SlowMist|Sep 11, 2026 09:41
🚨SlowMist TI Alert🚨
We first reached out to the http://ether.fi team privately to responsibly disclose the issue before making any public statement.
💸 @ether_fi Loss: ~15.45 ETH
🔍 Root Cause: `AtomicQueue.solve()` lacks access control on the caller-supplied `solver` — there is no `solver == msg.sender` check, nor any signature, registration, or consent verification. The attacker first created a maliciously crafted `AtomicRequest` using the `updateAtomicRequest()` function, then forced a victim address to act as the `solver`. AtomicQueue subsequently called `finishSolve` on the victim and executed `want.transferFrom(solver, users[i], assetsToUser)`, abusing the victim's pre-existing ERC-20 allowance to drain funds.
📌 Attacker: `0xa5cc6e490bce9185fa47b421f2eac677a83b64ea`
📌 Vulnerable Contract (AtomicQueue): `0xd45884b592e316eb816199615a95c182f75dea07`
Powered by http://SlowMist.AI
Tx: https://etherscan.io/tx/0x7cbe0b4349513fed6d03ba8bf9ed708e10e07a501d10b5f344a25ae10595599b(SlowMist)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink