People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!
Popsicle Finance Post Mortem- After Fragola Hack- 899
A big part of DeFi is rewarding those who put up their assets to be used. This is rewards distribution, yield... it has many words.
A user should be paid based upon their entry date rather than the first day money is put down. This rewards people staying around and keeping their funds in play.
Popsicle Finance doesn't transfer the debt when users transfer their shares to a different account. This allows for the claiming of share rewards for multiple shares over and over again.
Apparently, this bug has occurred several other times as well. The author points out WildCredit as an example of this as well.
Overall, interesting bug! Will confirm that all variables are updated when moving assets from account to account.