PublicAML

Nimiq Targeted by Meta-Transaction Auth Flaw Exploit

An attacker exploited a vulnerability in OpenGSN meta-transactions affecting Nimiq. The incident resulted in a loss of approximately $50,463.

An attacker exploited a flaw in OpenGSN meta-transactions on Polygon HTLC contracts, specifically by abusing the open/execute function which accepted a spoofed 'from' address without requiring a valid user signature. By impersonating the liquidity wallet 0x24cb…6773, the attacker was able to utilize leftover ERC-20 allowances to lock significant amounts of cryptocurrency into HTLCs with a recipient of their choice and a predetermined secret hash.

The attacker locked 26,130.64171 USDC, 24,332.489269 USDT0, and 0.661117 USDC.e into the HTLCs before redeeming them through a CREATE2 contract using the secret value of 1. This method allowed the attacker to bypass normal transaction validation processes, leading to the unauthorized redemption of funds.

The total loss from this single transaction was approximately $50,463. The incident highlights the potential risks associated with vulnerabilities in meta-transaction systems, particularly in how they handle user signatures and transaction authorization. The specific blockchain used in this incident is not stated, which limits the ability to trace the transaction on-chain.

Sources

Share:XTelegramLinkedIn
Nimiq Targeted by Meta-Transaction Auth Flaw Exploit | PublicAML