Degen.Money被曝存在双重授权漏洞,用户资金面临被窃取风险

This article is not available in the current language yet. Showing the original version.
推特上有网友发推文称,流动性挖矿项目Degen.Money的参与者面临着双重授权漏洞窃取用户资金的风险。

PANews 828日消息,推特上有网友发推文称,流动性挖矿项目Degen.Money的参与者面临着双重授权漏洞窃取用户资金的风险。第一次授权是针对质押合约,第二次授权针对转账权,会导致资金被攻击者提取。

对此,YFI创始人Andre Cronje也表示,这个风险确实存在,平台通过transferFrom函数取走用户资金,用户请求把资金从合约中撤出并不能够解决问题,是需要自己手动操作取消授权。

Share to:

Author: PA一线

Opinions belong to the column author and do not represent PANews.

This content is not investment advice.

Image source: PA一线. If there is any infringement, please contact the author for removal.

Follow PANews official accounts, navigate bull and bear markets together