BNB Chain Router Attack Results in Loss of 62.28 BNB

iconChaincatcher
Share
AI summary iconSummary
A Router contract on the BNB Chain was exploited due to vulnerabilities in its Swap entry and uniswapV3SwapCallback functions, resulting in the loss of 62.28 BNB. Attackers forged a V3 Pool/adapter and leveraged existing ERC-20 approvals to steal assets. The Router failed to verify the caller or bind the payer within the callback function. Users who had approved tokens to the Router may have lost assets without any further action on their part. This incident underscores the urgent need for stronger CFT measures and compliance with upcoming regulatory frameworks such as MiCA.

ChainCatcher report: According to SlowMist monitoring, a Router contract was exploited due to security vulnerabilities in its Swap entry point and uniswapV3SwapCallback function, resulting in an estimated loss of 62.28 BNB. The Router failed to verify whether the caller was a legitimate V3 Pool and did not bind the payer in the callback to the original transaction context. The attacker forged a V3 Pool/adapter and injected the victim’s address as the payer, leveraging previously granted ERC-20 approvals to the Router to execute transferFrom() and siphon assets. Users who had previously granted sufficient token approvals to this Router may have their authorized assets drained even without further interaction.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.