SlowMist has caught another onlyOwner vulnerability; even if the owner becomes 0, it can still be exploited. How did this contract pass the audit?

View Original
MarsBitNews
Data: ONTR token contract access control vulnerability results in approximately $98k in losses
SlowMist states that the ONTR token contract has an onlyOwner vulnerability, allowing an attacker to gain ownership when owner is address(0), transfer ownership, and inflate balances to 1e30 units through operations like desertJasper, glenFlash, ashBud without increasing totalSupply, resulting in a loss of approximately 49.4801 WETH (about $98k). Then, they exchange on PancakePair for WETH, involving addresses such as 0xe806...b760.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned