๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
๊ฐ€์ž… April 2018
408 ํŒ”๋กœ์ž‰ ์ค‘    88.8K ํŒฌ
๐ŸšจSlowMist TI Alert๐Ÿšจ ๐Ÿ’ธ @Lumi_Finance Loss: ~ $264k ๐Ÿ” Root Cause: A vulnerability in Lumi smart accounts allowed token approvals to be performed as a side effect during UserOperation validation. Due to improper validation logic, an attacker-controlled paymaster could trigger approval operations during the validation phase and obtain ERC20 allowances from multiple smart accounts without explicit user intent. ๐Ÿ“Œ Attacker: 0xce1a3bb0b98d0d90c7dd0620ab86c9a771888d88 ๐Ÿ“Œ Victim: Multiple Lumi smart accounts affected by unintended token approvals during UserOp validation ๐Ÿ“Œ Malicious contract: 0x56362412ae17cac443aafbab4289946ad958e8a1 The attacker abused a flaw in Lumi smart account UserOperation validation logic to obtain token allowances from multiple wallets through validation-time side effects. The attacker then used the malicious sweeping contract to batch drain approved ERC20 tokens, swapped the stolen assets into ETH, and transferred the proceeds to the attacker-controlled address. Powered by #SlowMist#.AI Tx:
๋” ๋ณด๊ธฐ