🚨SlowMist TI Alert🚨
💸 Unknown Gnosis Safe wallet Loss: ~$7.73M
🔍 Root Cause: In the `multicall(address, bytes[])` function of the Router contract (address `0x4f005592…`), the `_contract` parameter could be set to `address(this)`. Consequently, the `_isAuthorized` function—used for internal permission checks—would unconditionally return true. This allowed the victim Safe module contract to execute attacker-crafted malicious call data via `DelegateCall`, injecting aEthrsETH into an attacker-created liquidity pool equipped with a hook; the assets were subsequently swapped and redeemed for profit.
📌 Attacker: 0x2f7e143e27f2fa26ef3b8ac72698f1d321422f67
📌 Victim: 0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8
📌 Vulnerable Contract: 0x4f0055926c839d1d960a82cbf84e2ee933958ebc
Txs:
Powered by