PublicAML

DoinGud NFT Platform Exploited for $35,486 via Bug

The NFT platform DoinGud was exploited for $35,486 due to a bug in its bidding contract.

The dormant NFT platform DoinGud was exploited through a vulnerability in its Diamond bidding contract. The bug allowed the acceptBid function to pay out without clearing the bid record, enabling the same bid to be reused. An attacker utilized a flash loan to acquire USDC equivalent to the contract balance, then bid on themselves and accepted the bid twice, draining approximately $35,486 USDC from the platform.

The incident occurred on the Polygon network, which indicates that the transactions and activities related to the exploit can be traced on this blockchain. The mechanism of the attack involved leveraging the bug in the bidding process, which allowed for the manipulation of bids without proper record management. This exploitation highlights the risks associated with smart contract vulnerabilities in decentralized applications.

Sources

Share:XTelegramLinkedIn
DoinGud NFT Platform Exploited for $35,486 via Bug | PublicAML