According to Mars Finance, Enjin’s ERC-1155 “Crypto Items” allow each item to route transfers through a dedicated item adapter. The attacker registered and used a malicious transfer adapter to bypass owner approval checks, enabling the vulnerable contract to extract ENJ-backed items from approximately 52 unrelated wallet holders without approval. Subsequently, the attacker called melt() on each stolen item to redeem 500 ENJ per item from the platform’s reserve.
Enjin vulnerability exploited; $142,000 worth of ENJ stolen from 52 wallets
MarsBitShare
A vulnerability incident has emerged after an attacker exploited a flaw in Enjin’s ERC-1155 "Crypto Items." Using a malicious transfer adapter, the attacker bypassed owner approval checks and drained ENJ-backed items from 52 wallets. The attacker then used the melt() function to redeem 500 ENJ per item from platform reserves, resulting in total losses of $142,000. On-chain data reveals the attack was swift and targeted, with no direct connections between the affected wallets.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.