@DoinGudHQ hacked for ~$35K USDC
Rootcause: bids to be reusable - in acceptBid(bidder, id, price, qty), there are no SSTOREs other than for the reentrancy guard - the bid payout runs, but the bid record is never cleared.
This meant anyone could flash loan USDC equal to the contract's balance, place a bid on themselves, and accept it twice - draining the contract. @EthSecurity1
Post #423628
380
Forwarded from EthSecurity
