<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sam Sun on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/sam-sun/</link><description>Recent content in Sam Sun on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2020 07:00:03 -0400</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/sam-sun/index.xml" rel="self" type="application/rss+xml"/><item><title>Accidentally stepping on a DeFi lego</title><link>https://miscreants.github.io/blog.trailofbits.com/2020/08/05/accidentally-stepping-on-a-defi-lego/</link><pubDate>Wed, 05 Aug 2020 07:00:03 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2020/08/05/accidentally-stepping-on-a-defi-lego/</guid><description>The initial release of yVault contained logic for computing the price of yUSDC that could be manipulated by an attacker to drain most (if not all) of the pool’s assets. Fortunately, Andre, the developer, reacted incredibly quickly and disabled the faulty code, securing the approximately 400,000 USD held at the time. However, this bug still […]</description></item></channel></rss>