註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
加入 April 2018
405 正在關注    88.5K 粉絲
🚨 Exploit Analysis | ShapeShift FOX Colony Authorization Trust Chain Flaw SlowMist analyzed the recent ShapeShift FOX Colony exploit on Arbitrum, where attackers abused a semantic conflict between meta-transactions and DSAuth self-call authorization to hijack the resolver and drain all ERC20 assets via malicious delegatecall. 🔍 Key Takeaways: • Arbitrary self-call in executeMetaTransaction() • DSAuth auto-trust for address(this) • Resolver hijacking through meta-tx • Full asset drain via delegatecall 🌟This incident shows how individually “reasonable” designs can combine into a complete privilege bypass chain. Developers should strictly restrict sensitive selectors in meta-transaction systems and avoid unconditional self-call authorization patterns. Full analysis👇
顯示更多