ChainCatcher report: Blockchain security firm SlowMist tweeted that the Diamond contract associated with Aurellion Labs was compromised due to an unprotected `initialize(address)` function in the SafeOwnable Facet. The attacker re-entered the initialization function to alter the contract owner and executed a `diamondCut` to inject a malicious Facet containing `pullERC20`, thereby transferring authorized USDC assets. SlowMist identified affected contract addresses including 0x0adc63e7… (victim contract), 0x2e933518…, 0xa90714a1…, and 0xeced2d37…, with the attacker’s address being 0x9f49591a3b…, resulting in an estimated loss of approximately 455,003 USDC.
Aurellion Labs contract hacked via reentrancy, resulting in the loss of 455,003 USDC.
ChaincatcherShare






Aurellion Labs suffered a reentrancy attack on its Diamond contract, resulting in the loss of 455,003 USDC. SlowMist reported that the exploit utilized an unprotected `initialize(address)` function in the SafeOwnable Facet to transfer ownership and inject a malicious Facet. The attackers used `pullERC20` to drain funds from contracts including 0x0adc63e7… and 0x2e933518…, with the attacker’s address 0x9f49591a3b… displaying clear indicators for monitoring related altcoins. The incident may impact the Fear & Greed Index as traders respond to the security breach.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.