Nani finance hacked.

Nani finance has NLP contract that can be used for uniswap v3 liquidity management.

“contribute” function of NLP contract adds uniswap v3 liquidity using some of received eth and some Nani tokens stored in itself, and then exchanges remaining eth to Nani token. Here, Nani tokens used for liquidity belong to NLP contract, not user, means if someone call “contribute” with some eth, he gains some Nani tokens for free.

Hacker called “contribute” function, and then withdraw liquidity and exchanged gained Nani to eth. Total loss is $2k.


Posted

in

by

Tags:

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *