VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
Root cause
Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.
Forensic narrative
Vestra DAO tweeted that a hacker exploited a vulnerability in the locked staking contract, manipulating the reward mechanism to claim rewards exceeding their entitlement. As a result, a total of 73,720,000 VSTR tokens were stolen. The stolen tokens were gradually sold on Uniswap, causing approximately $500,000 in ETH liquidity losses. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 500,000.
Primary source
https://x.com/Vestra_DAO/status/1864677381459390781 ↗Sourced from
slowmist
Technical record
- chain
- —
- protocol
- Vestra DAO
- bug_class
- logic
- date_occurred
- 2024-12-04
- loss_usd
- $500,000
- source_id
- sm:vestra-dao::2024-12-04
Related — same bug class· logic