Fusion Ecosystem DeFi Project Under Attack: Smart Contract Vulnerability Leads to Fund Theft

robot
Abstract generation in progress

【BitPush】Another incident of an smart contract vulnerability. The security team detected suspicious activity within the Fusion ecosystem—the issue is related to the basic contract, and the project’s EOA account controlled through EIP-7702 technology has a defense loophole. What does this mean? It means this vulnerability opens the door to arbitrary external calls, giving attackers an opportunity. They took advantage of this to deploy malicious circuit breaker contracts for PlasmaVault, directly draining funds from the treasury. This type of DeFi security incident reminds us that even emerging account abstraction schemes require repeated audits, as small detail vulnerabilities can quickly become gaps leading to fund loss.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Repost
  • Share
Comment
0/400
FomoAnxietyvip
· 01-08 03:53
Here it comes again, always the same script... EIP-7702 can't stop these guys --- The account abstraction stuff feels like it's not ready yet but being rushed, sooner or later you'll suffer --- PlasmaVault is directly a loss this time; the treasury was drained, which is really not good --- Where is the promised repeated audits? It still failed at the basic contract, this is awkward --- DeFi is always high yield and high risk, looks like I need to be more cautious --- That circuit breaker contract trick is also incredible; technology is indeed a double-edged sword --- It's always like this, new technology comes out and is exposed to have vulnerabilities within days, when will it finally settle down --- Whose responsibility is it this time? The project team or the security team didn't do their best
View OriginalReply0
Token_Sherpavip
· 01-07 04:37
eip-7702 hype without the audits... classic move. account abstraction is just tradfi complexity dressed up in crypto clothing tbh
Reply0
TestnetNomadvip
· 01-07 04:35
Coming again? EIP-7702 can still be messed up like this, truly incredible --- Account abstraction solutions sound advanced, but it turns out the basic contracts are still not well implemented, hilarious --- PlasmaVault was directly drained, which is why I never touch new projects that haven't undergone multiple audits --- Feels like there are new vulnerabilities every week now, can this ecosystem still be played? --- Vulnerabilities in the defense line leading to arbitrary calls, it's outrageous that such basic errors can occur --- I knew it, funds on the chain are never that safe, in the end, it still depends on whether the code audit is reliable or not --- The circuit breaker contract was drained immediately after deployment, this operation is a textbook-level attack path
View OriginalReply0
DustCollectorvip
· 01-07 04:34
EIP-7702 looks quite innovative, but it still falls into old pitfalls. Audits really need to be stricter.
View OriginalReply0
ParanoiaKingvip
· 01-07 04:22
Here we go again, EIP-7702 is also unsafe, the details are really devilish.
View OriginalReply0
OldLeekMastervip
· 01-07 04:11
It's the same trick again; EIP-7702 can't even prevent it. What kind of audit is this, a joke audit?
View OriginalReply0
MetaNomadvip
· 01-07 04:11
It's the same old story again. Contract audits can't keep up with development speed. These projects really need to reflect and reconsider.
View OriginalReply0
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)