BlockSec Phalcon has identified suspicious transactions on the Ethereum blockchain, leading to a loss of approximately $120,000. The transactions, initiated by various externally owned accounts (EOAs), targeted two unknown contracts deployed to the same address. The breach is attributed to inadequate access control on critical functions, specifically approveERC20 and withdrawAll, within the victim contract, which is not open source. The attacker exploited these vulnerabilities to drain tokens, notably using a flash loan to acquire #sil tokens before executing multiple token swaps and the final attack.