扫码下载
BTC $65,844.32 +2.48%
ETH $1,720.98 +2.77%
BNB $616.87 +1.04%
XRP $1.18 +3.40%
SOL $71.39 +4.68%
TRX $0.3197 +1.27%
DOGE $0.0886 +1.46%
ADA $0.1815 +6.02%
BCH $213.26 +5.13%
LINK $8.21 +3.78%
HYPE $65.51 +8.44%
AAVE $70.62 +6.94%
SUI $0.7975 +5.30%
XLM $0.1899 +1.82%
ZEC $497.36 +16.82%
BTC $65,844.32 +2.48%
ETH $1,720.98 +2.77%
BNB $616.87 +1.04%
XRP $1.18 +3.40%
SOL $71.39 +4.68%
TRX $0.3197 +1.27%
DOGE $0.0886 +1.46%
ADA $0.1815 +6.02%
BCH $213.26 +5.13%
LINK $8.21 +3.78%
HYPE $65.51 +8.44%
AAVE $70.62 +6.94%
SUI $0.7975 +5.30%
XLM $0.1899 +1.82%
ZEC $497.36 +16.82%

慢雾:EIP-7702 账户漏洞遭利用,1,988.5 枚 QNT 被盗

2026-04-29 12:10:45
收藏

ChainCatcher 消息,据市场消息,攻击者利用一个存在缺陷的 EIP-7702 账户,从 QNT 储备池盗取 1,988.5 枚 QNT(约合 54.93 枚 ETH)。根本原因在于,该储备池管理员 EOA 通过 EIP-7702 将代码委托给 BatchExecutor 合约,而该合约将无权限控制的 BatchCall 合约设为授权调用方。

由于 BatchCall.batch() 函数未设置任何权限校验,任意外部调用者均可调用,最终导致储备池资产被耗尽。

app_icon
ChainCatcher 与创新者共建Web3世界