Prefer Koin Bülteni on Google Add as source

Bot Claims Bulk of $7.8 Million rsETH Exploit in Ethereum Wallet

Approximately 2,900 rsETH, worth about $7.8 million, was drained from a Gnosis Safe wallet on Ethereum using an authorization flaw in a helper contract.

A Gnosis Safe wallet used on Ethereum was the target of an approximately 2,900 rsETH attack on Tuesday. According to reports from BlockSec, Blockaid, and SlowMist, the total value of the assets was around $7.8 million.

The wallet had authorized a helper contract to move assets for transaction automation. Such contracts are supposed to check if the caller has the necessary permissions. However, security researchers found that the check also approved calls that specified the helper contract itself as the target.

The flaw allowed the attacker to move rsETH from the wallet without the required authorization. Security firms stated that the issue did not stem from Safe’s core contracts, but rather from the Multicall component selected by the wallet owner for transaction automation.

Yoink bot front-ran the exploit

The attacker transferred the stolen rsETH to a transaction pool created just minutes before the exploit. The pool contained a worthless token named Permissionless Attacker Token. In exchange for this transaction, the wallet was left with a worthless receipt.

An automated bot known as “Yoink” paid approximately $47,000 to front-run the exploit. The bot withdrew the majority of the assets and sent 2,882 rsETH to a separate address.

AstraSec explained that the root cause of the incident was a flawed authorization check in the Multicall contract. Kelp DAO, the issuer of rsETH, stated that its contracts are secure and the asset is fully collateralized. Kelp DAO temporarily paused the suspicious address that received the rsETH for 24 hours. During this period, rsETH cannot be sent or received via that address.

Tüm gelişmelerden ve paylaşımlardan haberdar olmak için Telegram kanalımıza katılın!