vielite's blog

vielite

offensive security researcher and CTF player with the infobahn ctf team . Actively finding vulnerabilities in decentralized systems, also recognised by Hexens as a top Glider security researcher. welcome to my blog

Glider queries

Broken CEI pattern with token transfers in ERC1155/ERC721 contracts
Broken CEI pattern with token transfers in ERC1155/ERC721 contracts

Finds ERC721/ERC1155 entry points that perform NFT transfers before critical effects are finalized, surfacing CEI violations that can expose unstake, redeem, claim, or withdraw flows to receiver-hook reentrancy and inconsistent state.

ethereum re-entrancy rare
Pyth oracle prices are not validated for freshness
Pyth oracle prices are not validated for freshness

Flags code paths that call standard Pyth oracle functions without checking freshness or validating timestamps.

ethereum oracles rare

Bugs