Mirror Protocol was susceptible to one of the most profitable exploits ever
twitter.com
twitter.com
Do the people setting up these platforms not automatically check for these flaws? Static code analysis has come a long way for normal programming languages and a cursory Google search comes up with at least 4 analysers and 2 fuzzers for these things. Are these tools not mature enough or did the devs simply neglect to run them?
Amusing to see that the developers so quietly patched it. I do wonder if they noticed the exploit themselves or were informed of it by an interested third party.