Unverified Ethereum Contract Vulnerability Causes $983,000 Loss

iconAiCoin
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
Ethereum news broke after a vulnerability incident caused a $983,000 loss from an unverified contract (0x143a…81a). A flaw in the execute() function allowed an attacker to drain 384.67 yvWETH from address 0x9828…5afe. The stolen funds were liquidated for 429.2 ETH. The incident underscores the risks of interacting with unverified Ethereum smart contracts.

According to BlockSec Phalcon monitoring, an unverified contract on Ethereum, 0x143a…81a, has a vulnerability in its execute() function due to missing permission checks, resulting in approximately $983,000 in losses. The attacker exploited the unlimited yvWETH allowance authorized by the victim address 0x9828…5afe to steal 384.67 yvWETH and liquidate them for approximately 429.2 ETH.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.