SlowMist|Sep 18, 2026 10:37
🚨SlowMist TI Alert🚨
💸 @nimiq Loss: ~$50,463
🔍 Root Cause: ERC20PermitHTLCHandler's `execute()` discards all five calldata parameters (including signature & nonce) and performs no EIP-712 signature, nonce, or business pre-check. The only signature/nonce validation lived in its `preRelayedCall()`, but GSN RelayHub calls `preRelayedCall` on the attacker-specified paymaster. So the attacker set himself as paymaster, fully bypassing that check, used 1 MATIC GSN relay registration to pass `onlyRelayHub` and forged `request.from = victim`, causing `openPrivate()` to call `token.transferFrom(victim, handler, full balance)`.
Finally, the attacker directly called the `redeem` function to withdraw these funds using the hosted secret they had crafted.
📌 Attacker: 0x2258491525C21f334c5a2dc22CE55e55023FC45D
📌 Victim: 0x24Cb173Ae221AeA93369f34bdcF0Ddb35b436773
📌 Vulnerable Contract: 0x0cFD862bE942846Cebad797d7c1BC6e47714959b, 0xf615bd7eA00C4Cc7F39fAAD0895Db5f40891359f
Powered by http://SlowMist.AI
Tx:
https://polygonscan.com/tx/0xb067efae73637f3564f58af7f6027afc497e81e47624b0048636085c678858c0
https://polygonscan.com/tx/0xb2ca76dfbfe571742b4b66465b777ab1e06988a8632be1631bef9654cc64d169
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink