PublicAML

WealthManagementV2 Contract Exploited for 26,414 USDT Loss

The WealthManagementV2 contract experienced a loss of 26,414 USDT due to suspected illegal transfer of owner privileges. An attacker manipulated contract parameters and withdrew funds in a single transaction.

The WealthManagementV2 contract on the BSC chain lost 26,414 USDT after owner privileges were suspected of being illegally transferred, potentially due to a leaked private key. The attacker gained control of the owner account and immediately set extreme plan parameters, including a period of 0 and an interest multiplier of 528,300,000, using the updatePlanConfig function without any timelock or bounds.

By minting inflated interest, the attacker was able to invest and redeem in the same transaction, effectively manipulating the contract's functionality. Following this, they unlocked and withdrew the funds through a second investment, resulting in the total loss of 26,414 USDT. The incident highlights the risks associated with compromised private keys and the potential for significant financial loss in DeFi contracts.

Sources

Share:XTelegramLinkedIn
WealthManagementV2 Contract Exploited for 26,414 USDT Loss | PublicAML