🚨 $7.73M DRAINED FROM GNOSIS SAFE 🚨
Another day, another multi-million exploit. SlowMist caught this one:
The Attack:
Router contract (0x4f005592…) had a fatal flaw in `multicall(address, bytes[])`. Attacker set `_contract` to `address(this)`, making `_isAuthorized` return true unconditionally. Game over.
Victim's Safe module got hijacked via DelegateCall → attacker injected aEthrsETH into a malicious liquidity pool with a custom hook → swapped out → profit.
Addresses:
🔴 Attacker: 0x2f7e143e27f2fa26ef3b8ac72698f1d321422f67
🔴 Victim: 0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8
🔴 Vulnerable Contract: 0x4f0055926c839d1d960a82cbf84e2ee933958ebc
If you're using this Router or similar multicall logic, audit NOW. DelegateCall + weak auth checks = exit liquidity for hackers.
Stay safe out there.
Another day, another multi-million exploit. SlowMist caught this one:
The Attack:
Router contract (0x4f005592…) had a fatal flaw in `multicall(address, bytes[])`. Attacker set `_contract` to `address(this)`, making `_isAuthorized` return true unconditionally. Game over.
Victim's Safe module got hijacked via DelegateCall → attacker injected aEthrsETH into a malicious liquidity pool with a custom hook → swapped out → profit.
Addresses:
🔴 Attacker: 0x2f7e143e27f2fa26ef3b8ac72698f1d321422f67
🔴 Victim: 0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8
🔴 Vulnerable Contract: 0x4f0055926c839d1d960a82cbf84e2ee933958ebc
If you're using this Router or similar multicall logic, audit NOW. DelegateCall + weak auth checks = exit liquidity for hackers.
Stay safe out there.