abi.encodePacked of multiple variable-length arguments can produce identical byte strings for different inputs (e.g. ['a','bc'] vs ['ab','c']), enabling hash collisions in signatures, Merkle leaves, or commitments.
bytes32 id = keccak256(abi.encode(name, symbol)); // length-safe
Largest recorded losses in the same failure class — related, not the same bug:
The SaferICO scanner runs 201 detectors over your Solidity source, SAFE-0048 among them. Paste an address or the source itself — a small per-scan fee, shown before you sign, or unlimited on any plan.