🚨SlowMist TI Alert🚨
💸 Loss: ~16.623 WETH
🔍 Root Cause: Selector 0x42be3129 of unverified contract 0xa317...c170 exposes an unrestricted low-level CALL, lacking access control & target/calldata validation. Attacker exploited the contract's existing ERC20 allowance to execute unauthorized transferFrom from victim.
📌 Attacker: 0xbdce6bdd52baceadd1fc91bf01f3bc6ab24df17a
📌 Victim: 0x386218744a2053d949a1cafae0b7b49a35e03f53
📌 Vulnerable Contract: 0xa31722ca2a32695280d0e7e325b3dd6d699fc170
Impact: The attacker drained the full WETH allowance (16.623 WETH) by abusing the arbitrary external call mechanism and bypassing the owner check.
Powered by
Tx: