PublicAML

Ether.fi Liquid Users Lose Funds Due to Access Control Exploit

Users of ether.fi Liquid lost approximately 15.45 ETH due to an exploit. The incident affected around 11 users.

Users of ether.fi Liquid (liquidETH) experienced a loss of about 15.45 ETH after an attacker exploited a missing access control in the AtomicQueue.solve() function. The attacker crafted a malicious AtomicRequest, which forced already-approved victim addresses to act as solvers, allowing the attacker to drain funds through existing ERC-20 allowances using the transferFrom method.

The incident resulted in a total loss of approximately 38,130 USD. The exploit specifically targeted the Ethereum chain, which means that the transactions can be traced on this blockchain. The use of ERC-20 allowances indicates that the attacker was able to leverage pre-existing permissions granted to the victim addresses to execute the unauthorized transfers.

The on-chain record would show the addresses involved in the transactions, detailing the movement of funds from the affected users to the attacker's address. This information could be used to analyze the flow of funds and potentially identify further actions taken by the attacker.

Sources

Share:XTelegramLinkedIn
Ether.fi Liquid Users Lose Funds Due to Access Control Exploit | PublicAML