SlowMist analyzes the cause of the ZetaChain attack: GatewayZEVM contract lacked access control

SlowMist reports that the vulnerability in the call function of the GatewayZEVM contract was exploited in the ZetaChain attack.

According to this analysis, the root cause lies in the lack of access control and input validation, allowing any user to initiate cross-chain commands via GatewayZEVM and then execute arbitrary operations on the target chain through the relay.

Attackers created malicious cross-chain events on ZetaChain. When the relay detects these events, they execute malicious commands on the target chain via TSS, thereby stealing funds.

Previously, ZetaChain stated that their GatewayEVM contract was attacked, but the attack was blocked and users’ funds remained safe.

Thank you for reading this article!

Please Like, Comment, and Follow TinTucBitcoin to stay updated with the latest news in the cryptocurrency market and not miss any important information!

ZETA1.94%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments