ChainCatcher Message, Dilation Effect reveals on X platform that the core pool series contracts of the Venus lending protocol have been found to have a precision loss vulnerability, which is big news!😮
The specific issue lies in the redeemUnderlying function of the VToken contract, where the division precision loss when calculating redeemTokens could allow attackers to exploit it and drain funds. Especially when the protocol adds new collateral assets, if the LTV is greater than 0 and the new asset pool is empty, hackers can easily intrude.💰
Dilation Effect suggests that Venus take measures to fix the vulnerability, including rounding up in calculations or mimicking Uniswap's design, and even considering removing the redeemUnderlying interface.🔧
This incident reminds us that blockchain security should not be underestimated.🔍