PANews|Sep 02, 2026 03:12
[GebProxyActions Contract Access Control Vulnerability Leads to Theft of 5.94 ETH]
According to monitoring by SlowMist, the GebProxyActions contract suffered a loss of approximately 5.9436 ETH due to a lack of caller access control. The affected users had previously directly invoked GebProxyActions.quitSystem instead of delegating the call through DSProxy, resulting in ownsSAFE[safe] being set to the GebProxyActions contract. The attacker directly called GebProxyActions.quitSystem(manager, safe, dst), bypassing the safeAllowed check in GebSafeManager and transferring the collateral to themselves.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink