A caller access control flaw in the GebProxyActions contract led to the theft of about 5.9436 ETH, according to monitoring cited on September 2. The issue stemmed from a user previously calling GebProxyActions.quitSystem directly instead of executing a delegated call through DSProxy, which set ownsSAFE[safe] to the GebProxyActions contract.
The attacker then directly called GebProxyActions.quitSystem(manager, safe, dst), bypassed GebSafeManager’s safeAllowed check, and transferred the collateral to their own address. The incident highlights how improper call flow and missing caller restrictions can expose user collateral to unauthorized withdrawals.
GebProxyActions Access Control Flaw Exploited for 5.94 ETH Theft
Aviso Legal: O conteúdo disponibilizado no Phemex News é apenas para fins informativos. Não garantimos a qualidade, precisão ou integridade das informações provenientes de artigos de terceiros. Este conteúdo não constitui aconselhamento financeiro ou de investimento. Recomendamos fortemente que você realize suas próprias pesquisas e consulte um consultor financeiro qualificado antes de tomar decisões de investimento.
