CoinDesk·3 min read·hard

How a simple coding mistake let a hacker drain $7.8 million from a crypto wallet

O
Oliver Knight
How a simple coding mistake let a hacker drain $7.8 million from a crypto wallet
AI Summary

A hacker drained $7.8 million from a crypto wallet by exploiting a flawed authorization check in a helper contract. Security firms identified that the vulnerability allowed unauthorized parties to move funds, which were then laundered through a worthless token.

Why it matters

This incident underscores the persistent security risks in decentralized finance (DeFi) and the importance of rigorous smart contract auditing.

Dive DeeperCreate a free account to unlock

An automated bot known as “yoink” front-ran the attack transaction and extracted the tokens, security firms BlockSec , Blockaid and SlowMist said.

The victim's wallet was set up to let a helper contract move money for it, an ordinary arrangement for people who automate their trading. The helper was meant to verify that the caller had permission, but SlowMist and BlockSec found the check approved anyone who named the helper itself as the target.

The attacker then dumped around 2,900 rsETH into a trading pool built minutes earlier around a worthless token called Permissionless Attacker Token, leaving the wallet with a receipt worth nothing. Yoink's bot paid roughly $47,000 to jump the queue and took the tokens, sending 2,882 rsETH to a separate address.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycryptobusiness

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in