DimonCoin(FUD), ERC20 token, allows... CVE-2018–11411

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Abstract I found a vulnerability of a smart contract for DimonCoin(FUD), an Ethereum ERC20 token (CVE-2018–11411)[1]. This vulnerability is exactly same with the UselessEthereumToken’s vulnerability[2, 3]. DimonCoin token also has the same vulnerable function which is transferFrom in UET token. Therefore, attackers can steal all victim’s balances into their accounts by exploiting this function. After more investigation, I found that DimonCoin(FUD) is a scam. There are multiple smart contracts of FUD token, and one of them has been dumped. I found the vulnerability in the different contract which is not dumped yet. In this article, I will explain the details of the vulnerability and the FUD token. ### Details As mentioned above, this vulnerability is same with the vulnerability of UselessEthereumToken (CVE-2018–10468)[3]. If you read the article “UselessEthereumToken(UET), ERC20 token, allows attackers to steal all victim’s balances (CVE-2018–10468)”, it will be helpful to...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息