DexibleApp aggregator hacked for $2M via 'selfSwap' function

DexibleApp aggregator hacked for $2M via 'selfSwap' function

full version at cointelegraph

The buggy function was intended to allow users to provide their own routing information, but the code did not limit routers to a pre-approved list.

Recent conversions

800000 COP to EUR 3000 BTC to CAD 5000 BTC to NZD 1 AXS to PHP 0.043 ETH to BTC 15 REAL to GBP 70 ETH to USD 2100 THB to AUD 0.023 BTC to USD 69.5 ETH to EUR 1.2 SOL to NZD