๐จSlowMist TI Alert๐จ
๐ธ
@Fetch_ai Loss: ~$2M
๐ Root Cause: TokenConversionManagerV3's conversionIn() leaves single-EOA ECDSA signature as the sole authorization check. It lacks the checkLimits(amount) modifier present in conversionOut(), and does not verify any on-chain burn/lock proof. Using the leaked authorizer private key, the attacker signed a fresh message for their own address, passed the check, and drained the bridge's entire FET balance in one call.
๐ Attacker: 0x1572f2af7696b39c85e3221cde8efb640f86c362
๐ Recipient: 0x2dcc1085fdcf418b421e45e86e4e54637cc21dfe
๐ Victim/Vulnerable Contract: 0xab424a430cc09864fa1277a38193111705adf3a3
Powered by
Tx: