Security incident · 2022-01-28
Qubit
According to the public DefiLlama incident dataset, Qubit (BSC) suffered a security incident on 2022-01-28, with about $80.0M reported lost.
| Date | 2022-01-28 |
|---|---|
| Reported loss | $80.0M |
| Chain | BSC |
| Target type | DeFi Protocol |
| Technique class | Input Validation |
| Technique | Missing Input Validation |
| Bridge incident | Yes |
| Within 2022 | #11 by loss that year, 2.2% of all reported losses that year |
How this kind of attack works
The contract did not check the parameters it received, and the attacker passed crafted data that made it do something it should not.
Would a pre-payment check have helped
Missing input validation is a contract code defect for code audits.
Other incidents with the same technique
- Portal2022-02-02 · $326.0M
- Orbit Bridge2023-12-31 · $81.7M
- Cashio2022-03-23 · $52.8M
- Hedgey2024-04-19 · $44.7M
- Transit Swap2022-10-02 · $28.9M
- ThalaSwap2024-11-15 · $25.5M

