manifoldfinance / defi-threat

a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations on decentralized finance
Mozilla Public License 2.0
485 stars 53 forks source link

Donation Attacks used in price manipulation #29

Open sambacha opened 9 months ago

sambacha commented 9 months ago

Price Manipulation via Donation Attacks

example from CREAM Finance attack

Here is the exploit: donate double existing amount yUSD to yUSD Vault. This doubles the value of yUSD so crYUSD collateral have doubled in value

https://github.com/Crypto-Virus/cream-finance-exploit-example/blob/master/contracts/Attack.sol