VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
Root cause
Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.
Forensic narrative
Bullran Index was attacked due to a lack of permission control. An MEV bot was able to burn the BUI tokens that a user deposited into a custom safe contract and exploit the lack of permission control to extract 136 ETH. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 310,000.
Primary source
https://x.com/tonyke_bot/status/1749489858807230734 ↗Sourced from
slowmist
Technical record
- chain
- —
- protocol
- Bullran Index
- bug_class
- logic
- date_occurred
- 2024-01-22
- loss_usd
- $310,000
- source_id
- sm:bullran-index::2024-01-22
Related — same bug class· logic