolidating The Global Travel Rule Network

April 29, 2026
Most Popular

DIA Reconstructs Oracle Architecture with Rollup-Based ‘Lumina’

September 11, 2024

Binance Launches New ‘Make Money Wednesday’ Promotion with Exclusive Offers

November 6, 2024

‘Banks can fully provide services to Crypto customers’ -Fed Chair Jerome Powell

January 31, 2025
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2026 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.