A staking contract named “OTSeaStaking” exploited, lost $26k.
Hacker called “withdraw” several times, got much more OTSea tokens than he staked. In “withdraw” function, deposit.amount is not decreased. Anyone can deposit once and withdraw multiple times.
Leave a Reply