๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
๊ฐ€์ž… April 2018
410 ํŒ”๋กœ์ž‰ ์ค‘    89.8K ํŒฌ
๐ŸšจSlowMist TI Alert๐Ÿšจ ๐Ÿ’ธ @nimiq Loss: ~$50,463 ๐Ÿ” Root Cause: ERC20PermitHTLCHandler's `execute()` discards all five calldata parameters (including signature & nonce) and performs no EIP-712 signature, nonce, or business pre-check. The only signature/nonce validation lived in its `preRelayedCall()`, but GSN RelayHub calls `preRelayedCall` on the attacker-specified paymaster. So the attacker set himself as paymaster, fully bypassing that check, used 1 MATIC GSN relay registration to pass `onlyRelayHub` and forged `request.from = victim`, causing `openPrivate()` to call `token.transferFrom(victim, handler, full balance)`. Finally, the attacker directly called the `redeem` function to withdraw these funds using the hosted secret they had crafted. ๐Ÿ“Œ Attacker: 0x2258491525C21f334c5a2dc22CE55e55023FC45D ๐Ÿ“Œ Victim: 0x24Cb173Ae221AeA93369f34bdcF0Ddb35b436773 ๐Ÿ“Œ Vulnerable Contract: 0x0cFD862bE942846Cebad797d7c1BC6e47714959b, 0xf615bd7eA00C4Cc7F39fAAD0895Db5f40891359f Powered by Tx:
๋” ๋ณด๊ธฐ