A caller access control flaw in the GebProxyActions contract led to the theft of about 5.9436 ETH, according to monitoring cited on September 2. The issue stemmed from a user previously calling GebProxyActions.quitSystem directly instead of executing a delegated call through DSProxy, which set ownsSAFE[safe] to the GebProxyActions contract.
The attacker then directly called GebProxyActions.quitSystem(manager, safe, dst), bypassed GebSafeManager’s safeAllowed check, and transferred the collateral to their own address. The incident highlights how improper call flow and missing caller restrictions can expose user collateral to unauthorized withdrawals.
GebProxyActions Access Control Flaw Exploited for 5.94 ETH Theft
Sorumluluk Reddi: Phemex Haberler'de sunulan içerik yalnızca bilgilendirme amaçlıdır. Üçüncü taraf makalelerden alınan bilgilerin kalitesi, doğruluğu veya eksiksizliğini garanti etmiyoruz. Bu sayfadaki içerik finansal veya yatırım tavsiyesi niteliği taşımaz. Yatırım kararları vermeden önce kendi araştırmanızı yapmanızı ve nitelikli bir finans danışmanına başvurmanızı şiddetle tavsiye ederiz.
