注册并分享邀请链接,可获得视频播放与邀请奖励。

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
加入 April 2018
410 正在关注    90.5K 粉丝
🚨SlowMist TI Alert🚨 💸 @enjin Loss: ~$162k 🔍 Root Cause: The protocol allows adapters with different storage layouts to execute in the storage context of the Managed Delegate Proxy via DELEGATECALL. However, the public initialize(uint256) function of a registered adapter writes to the adapter's slot 1, while the proxy also uses slot 1 to store pendingManager. An attacker can exploit this storage slot collision by invoking the adapter's initialize(uint256) through DELEGATECALL, causing their own address to be written into the proxy's pendingManager slot. They can then simply call acceptManager() to complete the privilege takeover and gain managerial control of the protocol. - Attacker EOA: 0x5ec1ba7892d11059c39557b762a97dd695778ca5 - Attack Contract: 0x7083ddece38216c7741fa76c75326bea744ed321 - Compromised Proxy: 0x268c039a3127d3107c014f0dc6c390a53e6db27f ⚠️ After gaining manager rights, the attacker registered a malicious adapter to steal victims' assets and routed them through `melt(0xf6089e12)` path for liquidation. Powered by Tx:
显示更多