Analysis of DODO attack incidents: Lifting a "rock" and hitting your own foot?
1. Event overview
secondary title
On March 9, 2021, Beijing time, according to the public opinion monitoring of [Beosin-Eagle Eye], the wCRES/USDT fund pool on the decentralized exchange DODO seems to have been hacked , Wrapped CRES (wCRES) worth nearly $980,000 and USDT worth nearly $1.14 million were transferred. According to DODO's official reply, the team is currently investigating.
The original link is as follows:
The security team of Chengdu Beosin immediately launched a security emergency response to the incident, and sorted out the detailed analysis of the incident for reference. In fact, the incident itself is not complicated, and its attack process is also very simple. However, because the incident involved hot topics such as "flash loans" and "reentrancy attacks", Chengdu Lianan believes that it is necessary to speak out about the incident.
2. Event analysis
2. Event analysis
The main reason for the attack of this incident is that the init function of the contract is not restricted, so that the attacker has the right to call, as shown in Figure 2:
△Figure 2
image description
△Figure 3
secondary title
3. Security Recommendations
The security team of Chengdu Beosin believes that this incident is not complicated, but it is worth sounding the alarm and attracting the attention of the majority of project parties. Specifically, DODO’s flash loan function has re-entry checks, but since the init function does not add re-entry checks, similar re-entry attacks have occurred.







