BTC $86,179.26 +1.43%
ETH $2,721.72 +1.05%
BNB $792.60 +0.63%
XRP $1.52 +1.78%
SOL $121.56 +0.42%
TRX $0.3351 -0.06%
DOGE $0.0963 +3.56%
ADA $0.2710 +10.62%
BCH $319.14 +0.17%
LINK $14.24 +1.78%
HYPE $92.03 +2.56%
AAVE $180.74 -0.93%
SUI $1.23 +5.26%
XLM $0.2234 +3.62%
ZEC $1,322.08 -0.73%
AAPL $332.41 -0.31%
AMZN $251.11 -0.51%
GOOGL $343.18 -0.23%
MSFT $514.59 -0.64%
META $726.38 -0.45%
NVDA $235.55 +0.39%
TSLA $372.04 +0.20%
SNDK $1,729.50 +0.78%
INTC $117.31 -0.67%
SPCX $160.15 +0.72%
MU $1,080.21 +1.29%
AMD $634.86 +0.26%
BTC $86,179.26 +1.43%
ETH $2,721.72 +1.05%
BNB $792.60 +0.63%
XRP $1.52 +1.78%
SOL $121.56 +0.42%
TRX $0.3351 -0.06%
DOGE $0.0963 +3.56%
ADA $0.2710 +10.62%
BCH $319.14 +0.17%
LINK $14.24 +1.78%
HYPE $92.03 +2.56%
AAVE $180.74 -0.93%
SUI $1.23 +5.26%
XLM $0.2234 +3.62%
ZEC $1,322.08 -0.73%
AAPL $332.41 -0.31%
AMZN $251.11 -0.51%
GOOGL $343.18 -0.23%
MSFT $514.59 -0.64%
META $726.38 -0.45%
NVDA $235.55 +0.39%
TSLA $372.04 +0.20%
SNDK $1,729.50 +0.78%
INTC $117.31 -0.67%
SPCX $160.15 +0.72%
MU $1,080.21 +1.29%
AMD $634.86 +0.26%

Slow Fog: The Numbers Protocol token project has a serious vulnerability and has been attacked. Please revoke authorization as soon as possible

2022-11-23 18:01:39

ChainCatcher news, according to the Slow Mist security team's intelligence, the Numbers Protocol (NUM) token project on the ETH chain has been attacked, with the attacker profiting approximately $13,836.

The Slow Mist security team shared the following in a brief:

  1. The attacker created a malicious anyToken token, which is the attack contract (0xa68cce), and the underlying token of this malicious token contract points to the NUM token address;
  2. Then, they called the anySwapOutUnderlyingWithPermit function of the Router contract of the Multichain cross-chain bridge. This function takes anyToken as input and calls the permit function of the underlying token for signature approval, then exchanges the authorized user's underlying token to a specified address. However, since the NUM token does not have a permit function and has a callback feature, even if the attacker inputs a fake signature, it can still return normally, causing the transaction not to fail, resulting in the NUM tokens of the victim's address being ultimately transferred to the specified attack contract;
  3. The attacker then exchanged the profited NUM tokens for USDC through Uniswap and then converted them to ETH for profit;

The main reason for this attack is that the NUM token does not have a permit function and has a callback feature, allowing fake signatures to deceive the cross-chain bridge, leading to unexpected transfers of user assets. (Source link)

app_icon
ChainCatcher Building the Web3 world with innovations.