Internet Token DAO Exploited for $265,000 in LiquidityUnifier Incident
Internet Token DAO's LiquidityUnifier was exploited, resulting in a significant loss. The attacker manipulated a Uniswap V3 pool address to mint a large amount of INT tokens.
Internet Token DAO's LiquidityUnifier was exploited when it relied on a caller-supplied Uniswap V3 pool address. This vulnerability allowed the attacker to execute a fake pool callback that minted approximately 925 million INT tokens. As a result, the attacker drained 5.847 WETH, valued at about $16,033.55, from the official INT/WETH pool and retained around 764 million INT tokens for themselves.
The exploit occurred due to the mint role not being revoked in a timely manner, which enabled the attacker to inflate the total supply of INT tokens to about 156 billion through copycat exploits. Following the incident, the attacker submitted a governance proposal with the intention of moving treasury funds, further complicating the situation for the Internet Token DAO. The specific blockchain on which this incident occurred is not stated, limiting the ability to trace the transactions directly.
The on-chain record indicates that a significant amount of INT tokens was minted without backing, leading to a drastic increase in supply. This incident raises concerns about the governance and security measures in place for the Internet Token DAO's liquidity mechanisms.
