A caller access control flaw in the GebProxyActions contract led to the theft of about 5.9436 ETH, according to monitoring cited on September 2. The issue stemmed from a user previously calling GebProxyActions.quitSystem directly instead of executing a delegated call through DSProxy, which set ownsSAFE[safe] to the GebProxyActions contract.
The attacker then directly called GebProxyActions.quitSystem(manager, safe, dst), bypassed GebSafeManager’s safeAllowed check, and transferred the collateral to their own address. The incident highlights how improper call flow and missing caller restrictions can expose user collateral to unauthorized withdrawals.
GebProxyActions Access Control Flaw Exploited for 5.94 ETH Theft
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
