⚠️ Security Warning: With the development of large-scale AI models, hackers are more efficiently scanning for vulnerabilities in legacy contracts on the EVM. Recently, attackers have successfully extracted assets from multiple contracts deployed over 6 years ago. If you authorized a contract with tokens years ago and haven't revoked it, attackers can directly call the contract to transfer your tokens if these older contracts have vulnerabilities. This process won't trigger new signature requests in your wallet, so you won't be aware of it. Hardware wallets can protect private keys, but they cannot prevent authorized contracts from transferring assets. Therefore, we recommend regularly using http:/Revoke.cash or @Rabby_io's built-in function to check and clean up unused authorizations.
This article is machine translated
Show original

deebeez
@deeberiroz
03-15
A hacker (likely LLM assisted) is exploiting old contracts on Ethereum mainnet that have signature verification logic
🧵

From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share
Relevant content




