Home
News Flash
Events
Projects
Columns
Topics
Technical Support
Enter keyword to search
Download APP
Unlock more information
Beosin:跨链协议 LI.FI 遭受攻击事件分析
TechFlame
2024-07-16 15:10
TechFlame
2024-07-16 15:10
TechFlame 消息,据 Beosin Alert 监控预警发现,跨链协议 LI.FI 遭受攻击,Beosin 安全团队发现漏洞原因是攻击者利用项目合约的 call 注入将授权给合约的用户资产转移走。LI.FI 项目合约存在一个 depositToGasZipERC20 函数,可将指定代币兑换为平台币并存入 GasZip 合约,但是在兑换逻辑处的代码未对 call 调用的数据进行限制,导致攻击者可利用此函数进行 call 注入攻击,提取走给合约授权用户的资产。 攻击者地址:0x8B3Cb6Bf982798fba233Bca56749e22EEc42DcF3 被攻击合约:0x1231DEB6f5749EF6cE6943a275A1D3E7486F4EaE Beosin Trace 正在对被盗资金进行追踪。
Latest News Flash
More
Recommended reading
More
KBW 2025's Best Events Roundup: Unmissable Big Parties and Summits
TechFlame.2025-09-24 09:02
The feeling of emptying has not dissipated, and the stablecoin concept heats up: a strong opportunity for Mercurity Fintech (MFH.US)
TechFlame.2025-08-01 08:03
Hong Kong Web3 Carnival Kicks Off in April: Top-Tier Topics Unveiled, Heavyweight Guests Gather in Hong Kong
TechFlame.2026-03-20 14:59
Shanghai Wanxiang Blockchain Week High Energy Gathering: Industry Night and Innovation Summit Inventory
TechFlame.2025-10-21 00:55
Stablecoin Advancement Path: From DeFi Pillar to Payments Revolution
TechFlame.2025-09-25 22:51