Foresight News|11月 23, 2025 06:01
[Port3: The theft was caused by a boundary condition verification vulnerability in the cross-chain token solution CATERC20, and tokens will be reissued using a new contract]
Foresight News reports that Port3 Network has released an analysis report on the hacking incident. PORT3 adopted NEXA's CATERC20 cross-chain token solution, which has a boundary condition verification vulnerability. When token ownership is renounced, the value returned by the function is 0, which coincides with the ownership verification condition. As a result, ownership verification fails, making unauthorized access possible. This issue was not identified in the CATERC20 audit report. Since Port3 tokens had previously renounced ownership to achieve greater decentralization, they were in this vulnerable state.
The hacker discovered this authorization verification vulnerability in the PORT3 contract and initiated a RegisterChains operation, registering their own address as an address authorized to perform the BridgeIn operation. Meanwhile, the hacker deployed a counterfeit token on the Arbitrum One chain and initiated a cross-chain transaction. Due to the vulnerability in the BSC-side Port3 token contract, the verification was erroneously passed, resulting in the wrongful minting of 1 billion tokens. Subsequently, the hacker sold these tokens on decentralized exchanges (DEX), causing a rapid price crash. Port3 has contacted major exchanges to request a suspension of deposits and withdrawals. Next, the team will address this issue by reissuing tokens using a new contract.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink