ether.fi lost approximately 15.45 ETH after an access-control vulnerability in its AtomicQueue contract was exploited. The flaw in the solve() function allowed an attacker to use updateAtomicRequest() to create a malicious request and designate a victim address as the solver.
AtomicQueue then called the victim’s finishSolve function and executed want.transferFrom, abusing the victim’s existing ERC-20 allowance to transfer funds. SlowMist privately disclosed the issue to ether.fi before publishing the attacker address and vulnerable contract address.
ether.fi Loses 15.45 ETH in AtomicQueue Access-Control Exploit
免責事項: Phemexニュースで提供されるコンテンツは、あくまで情報提供を目的としたものであり、第三者の記事から取得した情報の正確性・完全性・信頼性について保証するものではありません。本コンテンツは金融または投資の助言を目的としたものではなく、投資に関する最終判断はご自身での調査と、信頼できる専門家への相談を踏まえて行ってください。
