Lumi Finance on Arbitrum Suffers $270,000 Attack

iconKuCoinFlash
Share
AI summary iconSummary
Lumi Finance on Arbitrum suffered a $270,000 exploit on July 13, according to on-chain data. The attack exploited a vulnerability in the Sodium smart account contract’s validateUserOp function. On-chain analysis revealed that the flaw allowed the attacker to pass their own address as the signer. Although ECDSA.tryRecover failed, it did not revert, enabling the attacker’s isValidSignature function to pass verification.

Odaily Planet Daily reports that, according to GoPlus monitoring, Lumi Finance on Arbitrum was attacked on July 13, resulting in a loss of approximately $270,000. The vulnerability stemmed from a logic flaw in the validateUserOp function of the Sodium smart account contract (ERC-4337). When calling _validateSignature to verify the signature, the signer parameter was passed as the attacker’s address. After ECDSA.tryRecover failed, it did not revert but instead called the isValidSignature function in the attacker’s contract, which passed validation.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.