๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
๊ฐ€์ž… April 2018
410 ํŒ”๋กœ์ž‰ ์ค‘    90.5K ํŒฌ
๐ŸšจSlowMist TI Alert๐Ÿšจ ๐Ÿ’ธ @enjin Loss: ~$162k ๐Ÿ” Root Cause: The protocol allows adapters with different storage layouts to execute in the storage context of the Managed Delegate Proxy via DELEGATECALL. However, the public initialize(uint256) function of a registered adapter writes to the adapter's slot 1, while the proxy also uses slot 1 to store pendingManager. An attacker can exploit this storage slot collision by invoking the adapter's initialize(uint256) through DELEGATECALL, causing their own address to be written into the proxy's pendingManager slot. They can then simply call acceptManager() to complete the privilege takeover and gain managerial control of the protocol. - Attacker EOA: 0x5ec1ba7892d11059c39557b762a97dd695778ca5 - Attack Contract: 0x7083ddece38216c7741fa76c75326bea744ed321 - Compromised Proxy: 0x268c039a3127d3107c014f0dc6c390a53e6db27f โš ๏ธ After gaining manager rights, the attacker registered a malicious adapter to steal victims' assets and routed them through `melt(0xf6089e12)` path for liquidation. Powered by Tx:
๋” ๋ณด๊ธฐ