An attacker exploited a critical signature flaw in GiddyDefi's GiddyVaultV3, replaying a valid signature with swapped parameters to drain $1.3M in staked LP tokens.
TX: 0x5edb…82e5
EXPLANATION:
The vault's signature verification only checked the data bytes inside each SwapInfo struct, ignoring critical fields like the aggregator address, token addresses and amount. The attacker took a legitimate signed transaction, replaced the aggregator with their own malicious contract, swapped the tokens for the vault's staked LP tokens, and set the amount to MAX_UINT256 to drain everything. The signature was valid, the vault approved it, funds gone.
Another audit that missed the obvious. 👇
🔔 @Observer • 💬 Join community • 🌟 HighQuality OTC
