SlowMist
SlowMist|Sep 20, 2026 02:48
🚨SlowMist TI Alert🚨 💸 @Fetch_ai Loss: ~$2M 🔍 Root Cause: TokenConversionManagerV3's conversionIn() leaves single-EOA ECDSA signature as the sole authorization check. It lacks the checkLimits(amount) modifier present in conversionOut(), and does not verify any on-chain burn/lock proof. Using the leaked authorizer private key, the attacker signed a fresh message for their own address, passed the check, and drained the bridge's entire FET balance in one call. 📌 Attacker: 0x1572f2af7696b39c85e3221cde8efb640f86c362 📌 Recipient: 0x2dcc1085fdcf418b421e45e86e4e54637cc21dfe 📌 Victim/Vulnerable Contract: 0xab424a430cc09864fa1277a38193111705adf3a3 Powered by http://SlowMist.AI Tx: https://etherscan.io/tx/0xfe12c63b322d52727c615f3342222138d1563400a9880cebb516a9a162ac69e2
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads