A caller access control flaw in the GebProxyActions contract led to the theft of about 5.9436 ETH, according to monitoring cited on September 2. The issue stemmed from a user previously calling GebProxyActions.quitSystem directly instead of executing a delegated call through DSProxy, which set ownsSAFE[safe] to the GebProxyActions contract.
The attacker then directly called GebProxyActions.quitSystem(manager, safe, dst), bypassed GebSafeManager’s safeAllowed check, and transferred the collateral to their own address. The incident highlights how improper call flow and missing caller restrictions can expose user collateral to unauthorized withdrawals.
GebProxyActions Access Control Flaw Exploited for 5.94 ETH Theft
Отказ от ответственности: Контент, представленный на сайте Phemex News, предназначен исключительно для информационных целей.Мы не гарантируем качество, точность и полноту информации, полученной из статей третьих лиц.Содержание этой страницы не является финансовым или инвестиционным советом.Мы настоятельно рекомендуем вам провести собственное исследование и проконсультироваться с квалифицированным финансовым консультантом, прежде чем принимать какие-либо инвестиционные решения.
