<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=IVest_DAO_Smart_Contract_Transfer_Vulnerability</id>
	<title>IVest DAO Smart Contract Transfer Vulnerability - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=IVest_DAO_Smart_Contract_Transfer_Vulnerability"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=IVest_DAO_Smart_Contract_Transfer_Vulnerability&amp;action=history"/>
	<updated>2026-05-01T14:36:42Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=IVest_DAO_Smart_Contract_Transfer_Vulnerability&amp;diff=6171&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/ivestdaosmartcontracttransfervulnerability.php}} {{Unattributed Sources}}  iVest DAO Logo/HomepageThe iVest DAO is a community equity and investment ecosystem. They provide a source of passive income for holders of the token. An exploit was present in their smart contract which allowed an attacker to profit by donating funds to a burn address. A significant am...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=IVest_DAO_Smart_Contract_Transfer_Vulnerability&amp;diff=6171&amp;oldid=prev"/>
		<updated>2024-09-25T20:25:24Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/ivestdaosmartcontracttransfervulnerability.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Ivestdao.jpg&quot; title=&quot;File:Ivestdao.jpg&quot;&gt;thumb|iVest DAO Logo/Homepage&lt;/a&gt;The iVest DAO is a community equity and investment ecosystem. They provide a source of passive income for holders of the token. An exploit was present in their smart contract which allowed an attacker to profit by donating funds to a burn address. A significant am...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/ivestdaosmartcontracttransfervulnerability.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Ivestdao.jpg|thumb|iVest DAO Logo/Homepage]]The iVest DAO is a community equity and investment ecosystem. They provide a source of passive income for holders of the token. An exploit was present in their smart contract which allowed an attacker to profit by donating funds to a burn address. A significant amount was drained from the smart contract. The team has yet to acknowledge the exploit or prepare any path forward.&amp;lt;ref name=&amp;quot;slowmisthackedarchive-14883&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;slowmistteamtwitter-14884&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;bscscan-14885&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ivestfinance-14886&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ivestfinance-14887&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;bscscan-14888&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;olympixaitwitter-14889&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;bscscan-14890&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;anciliainctwitter-14891&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;exvulsectwitter-14892&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;quillauditsaitwitter-14893&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About iVest DAO ==&lt;br /&gt;
&amp;quot;The iVest DAO is a bootstrapping web3 powered decentralized community equity &amp;amp; investment ecosystem.&lt;br /&gt;
&lt;br /&gt;
We combine SocialFi and DAO governance with unique tokenomics to support our members and create thriving community projects.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Grassroots Fair Launch. No Pre-Sale, No Dev Tokens, No ICO, No Referrals. Launched with 100% community donated liquidity.&lt;br /&gt;
&lt;br /&gt;
Fees collected from transactions and DAO related activities are shared as rewards to token holders and DAO contributors.&lt;br /&gt;
&lt;br /&gt;
The combined effects of the Vesting Pool and fee schedule promotes an antifragile, deflationary ecosystem.&lt;br /&gt;
&lt;br /&gt;
Holders passively earn more tokens while iVEST circulating supply dwindles... Sellers wait for locked tokens to exit their position smoothing price action, limiting dumps, panic &amp;amp; manipulation.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;iVest DAO was attacked due to a smart contract vulnerability, resulting in a loss of approximately $172,000.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - iVest DAO Smart Contract Transfer Vulnerability&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|August 11th, 2024 10:52:39 PM MDT&lt;br /&gt;
|Blockchain Transaction&lt;br /&gt;
|The blockchain transaction which attacks the iVest DAO, according to Olympix and Ancilia, Inc.&lt;br /&gt;
|-&lt;br /&gt;
|August 11th, 2024 11:38:00 PM MDT&lt;br /&gt;
|Ancilia Inc. Tweet Posted&lt;br /&gt;
|Ancilia posts a tweet with details of the transaction and&lt;br /&gt;
