If this research helped you, please consider giving it a ⭐ Star.
Found this research useful?
- Star ⭐ this repo to keep track of it.
- Follow me on GitHub for more DeFi security research.
- Fork it if you want to run your own experiments.
If you appreciate the work and want to support further security research:
Wallet Address (ETH/EVM): 0xBDDD7973D0DE27B715A4A5cbdb87d0DF78757b3A
This repository contains a PoC for Business Logic Corruption identified on Backpack Exchange. The vulnerability stems from exposing production Amplitude API keys on the client-side.
An attacker can use this key to:
- Pollute Analytics Data: Inject thousands of fake "Deposit" or "Trade" events.
- Sabotage Marketing: Destroy the integrity of Conversion Rates, CAC, and LTV metrics.
- Internal Chaos: Lead the product team to make wrong decisions based on corrupted data dashboards.
pip install requests
python exploit_amplitude.py