Phalcon: The TrustPad protocol was attacked due to several design flaws in the staking logic
Phalcon, a trading browser, claimed on social media X (formerly Twitter) that the TrustPad protocol was attacked due to several design flaws in the staking logic, namely manipulating the locking period through external calls from untrusted sources to obtain pending rewards. In the receiveUpPool function of the LaunchpadLockableStake contract, if an account is not locked, the depositLockStart time will be set. Then the attacker manipulates it to immediately deposit (through the receiveUpPool function) and withdraw to accumulate pending rewards. In addition, another function, stakePendingRewards, allows attackers to convert accumulated pending rewards into staked amounts, allowing them to extract staking rewards in the form of TPAD tokens in future transactions and sell tokens for profit.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Evaluating Probability of Ethereum Breaching the $4K Milestone Soon
Ethereum's Potential Bull Run Versus Existing Downward Forces: The Battle for the $4K Mark
![](https://img.bgstatic.com/multiLang/image/social/a3e1b4ed5bea1a811ee9bc69e495eca01739039599124.png)
What Stage of the Bitcoin Bull are We in? Are We Nearing The End Or Are We Just Getting Started?
Which stage of the bull run are we in in Bitcoin, the world's largest cryptocurrency? Are we nearing the end of the bull run? Here is the analyst forecast.
IOTA Rebased Testnet Onboards Trusted Validators Securing Billions in Assets
![](https://img.bgstatic.com/multiLang/image/social/2e439c7d5fd5f6faef1ba09b04d7b8921739033707173.jpg)
NEAR Protocol Supports Web3 AI With New $20M Development Fund
![](https://img.bgstatic.com/multiLang/image/social/867c79bdb67f7bd61c98b9af1146badc1739033706549.png)
Trending news
MoreCrypto prices
More![Bitcoin](https://img.bgstatic.com/multiLang/coinPriceLogo/bitcoin.png)
![Ethereum](https://img.bgstatic.com/multiLang/coinPriceLogo/ethereum.png)
![Tether USDt](https://img.bgstatic.com/multiLang/coinPriceLogo/0208496be4e524857e33ae425e12d4751710262904978.png)
![XRP](https://img.bgstatic.com/multiLang/coinPriceLogo/ripple.png)
![Solana](https://img.bgstatic.com/multiLang/coinPriceLogo/solana.png)
![BNB](https://img.bgstatic.com/multiLang/coinPriceLogo/binance.png)
![USDC](https://img.bgstatic.com/multiLang/coinPriceLogo/usdc.png)
![Dogecoin](https://img.bgstatic.com/multiLang/coinPriceLogo/dogecoin.png)
![Cardano](https://img.bgstatic.com/multiLang/coinPriceLogo/cardano.png)
![TRON](https://img.bgstatic.com/multiLang/coinPriceLogo/tron.png)