Home > Quick > Body

Beosin:LI.FI攻击者利用项目合约的call注入将授权给合约的用户资产转走

clock
2024-07-16 15:40:30
据Beosin Alert监控预警发现,跨链协议LI.FI遭受攻击,Beosin安全团队发现漏洞原因是攻击者利用项目合约的call注入将授权给合约的用户资产转移走。LI.FI项目合约存在一个depositToGasZipERC20函数,可将指定代币兑换为平台币并存入GasZip合约,但是在兑换逻辑处的代码未对call调用的数据进行限制,导致攻击者可利用此函数进行call注入攻击,提取走给合约授权用户的资产。
攻击者地址:0x8B....DcF3。被攻击合约:0x1231....F4EaE。
Disclaimer:
1. The information provided does not constitute investment advice. Investors should make independent decisions and bear all risks themselves.
2. The copyright of this content belongs to the original author. The views expressed herein are solely those of the author and do not represent the stance or position of this website.
New Tab Page - Desk3 | Plugin
Stay ahead of the game in the cryptocurrency space.