We take care of our community's safety and put many resources to prevent any mistakes in contracts. There is no risk for funds in the Unit protocol, and the COL token is safe. Everything works as planned so far.
We have reviewed the community proposal (Pink Duck: An implementation for vastly superior memonomics and quackonomy) and found a critical bug in it: https://github.com/banteg/pink-duck/blob/master/contracts/Duck.vy#L60-L63
There is a vulnerability in the contract Duck.vy
The attack vector is provided below
1. User deposits his total COL balance to Duck.vy contract calling quack_quack function and receives divided by 100 amount of DUCK's
2. User transfers the minted DUCK's to another address leaving 1e-18 DUCK's on his balance
3. User withdraws previously packed COL amount calling pussy_out function, the contract burns the dust of DUCK on the user's balance
The packed COL is redeemed for the dust of DUCK
All of the previously minted DUCK's stays on another address except the burned dust.
We can't risk compromising our users' safety, and soon we will make the community vote about token rebranding. Be good duck - be alive duck. Stay quacking safe.
Post #61
1.4K