PublicAML

OMNI404 Token Exploit Results in Loss of $5,923

An exploit involving the OMNI404 token led to a loss of $5,923. The attack utilized flash loans and Uniswap V3 swaps to drain funds from the pool.

The incident involved the Ethereum ERC-404 token OMNI404 (O404), which experienced an exploit that resulted in a loss of $5,923. The attacker manipulated the mint and burn counts derived from the integer balanceOf and units differences in the _transfer() function. The transfer() function treated values less than or equal to 50 as ERC-721 IDs while still transferring a fixed amount of 1e18 units, allowing for the exploitation of the token's mechanics.

The attacker employed flash loans and executed exact-output swaps on Uniswap V3, specifically using the transfer function with varying recipient amounts. This method enabled the attacker to receive full-unit tokens while the liquidity pool recorded only minimal wei-level amounts. As a result, approximately 2.4 WETH was drained from the pool during the exploit.

Sources

Share:XTelegramLinkedIn
OMNI404 Token Exploit Results in Loss of $5,923 | PublicAML