SlowMist: ONTR token contract access control vulnerability resulted in a loss of approximately $98,000.

PANews reported on May 29th that, according to SlowMist monitoring, the ONTR token contract suffered a loss of 49.4801 WETH, worth approximately $98,000, due to an access control vulnerability in the "onlyOwner" modifier. The attacker (0xe806...b760) exploited this vulnerability, bypassing permission checks when "owner" was "address(0)", calling "transferOwnership()" to set the attacker's contract as owner, then calling "desertJasper()" to add a hidden balance to the queue, and finally calling "glenFlash()" to execute "ashBud()", directly increasing the address balance by 1e30 basic units without increasing "totalSupply". The attacker then transferred the inflated tokens to PancakePair (0xd46d...83fd) and exchanged them for WETH using "swap()".

Share to:

Author: PA一线

This content is for market information only and is not investment advice.

Follow PANews official accounts, navigate bull and bear markets together
PANews APP
SEC Chairman Atkins reiterated the "Crypto Capital of America" ​​strategy, which will drive reforms in on-chain capital markets.
PANews Newsflash