|-&lt;br /&gt;
|August 12th, 2024 12:41:17 AM MDT&lt;br /&gt;
|Blockchain Transaction&lt;br /&gt;
|The blockchain transaction which attacks the iVest DAO, according to QuillAudits.&lt;br /&gt;
|-&lt;br /&gt;
|August 12th, 2024 12:52:00 AM MDT&lt;br /&gt;
|SlowMist Tweets&lt;br /&gt;
|SlowMist tweets to report about &amp;quot;suspicious activity&amp;quot;. in this smart contract. No transaction ID is provided.&lt;br /&gt;
|-&lt;br /&gt;
|August 12th, 2024 1:46:00 AM MDT&lt;br /&gt;
|ExVul Tweet&lt;br /&gt;
|ExVul tweets to report on the malicious transaction further.&lt;br /&gt;
|-&lt;br /&gt;
|August 12th, 2024 3:14:00 AM MDT&lt;br /&gt;
|Olympix Tweet&lt;br /&gt;
|The Olympix team tweets to report about the malicious transaction.&lt;br /&gt;
|-&lt;br /&gt;
|August 12th, 2024 3:48:00 AM MDT&lt;br /&gt;
|QuillAudits Tweet Post&lt;br /&gt;
|QuillAudits posts an description of the exploit and transactions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;The exploit centers around a vulnerability in the token contract’s transfer function.&lt;br /&gt;
&lt;br /&gt;
The transfer function contains flawed logic: when tokens are transferred to the burn address (0x0), the sender’s balance is incorrectly reduced by double the intended amount.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The attacker took advantage of this by transferring iVest tokens to a Uniswap pair and then calling skim(0x0) and sync().&lt;br /&gt;
&lt;br /&gt;
Due to the flawed transfer logic, the pair’s balance was drastically reduced.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;By repeatedly exploiting this flaw, the attacker managed to drain the liquidity pool, resulting in the loss of $156,309.94.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;root case is wrong implement of _transfer 0 address, when transfer to 0 addrees, `makeDonation` funciton will be called , and decrease  part of sender  token amounts, the issue is when call `skim` , pancke  pair  amount will decrease, this will increase the value of  `iVest Token` ,attacker call multiple times  skim and  then swap to drain  pair weth&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
QuillAudits: $156,309.94&lt;br /&gt;
Olympix: $172,000&lt;br /&gt;
ExVul: $205,153&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $172,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
The iVest team does not appear to have even acknowledged the exploit yet.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The total amount recovered is unknown.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;slowmisthackedarchive-14883&amp;quot;&amp;gt;[https://web.archive.org/web/20240812161233/https://hacked.slowmist.io/ SlowMist Hacked - SlowMist Zone] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;slowmistteamtwitter-14884&amp;quot;&amp;gt;[https://twitter.com/SlowMist_Team/status/1822888837670113330 @SlowMist_Team Twitter] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;bscscan-14885&amp;quot;&amp;gt;[https://bscscan.com/address/0x786fcf76dc44b29845f284b81f5680b6c47302c6 iVESTDAO | Address 0x786fcf76dc44b29845f284b81f5680b6c47302c6 | BscScan] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ivestfinance-14886&amp;quot;&amp;gt;[https://ivest.finance/ iVest.finance] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ivestfinance-14887&amp;quot;&amp;gt;[https://ivest.finance/media/litepaper.pdf https://ivest.finance/media/litepaper.pdf] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;bscscan-14888&amp;quot;&amp;gt;[https://bscscan.com/tx/0xeba52e500394fe8916dd9f6404603f317c7a659392bf599e61a6b5a284fcc0db BNB Smart Chain Transaction Hash (Txhash) Details | BscScan] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;olympixaitwitter-14889&amp;quot;&amp;gt;[https://twitter.com/Olympix_ai/status/1822924631046545491 @Olympix_ai Twitter] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;bscscan-14890&amp;quot;&amp;gt;[https://bscscan.com/tx/0x12f27e81e54684146ec50973ea94881c535887c2e2f30911b3402a55d67d121d BNB Smart Chain Transaction Hash (Txhash) Details | BscScan] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;anciliainctwitter-14891&amp;quot;&amp;gt;[https://twitter.com/AnciliaInc/status/1822870201698050064 @AnciliaInc Twitter] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;exvulsectwitter-14892&amp;quot;&amp;gt;[https://twitter.com/EXVULSEC/status/1822902541367333017 @EXVULSEC Twitter] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;quillauditsaitwitter-14893&amp;quot;&amp;gt;[https://twitter.com/quillaudits_ai/status/1822933244943253888 @quillaudits_ai Twitter] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>