🌟 Bugs in TON again:

Peskar found a vulnerability in subscriptions and withdrew money from 400 wallets — a year and a half after deactivation.

(Subscriptions, conditionally, are a subscription to a private channel, where every month money was automatically deducted from your wallet)

👀 After #Tonviewer started displaying installed plugins in wallets, he noticed that many subscriptions were still listed as active, even though they seemed to be disabled. The plugin remains in the wallet even if the contract "self-destructed".

👃 As a result, he decided to humorously withdraw payment for subscriptions from 400 people (a year and a half later) — and it worked!

🔧 A bug was also found in the subscription smart contract. It turned out that if a user tries to turn off the subscription, the contract self-destructs, but the plugin remains in the wallet: Accordingly, someone can recreate the subscription contract and start withdrawing money again.

Another funny thing is that in #TonKeeper these payments may not be displayed in the transaction history 🌟