Update & Correction: The second LZMultiCall incident stemmed from user misuse, not a protocol vulnerability. The design functioned as intended (see figure). The attacker exploited this user error to drain funds.

BlockSec Phalcon
@Phalcon_xyz
ALERT! Our system detected two suspicious transactions on #Ethereum hours ago exploiting arbitrary call vulnerabilities, resulting in approximately ~$205K in total losses. 1. Unknown SafeWallet (~$63K): a SafeWallet module's receiveFlashLoan() enabled attacker-controlled
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments