【Warning! EIP-7702 Vulnerability Exploited, QNT Reserve Pool Loses Nearly 55 ETH!】A recent smart contract vulnerability incident has attracted widespread market attention. The attacker exploited the EIP-7702 account vulnerability to steal 1,988.5 QNT from the QNT reserve pool, worth approximately 54.93 ETH. The root cause of this attack lies in the lack of permission settings in the management contract of the reserve pool, allowing the attacker to call contract functions without authorization.


Vulnerability analysis:
Attack path: The reserve pool's administrator account EOA delegated code to the Batcecutor contract via the EIP-770 contract, which in turn set the BatchCall contract, with no permission control, as the authorized caller.
Root cause of the vulnerability: Because the BatchCall() function lacks permission verification, any external caller can invoke it, ultimately leading to the illegal extraction of QNT assets from the reserve pool.
#WCTC交易王PK #加密市场小幅下跌 #Polymarket每日热点 #Strategy吸筹速度超挖矿两倍 #GateCard一拍即付
QNT0.34%
ETH-0.15%
View Original
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments