Merlin Lab Performance Fee Minting Incident Analysis

Fool me once, shame on you. Fool me twice, shame on me. Fool me three times, shame on both of us.

The Exploit

How?

Why?

Use wallet balance of CAKE as the profit (performanceFee) which can be easily tampered with by just sending the CAKE token to the vault contract.

About Us

--

--

Pug against Rug

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store