PANews
PANews|9月 11, 2026 09:37
[ether.fi loses approximately 15.45 ETH due to an access control vulnerability in the AtomicQueue contract] According to a security alert from SlowMist, ether.fi's AtomicQueue contract suffered a theft of approximately 15.45 ETH due to the lack of access control in the `solve()` function. The attacker exploited the `updateAtomicRequest()` function to create malicious requests, forcing the victim's address to act as the solver. Subsequently, AtomicQueue invoked the victim's `finishSolve` and executed `want.transferFrom`, abusing the victim's existing ERC-20 authorization to transfer funds. SlowMist privately disclosed the issue to the ether.fi team beforehand, and the attacker's address along with the vulnerable contract address have been made public.
+3
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads