๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
๊ฐ€์ž… April 2018
410 ํŒ”๋กœ์ž‰ ์ค‘    90.5K ํŒฌ
๐ŸšจSlowMist TI Alert๐Ÿšจ ๐Ÿ’ธ Loss: ~24.7 ETH ๐Ÿ” Root Cause: Missing access control in order factory function `0xbde886fc` (createOrderForBuyer). It only checks `_requests[buyer].active` โ€” no `msg.sender == buyer`, no buyer signature/nonce/authorization verification, and no check on the attacker-supplied seller. The factory then calls the whitelisted account system, deducting full ETH balances from arbitrary active buyers into new order proxies. Order init writes the attacker contract into privileged storage slot 27, passing the `abort` check and draining all ETH from each proxy. ๐Ÿ“Œ Attacker EOA: `0x77071d2bbd8f3c296c8cd7d0abd21bc172420cda` ๐Ÿ“Œ Victim Contract (Account System): `0xfcf3d97c6db4c3bf6020a2b99af074b595bda163` ๐Ÿ“Œ Vulnerable Contract (Order Factory): `0xa27bcd590195b2a9bdc29379de4f040b2d8066e0` Powered by Tx:
๋” ๋ณด๊ธฐ