SlowMist: EIP-7702 account vulnerability exploited, 1,988.5 QNT stolen

Golden Finance reports that on April 29, according to SlowMist monitoring, an attacker exploited a vulnerable EIP-7702 account to steal 1,988.5 QNT from the QNT reserve pool (approximately 54.93 ETH). The root cause was that the reserve pool administrator’s EOA delegated code to the BatchExecutor contract via EIP-7702, and this contract set the permissionless BatchCall contract as the authorized caller.
Because the BatchCall.batch() function did not have any permission checks, it could be called by any external caller, ultimately leading to the depletion of the reserve pool assets.

QNT0.71%
ETH-1.25%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments