๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
๊ฐ€์ž… April 2018
410 ํŒ”๋กœ์ž‰ ์ค‘    90.5K ํŒฌ
๐ŸšจSlowMist TI Alert๐Ÿšจ We first reached out to the team privately to responsibly disclose the issue before making any public statement. ๐Ÿ’ธ @ether_fi Loss: ~15.45 ETH ๐Ÿ” Root Cause: `AtomicQueue.solve()` lacks access control on the caller-supplied `solver` โ€” there is no `solver == msg.sender` check, nor any signature, registration, or consent verification. The attacker first created a maliciously crafted `AtomicRequest` using the `updateAtomicRequest()` function, then forced a victim address to act as the `solver`. AtomicQueue subsequently called `finishSolve` on the victim and executed `want.transferFrom(solver, users[i], assetsToUser)`, abusing the victim's pre-existing ERC-20 allowance to drain funds. ๐Ÿ“Œ Attacker: `0xa5cc6e490bce9185fa47b421f2eac677a83b64ea` ๐Ÿ“Œ Vulnerable Contract (AtomicQueue): `0xd45884b592e316eb816199615a95c182f75dea07` Powered by Tx:
๋” ๋ณด๊ธฐ