đš $7.73M DRAINED FROM GNOSIS SAFE đš
Another day, another multi-million exploit. SlowMist caught this one:
The Attack:
Router contract (0x4f005592âŠ) had a fatal flaw in `multicall(address, bytes[])`. Attacker set `_contract` to `address(this)`, making `_isAuthorized` return true unconditionally. Game over.
Victim's Safe module got hijacked via DelegateCall â attacker injected aEthrsETH into a malicious liquidity pool with a custom hook â swapped out â profit.
Addresses:
đŽ Attacker: 0x2f7e143e27f2fa26ef3b8ac72698f1d321422f67
đŽ Victim: 0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8
đŽ Vulnerable Contract: 0x4f0055926c839d1d960a82cbf84e2ee933958ebc
If you're using this Router or similar multicall logic, audit NOW. DelegateCall + weak auth checks = exit liquidity for hackers.
Stay safe out there.
Another day, another multi-million exploit. SlowMist caught this one:
The Attack:
Router contract (0x4f005592âŠ) had a fatal flaw in `multicall(address, bytes[])`. Attacker set `_contract` to `address(this)`, making `_isAuthorized` return true unconditionally. Game over.
Victim's Safe module got hijacked via DelegateCall â attacker injected aEthrsETH into a malicious liquidity pool with a custom hook â swapped out â profit.
Addresses:
đŽ Attacker: 0x2f7e143e27f2fa26ef3b8ac72698f1d321422f67
đŽ Victim: 0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8
đŽ Vulnerable Contract: 0x4f0055926c839d1d960a82cbf84e2ee933958ebc
If you're using this Router or similar multicall logic, audit NOW. DelegateCall + weak auth checks = exit liquidity for hackers.
Stay safe out there.