Scan to download
BTC $74,688.03 -0.50%
ETH $2,321.89 -1.55%
BNB $628.00 +0.53%
XRP $1.43 +1.44%
SOL $87.67 +2.63%
TRX $0.3255 -0.06%
DOGE $0.0968 +0.38%
ADA $0.2530 +1.36%
BCH $447.94 +1.02%
LINK $9.36 +0.49%
HYPE $43.52 -4.72%
AAVE $112.11 +5.30%
SUI $0.9778 +0.79%
XLM $0.1648 +3.00%
ZEC $332.17 -3.01%
BTC $74,688.03 -0.50%
ETH $2,321.89 -1.55%
BNB $628.00 +0.53%
XRP $1.43 +1.44%
SOL $87.67 +2.63%
TRX $0.3255 -0.06%
DOGE $0.0968 +0.38%
ADA $0.2530 +1.36%
BCH $447.94 +1.02%
LINK $9.36 +0.49%
HYPE $43.52 -4.72%
AAVE $112.11 +5.30%
SUI $0.9778 +0.79%
XLM $0.1648 +3.00%
ZEC $332.17 -3.01%

Scam Sniffer: A user lost $927,000 after signing a transaction to the GMX reward router on Arbitrum

2023-11-12 20:28:48
Collection

ChainCatcher message, Scam Sniffer stated on social media that today a user lost $927,000 worth of GMX after signing the "signalTransfer(address receiver)" transaction to the GMX Reward Router on Arbitrum.

It is reported that this method grants the "receiver" the authority to withdraw their LP tokens. The receiver's address starting with 0xbD2B is a pre-calculated contract address created when the Drainer transferred assets.

The Drainer abuses Create2 to bypass security alerts in certain wallets by generating new addresses for each malicious signature. The CREATE2 opcode allows predicting the address of a contract before it is deployed to the Ethereum network. Through Create2, the Drainer can easily generate temporary new addresses for each malicious signature. After the victim signs, the Drainer creates a contract at that address and transfers the user's assets.

Related tags
app_icon
ChainCatcher Building the Web3 world with innovations.