PANews|9月 11, 2026 09:37
[ether.fi loses approximately 15.45 ETH due to an access control vulnerability in the AtomicQueue contract]
According to a security alert from SlowMist, ether.fi's AtomicQueue contract suffered a theft of approximately 15.45 ETH due to the lack of access control in the `solve()` function. The attacker exploited the `updateAtomicRequest()` function to create malicious requests, forcing the victim's address to act as the solver. Subsequently, AtomicQueue invoked the victim's `finishSolve` and executed `want.transferFrom`, abusing the victim's existing ERC-20 authorization to transfer funds. SlowMist privately disclosed the issue to the ether.fi team beforehand, and the attacker's address along with the vulnerable contract address have been made public.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink