According to monitoring by the SlowMist Security Team, due to a design flaw in the EIP-7702 account, a certain QNT reserve pool was maliciously attacked, resulting in a loss of approximately 1988.5 QNT (about 54.93 ETH).


The root cause of the vulnerability is that the management permission of this QNT reserve pool is held by an external account (EOA), which delegates its code to a contract through the EIP-7702 mechanism.
However, the contract function is fully open to any external caller and lacks necessary permission checks.
This arbitrary call vulnerability allows attackers to directly extract QNT tokens from the reserve pool.
Currently, the attack transaction has been confirmed on the blockchain, and SlowMist reminds relevant protocols and users to pay attention to the security of the implementation of new features in EIP-7702.
QNT0.22%
ETH1.78%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments