Unverified contract vulnerability leads to theft of 16.6 WETH

iconKuCoinFlash
Share
AI summary iconSummary
On August 1 (UTC+8), the Slow Mist security team identified a contract vulnerability in an unverified contract. The issue arose from an unrestricted low-level call using selector 0x42be3129, lacking proper access control and validation. This enabled the theft of approximately 16.6 WETH. The attacker exploited existing ERC20 approvals to bypass ownership checks and execute unauthorized transferFrom operations. (Source: ODAILY)

ME News reports that on August 1 (UTC+8), according to monitoring by the SlowMist Security Team, an unverified contract exposed an unrestricted low-level call vulnerability via the selector 0x42be3129, lacking access control and target data validation, resulting in the theft of approximately 16.6 WETH. The attacker exploited the contract’s existing ERC20 approval allowance to bypass owner checks and execute unauthorized transferFrom operations. (Source: ODAILY)

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.