How a simple coding mistake let a hacker drain $7.8 million from a crypto wallet

A hacker drained $7.8 million from a crypto wallet by exploiting a flawed authorization check in a helper contract. Security firms identified that the vulnerability allowed unauthorized parties to move funds, which were then laundered through a worthless token.
Why it matters
This incident underscores the persistent security risks in decentralized finance (DeFi) and the importance of rigorous smart contract auditing.
An automated bot known as “yoink” front-ran the attack transaction and extracted the tokens, security firms BlockSec , Blockaid and SlowMist said.
The victim's wallet was set up to let a helper contract move money for it, an ordinary arrangement for people who automate their trading. The helper was meant to verify that the caller had permission, but SlowMist and BlockSec found the check approved anyone who named the helper itself as the target.
The attacker then dumped around 2,900 rsETH into a trading pool built minutes earlier around a worthless token called Permissionless Attacker Token, leaving the wallet with a receipt worth nothing. Yoink's bot paid roughly $47,000 to jump the queue and took the tokens, sending 2,882 rsETH to a separate address.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in