扫码下载
BTC $61,253.43 +0.55%
ETH $1,585.32 +0.58%
BNB $577.54 +0.24%
XRP $1.11 +1.05%
SOL $63.23 -0.61%
TRX $0.3236 +1.11%
DOGE $0.0829 +1.86%
ADA $0.1600 +1.96%
BCH $217.97 +2.27%
LINK $7.53 +2.38%
HYPE $57.85 -2.95%
AAVE $62.02 +1.48%
SUI $0.7459 +6.38%
XLM $0.2103 +6.71%
ZEC $376.93 +0.02%
BTC $61,253.43 +0.55%
ETH $1,585.32 +0.58%
BNB $577.54 +0.24%
XRP $1.11 +1.05%
SOL $63.23 -0.61%
TRX $0.3236 +1.11%
DOGE $0.0829 +1.86%
ADA $0.1600 +1.96%
BCH $217.97 +2.27%
LINK $7.53 +2.38%
HYPE $57.85 -2.95%
AAVE $62.02 +1.48%
SUI $0.7459 +6.38%
XLM $0.2103 +6.71%
ZEC $376.93 +0.02%

慢雾:UvToken 矿池合约因未检查用户传参合法性导致被黑,攻击者获利超 5000 BNB

2022-10-27 16:44:24
收藏

ChainCatcher 消息,根据慢雾区情报,UvTokenWallet Eco Staking 矿池合约被黑,漏洞关键原因在于,矿池合约取款函数未严格判断用户输入,导致攻击者可以直接传入恶意合约地址并利用恶意合约掏空相关资金。

慢雾 MistTrack 对资金进行了追踪溯源分析:截止目前黑客已将获利资金共计 5,011 BNB 转移到 Tornado Cash。此外,攻击的手续费来源同样为 Tornado Cash。

app_icon
ChainCatcher 与创新者共建Web3世界