According to Foresight News , according to monitoring by Beosin's EagleEye, the Socket protocol suffered a call injection attack, resulting in the theft of a large number of authorized user funds. This attack is mainly due to unsafe call calls in the performAction function of the Socket contract. The attacker constructs calldata and calls the transferfrom of any token to transfer the tokens authorized by other users to the contract to the attacker's address. The attacker has currently converted the stolen funds into 1,137 Ethereum (approximately $2.91 million).
Beosin: The reason why Socket was attacked was that there was an unsafe call in the contract’s performAction function.
This article is machine translated
Show original
Sector:
Source
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share
Relevant content