🚨SlowMist TI Alert🚨
We first reached out to the team privately to responsibly disclose the issue before making any public statement.
💸
@ether_fi Loss: ~15.45 ETH
🔍 Root Cause: `AtomicQueue.solve()` lacks access control on the caller-supplied `solver` — there is no `solver == msg.sender` check, nor any signature, registration, or consent verification. The attacker first created a maliciously crafted `AtomicRequest` using the `updateAtomicRequest()` function, then forced a victim address to act as the `solver`. AtomicQueue subsequently called `finishSolve` on the victim and executed `want.transferFrom(solver, users[i], assetsToUser)`, abusing the victim's pre-existing ERC-20 allowance to drain funds.
📌 Attacker: `0xa5cc6e490bce9185fa47b421f2eac677a83b64ea`
📌 Vulnerable Contract (AtomicQueue): `0xd45884b592e316eb816199615a95c182f75dea07`
Powered by
Tx: