Transit Finance项目遭到攻击,损失约11万美元

This article is not available in the current language yet. Showing the original version.

PANews 12月20日消息,据Beosin旗下EagleEye安全风险监控、预警与阻断平台监测显示,Transit Finance项目遭到攻击,损失约110,000美元。Beosin安全团队分析发现Transit Finance的SwapRouter中的exactInputV3Swap函数由于缺乏对pool输入合法校验,导致被攻击。以0x93ae5...6de1081交易为例,攻击者传入伪造的pool和WBNB/BUSD池子路径、从而在第一次兑换中控制了actualAmountIn。导致SwapRouter将伪造的actualAmountIn作为在WBNB/BUSD池子中兑换的初始值,从而窃取了SwapRouter中的BUSD。

Transit Finance项目遭到攻击,损失约11万美元

Transit Finance项目遭到攻击,损失约11万美元

Share to:

Author: PA一线

This content is for market information only and is not investment advice.

Follow PANews official accounts, navigate bull and bear markets together
PANews APP
JPMorgan Chase CEO: We are considering offering prediction market services to clients, but will not cover areas such as sports and politics.
PANews Newsflash