SlowMist: Asterix attacks are similar to Flooring Protocol and BMP, with attackers looking for common vulnerabilities.

robot
Abstract generation in progress
Mars Finance news, SlowMist founder Yu Xian posted that the attack encountered by Asterix is similar to yesterday's Flooring Protocol and BMP (underlying protocols are DN404 and BT404), involving overflow reuse of high-level NFT ID displacement operations. It seems the attacker is looking for common vulnerabilities.
It is reported that Asterix disclosed an attack incident affecting the ASTX token contract yesterday, stating that its Uniswap v4 liquidity pool was attacked on June 8, with the attacker stealing about 30 ETH through 242 transactions.
The vulnerability stemmed from the lack of token ID restriction checks on approval operations in early versions of DN404. The attacker exploited outdated token approvals to repeatedly sell tokens in the pool for ETH, then forged IDs to extract an equivalent amount of tokens, with the cycle draining the funds.
Smart contracts are immutable and cannot be patched, and the team recommends users stop interacting with the current pool and tokens. They are planning to migrate and deploy secure tokens.
The team suspects the attacker used jailbroken AI tools for fuzz testing to discover unconventional logical paths.
ETH0.76%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned