ton-blockchain / bug-bounty

TON security bug bounty description
115 stars 9 forks source link

decimals hide #18

Open u1tran opened 3 weeks ago

u1tran commented 3 weeks ago

When you mint token with 2 decimals it will be 1.00, if you later decided to get more digits, then tokens q may looks like: decimals 3: 0.101 decimals 5: 0.00101 It will change past transactions, change number of digits in portfolio in other side 10.00, 1000.00, etc.! image image and pools stay same

I think this bug may be used to hide past over transactions or delete them at all from visible code

u1tran commented 3 weeks ago

dup lol, but have no actual cost on somewhere. IMG_3696

u1tran commented 3 weeks ago

it is mean nothing

u1tran commented 3 weeks ago

I think better to set attention message near editable decimals field about problems that may be when this number change. This number change and actions to avoid this unwanted protocol interpretation. For example it may be: Close all liquidity pools, Close deposit and withdrawals, bye actions like P2P... I think nobody even think about this shit - better to automatizare some prepare actiobs. meow