ether.fi lost approximately 15.45 ETH after an access-control vulnerability in its AtomicQueue contract was exploited. The flaw in the solve() function allowed an attacker to use updateAtomicRequest() to create a malicious request and designate a victim address as the solver.
AtomicQueue then called the victim’s finishSolve function and executed want.transferFrom, abusing the victim’s existing ERC-20 allowance to transfer funds. SlowMist privately disclosed the issue to ether.fi before publishing the attacker address and vulnerable contract address.
ether.fi Loses 15.45 ETH in AtomicQueue Access-Control Exploit
면책 조항: Phemex 뉴스에서 제공하는 콘텐츠는 정보 제공 목적으로만 제공됩니다. 제3자 기사에서 출처를 얻은 정보의 품질, 정확성 또는 완전성을 보장하지 않습니다.이 페이지의 콘텐츠는 재무 또는 투자 조언이 아닙니다.투자 결정을 내리기 전에 반드시 스스로 조사하고 자격을 갖춘 재무 전문가와 상담하시기 바랍니다.
