Alchemix yvVault users were attacked due to mistaken authorization, losing approximately $1 million.

robot
Abstract generation in progress

Deep Tide TechFlow News, April 29th, according to on-chain analyst PeckShield (@PeckShieldAlert) monitoring, a user’s Alchemix Yearn yvVault position (token $yvWETH) was attacked, with an estimated loss of about 1 million USD.

The root cause of the attack was that the user previously authorized an unverified contract (contract address: 0x143a), which was deployed 10 days ago. Through decompilation analysis, the contract was found to have a vulnerability that could be exploited to execute arbitrary calls. The attacker exploited this vulnerability to successfully transfer the victim’s yvVault position.

Currently, PeckShield has publicly disclosed the specific logic of the vulnerability. Users are advised to check and revoke token approvals for unknown or unverified contracts to reduce asset risk.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments