KiloEx’s summary of the hacking incident: a bug in the TrustedForwarder contract led to the attack

avatar
MarsBit
04-21
This article is machine translated
Show original
Mars Finance News: According to KiloEx's analysis and post-event summary of the hacking incident, the root cause was that the TrustedForwarder contract in their smart contract inherited OpenZeppelin's MinimalForwarderUpgradeable but did not override the execute method, allowing the function to be called arbitrarily. The attack occurred from 18:52 to 19:40 UTC on April 14, with the hacker deploying attack contracts across multiple chains including opBNB, Base, BSC, Taiko, B2, and Manta. After negotiations, the hacker agreed to keep 10% of the bounty and has returned all stolen assets (including USDT, USDC, ETH, BNB, WBTC, and Dai) to the multi-signature wallet designated by KiloEx.

Source
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
1
Add to Favorites
Comments