SlowMist|9月 08, 2026 02:47
🚨SlowMist TI Alert🚨
💸 Loss: ~62.28 BNB
🔍 Root Cause: The vulnerable Router implementation exposes swap entry `0x33411b5e(...)` and an unsafe `uniswapV3SwapCallback`. The Router failed to verify that `msg.sender` was a legitimate V3 Pool derived from a trusted factory/token pair/fee, and did not bind the callback `payer` to the original swap context. An attacker supplied a fake V3 Pool/adapter, injected victim addresses as `payer`, and abused existing Router allowances to execute `transferFrom()`.
📌 Attacker: `0xb929c7215c0ec8ebad5fbf73b1da63bccfff1896`
📌 Victim: `0xb5218384398e3b746fdab12f7ba7314bbdaa7282`
📌 Vulnerable Router: `0xa331fde028e6f17425ab9333c39ae43722340d24`
Users with sufficient ERC-20 allowance to the Router could have their approved assets drained without further interaction.
Powered by http://SlowMist.AI(SlowMist)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink