Beosin: The reason for the attack on WazirX may be the leakage of the administrators private key of the multi-signature wallet
Odaily2024/07/18 09:09
By:Odaily
Odaily News On July 18, 2024, according to Beosin Alert monitoring and warning, the Indian exchange WazirX was attacked. The attacker obtained the signature data of the exchanges multi-signature wallet administrator, modified the wallets logic contract, and made the wallet execute the wrong logic to steal assets. Attacker address: 0x6eedf92fb92dd68a270c3205e96dccc527728066 Attacked address: 0x27fd43babfbe83a81d14665b1a6fb8030a60c9b4 Based on the attackers attack behavior, it is speculated that the cause is the leakage of the administrators private key of the multi-signature wallet. Beosin briefly analyzes the cause of the attack as follows: 1. The attacker deployed the attack contract: 0x27fd43babfbe83a81d14665b1a6fb8030a60c9b4. The function of this contract is to extract the token assets specified by this contract. 2. The attacker obtains the signature data of the administrator of the wazirx multi-signature wallet and modifies the logical contract of the wallet to the deployed attack contract. The corresponding transaction is: https://etherscan.io/tx/0x48164d3adbab78c2cb9876f6e17f88e321097fcd14cadd57556866e4ef3e185d 3. The attacker submits a token extraction transaction to the wazirx multi-signature wallet. Due to the mechanism of the proxy mode, the wallet contract will use delegatecall to call the relevant functions of the attack contract and transfer the wallet tokens. Beosin Trace is tracking the stolen funds.
0
0
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!
You may also like
Bankrupt Cryptopia Exchange to Refund $225 Million to Its Clients
HappyCoinNews•2024/12/21 04:00
US approves dual ETFs based on Bitcoin and Ethereum
HappyCoinNews•2024/12/21 04:00
European Crypto Exchanges to Delist USDT by December 30
HappyCoinNews•2024/12/21 04:00
German Regulators Crack Down on Worldcoin Data Practices
The World Foundation is seeking clarity on whether its Privacy Enhancing Technologies (PETs) meet the EU’s standards for anonymization.
Altcoinbuzz•2024/12/21 04:00
Trending news
MoreCrypto prices
MoreBitcoin
BTC
$97,686.31
+0.49%
Ethereum
ETH
$3,488.75
+2.86%
Tether USDt
USDT
$0.9995
+0.04%
XRP
XRP
$2.32
+0.70%
BNB
BNB
$687.59
+2.13%
Solana
SOL
$197.46
+1.36%
Dogecoin
DOGE
$0.3321
+3.56%
USDC
USDC
$1
+0.01%
Cardano
ADA
$0.9599
+6.64%
TRON
TRX
$0.2502
-0.68%
Bitget pre-market
Buy or sell coins before they are listed, including ME, TOMA, OGC, USUAL, and more.
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new Bitgetters!
Sign up now