GoPlus: ListaDAO's liquidity staking vault was attacked, and the attacker exploited a logical vulnerability to steal funds

By: rootdata|2026/04/16 22:42:02
0
Share
copy

GoPlus Security released an analysis stating that the Liquid Staking Vault contract of ListaDAO was attacked due to a business logic flaw. The attacker triggered the share calculation function of the Dividend contract when transferring specific tokens, which affected the reward distribution logic of the staking vault, ultimately stealing a large amount of assets from the contract.

GoPlus Security reminds that this logical vulnerability exists in both the Liquid Staking Vault and Dividend contracts, and any fork or reused implementation carries a high risk of being exploited. Developers and projects are strongly advised to conduct reviews and fix the vulnerabilities accordingly. Smart contract security should not rely on "one-time audits."

-- Price

--

You may also like

Contents

Popular coins

Latest Crypto News

Read more