SlowMist|Aug 01, 2026 11:05
🚨SlowMist TI Alert🚨
💸 Loss: ~16.623 WETH
🔍 Root Cause: Selector 0x42be3129 of unverified contract 0xa317...c170 exposes an unrestricted low-level CALL, lacking access control & target/calldata validation. Attacker exploited the contract's existing ERC20 allowance to execute unauthorized transferFrom from victim.
📌 Attacker: 0xbdce6bdd52baceadd1fc91bf01f3bc6ab24df17a
📌 Victim: 0x386218744a2053d949a1cafae0b7b49a35e03f53
📌 Vulnerable Contract: 0xa31722ca2a32695280d0e7e325b3dd6d699fc170
Impact: The attacker drained the full WETH allowance (16.623 WETH) by abusing the arbitrary external call mechanism and bypassing the owner check.
Powered by http://SlowMist.AI
Tx: https://basescan.org/tx/0xe831f3991132cbaffbb4a3738da7d1e254a6c02f0adce605a333229a61e27ad7(SlowMist)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink