A caller access control flaw in the GebProxyActions contract led to the theft of about 5.9436 ETH, according to monitoring cited on September 2. The issue stemmed from a user previously calling GebProxyActions.quitSystem directly instead of executing a delegated call through DSProxy, which set ownsSAFE[safe] to the GebProxyActions contract.
The attacker then directly called GebProxyActions.quitSystem(manager, safe, dst), bypassed GebSafeManager’s safeAllowed check, and transferred the collateral to their own address. The incident highlights how improper call flow and missing caller restrictions can expose user collateral to unauthorized withdrawals.
GebProxyActions Access Control Flaw Exploited for 5.94 ETH Theft
Avertissement : Le contenu proposé sur Phemex News est à titre informatif uniquement. Nous ne garantissons pas la qualité, l'exactitude ou l'exhaustivité des informations provenant d'articles tiers. Ce contenu ne constitue pas un conseil financier ou d'investissement. Nous vous recommandons vivement d'effectuer vos propres recherches et de consulter un conseiller financier qualifié avant toute décision d'investissement.
