ether.fi lost approximately 15.45 ETH after an access-control vulnerability in its AtomicQueue contract was exploited. The flaw in the solve() function allowed an attacker to use updateAtomicRequest() to create a malicious request and designate a victim address as the solver.
AtomicQueue then called the victim’s finishSolve function and executed want.transferFrom, abusing the victim’s existing ERC-20 allowance to transfer funds. SlowMist privately disclosed the issue to ether.fi before publishing the attacker address and vulnerable contract address.
ether.fi Loses 15.45 ETH in AtomicQueue Access-Control Exploit
Отказ от ответственности: Контент, представленный на сайте Phemex News, предназначен исключительно для информационных целей.Мы не гарантируем качество, точность и полноту информации, полученной из статей третьих лиц.Содержание этой страницы не является финансовым или инвестиционным советом.Мы настоятельно рекомендуем вам провести собственное исследование и проконсультироваться с квалифицированным финансовым консультантом, прежде чем принимать какие-либо инвестиционные решения.
