Zetachain team wallet encounters security vulnerability, funds stolen

robot
Abstract generation in progress

CryptoWorld News reports that, according to U.Today, the interoperability-focused blockchain network Zetachain suffered a security vulnerability that led to funds from the internal team wallet being stolen. Fortunately, the developers quickly patched the vulnerability, preventing the attackers from harming users’ assets. According to security expert SlowMist’s analysis, the core vulnerability was in the call function of Zetachain’s gatewayzevm contract, which lacked proper access control mechanisms and input validation parameters. Due to the absence of these security checks, the system was left entirely exposed to attack. The attacker was able to craft a highly specific malicious call that directly issued a fake cross-chain event on Zetachain. Zetachain’s relayer automatically received and executed the malicious call, resulting in the funds being effectively siphoned. Zetachain has assured the community that the losses were limited to the funds it held itself. The developers said: “Today’s attack on the Zetachain gatewayevm contract only affected the internal team wallet. We have blocked the attack vector to ensure that no more funds are threatened.”

ZETA2.88%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments