SIR Protocol Exploit: Analyzing the Transient Storage Vulnerability

Summary
About SIR Trading
Initial Reporting and Founder Reaction
Major Addresses Involved
Prerequisite Knowledge
Decoding the Exploit


uniswapV3SwapCallback to bypass pool verification in the Vault (Victim Contract) via transient storage manipulation. This enabled the minting of tokens and granted Token A contract, which was the full transactional control during the exploit.
On-Chain Activity


Timeline and Breakdown
30 January 2025 at 6:18 UTC


30 January 2025 at 6:21 UTC






January 30 2025 at 6:25 UTC

Cohort Analysis

Conclusion

0x0ffcbb86700e0ebb5ee0c3fd46b81c943a5027cc68738cbb17d364f893f31018
Last updated
