As per ChainSecurity, post-Constantinople upgrade, the functions “address.transfer(….)” & “address.send(….) are susceptible to attack in Solidity smart contracts. Employing these functions, a malicious attacker can call an attack function on his individual smart contract and slip other user’s ETHs out of the contract.
Read the details in the article of Coinidol dot com, the world blockchain news outlet: https://coinidol.com/chainsecurity-reve ... e-upgrade/
