EIP-7702 Flaw Drains 1,988.5 QNT From Reserve Pool

robot
Abstract generation in progress

A design flaw in an EIP-7702 account let an attacker drain 1,988.5 QNT from a reserve pool, worth about 54.93 ETH. SlowMist said the reserve pool administrator was an address that delegated its code to the BatchExecutor contract through EIP-7702. SlowMist said the attacker then used missing permission checks in BatchCall.batch to make arbitrary calls and remove tokens from the pool.

QNT1.34%
ETH1.84%
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments