BTC $86,724.44 +2.31%
ETH $2,725.93 +1.27%
BNB $799.02 +2.00%
XRP $1.52 +2.31%
SOL $121.13 +0.93%
TRX $0.3361 +0.12%
DOGE $0.0961 +3.80%
ADA $0.2637 +8.16%
BCH $318.98 +0.36%
LINK $14.18 +0.69%
HYPE $90.33 +0.59%
AAVE $181.22 -0.77%
SUI $1.22 +3.79%
XLM $0.2249 +4.17%
ZEC $1,342.14 +2.37%
AAPL $333.56 +0.08%
AMZN $252.86 +0.25%
GOOGL $344.83 +0.32%
MSFT $516.96 -0.16%
META $729.52 -0.18%
NVDA $236.16 +0.55%
TSLA $373.07 +0.41%
SNDK $1,736.08 +1.12%
INTC $118.90 +1.43%
SPCX $160.43 +0.95%
MU $1,080.21 +1.26%
AMD $642.87 +1.48%
BTC $86,724.44 +2.31%
ETH $2,725.93 +1.27%
BNB $799.02 +2.00%
XRP $1.52 +2.31%
SOL $121.13 +0.93%
TRX $0.3361 +0.12%
DOGE $0.0961 +3.80%
ADA $0.2637 +8.16%
BCH $318.98 +0.36%
LINK $14.18 +0.69%
HYPE $90.33 +0.59%
AAVE $181.22 -0.77%
SUI $1.22 +3.79%
XLM $0.2249 +4.17%
ZEC $1,342.14 +2.37%
AAPL $333.56 +0.08%
AMZN $252.86 +0.25%
GOOGL $344.83 +0.32%
MSFT $516.96 -0.16%
META $729.52 -0.18%
NVDA $236.16 +0.55%
TSLA $373.07 +0.41%
SNDK $1,736.08 +1.12%
INTC $118.90 +1.43%
SPCX $160.43 +0.95%
MU $1,080.21 +1.26%
AMD $642.87 +1.48%

Slow Fog: The Numbers Protocol token project has a serious vulnerability and has been attacked. Please revoke authorization as soon as possible

2022-11-23 18:01:39

ChainCatcher news, according to the Slow Mist security team's intelligence, the Numbers Protocol (NUM) token project on the ETH chain has been attacked, with the attacker profiting approximately $13,836.

The Slow Mist security team shared the following in a brief:

  1. The attacker created a malicious anyToken token, which is the attack contract (0xa68cce), and the underlying token of this malicious token contract points to the NUM token address;
  2. Then, they called the anySwapOutUnderlyingWithPermit function of the Router contract of the Multichain cross-chain bridge. This function takes anyToken as input and calls the permit function of the underlying token for signature approval, then exchanges the authorized user's underlying token to a specified address. However, since the NUM token does not have a permit function and has a callback feature, even if the attacker inputs a fake signature, it can still return normally, causing the transaction not to fail, resulting in the NUM tokens of the victim's address being ultimately transferred to the specified attack contract;
  3. The attacker then exchanged the profited NUM tokens for USDC through Uniswap and then converted them to ETH for profit;

The main reason for this attack is that the NUM token does not have a permit function and has a callback feature, allowing fake signatures to deceive the cross-chain bridge, leading to unexpected transfers of user assets. (Source link)

app_icon
ChainCatcher Building the Web3 world with innovations.