header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Profit of about $1.8 million zkSync Eco DEX Merlin security incident analysis

Read this article in 8 Minutes
The Beosin security team suggests that projects should use multi-sign-wallet or DAO governance to manage addresses with important permissions, and that users should be more aware of the risks involved when interacting with projects.
Original Title: Analysis of zkSync Ecodex Merlin Security Incident that Earned About $1.8 Million
Foresightnews


On April 26, 2023, according to the Beosin-Eagle Eye situational awareness platform, a security incident occurred at Merlin Dex, and all funds from the USDC-WETH liquidity pool have been withdrawn, resulting in a total profit of about $1.8 million for the attackers. It is understood that Merlin Dex is a decentralized exchange. As for this security incident, the Beosin security team immediately analyzed the incident and the results are as follows.



Event related information


Let's take one of those deals as an example


Attack transaction


0xf21bedfb0e40bc4e98fd89d6b2bdaf82f0c452039452ca71f2cac9d8fea29ab2


Attacker address


0xc0D6987d10430292A3ca994dd7A31E461eb28182


0x2744d62a1e9ab975f4d77fe52e16206464ea79b7


Attacked contract


0 x82cf66e9a45df1cd3837cf623f7e73c1ae6dff1e (USDC - WETH pool)


Attack flow


1. The first step, the pool creator (0 xc0d6987d10430292a3ca994dd7a31e461eb28182) created the factory contract


(0 x63e6fdadb86ea26f917496beeeaea4efb319229f), when the initialization Feeto address has been set to


Xc0d6987d10430292a3ca994dd7a31e461eb28182 (0).



2. The attacker USDC deployment over the factory contract - WETH pond (0 x82cf66e9a45df1cd3837cf623f7e73c1ae6dff1e), pool initialization time and gave the USDC pool and WETH maximize license contract Feeto address of the factory, You can see that there is a clear risk of centralization.



3. Then, with the maximum authorization, the attacker transfers all the tokens in the pool.



4. It is worth noting that the Owner and Feeto addresses of the factory contract were changed before the attack occurred, but this step is not necessary for the attack. It may be the attacker's operation to confuse others.




Finally, it can be seen that all the funds in the USDC-WETH liquidity pool have been withdrawn, and the attacker has made a total profit of about 1.8 million dollars.


Vulnerability analysis


Beosin security team analyzed that this attack mainly took advantage of the centralization problem of the pair contract, which maximized the authorization of the Feeto address in the factory contract during initialization, so that the funds in the pool could be extracted at any time by the Feeto address specified during initialization.


Money tracking


Attacker calls the transferFrom function from the pool turned out 811 k USDC to attackers address 1 (0 x2744d62a1e9ab975f4d77fe52e16206464ea79b7). Attacker address 2 (0 xce4ee0e01bb729c1c5d6d2327bb0f036fa2ce7e2) extracted from token1 contracts (WETH) 435.2 eth, After through Anyswap across the chain to the etheric fang (0 xa7d481944730a88b862eb57248cb1b2c8aa358ad) and addresses


X0b8a3ef6307049aa0ff215720ab1fc885007393d (0), a total profit of about $1.8 million.


As of the time of publication, the anti-money laundering analysis platform Beosin KYT has found that the stolen funds are still stored on the two main Ethereum addresses of the aforementioned attackers. The Beosin security team will continue to monitor and track the stolen funds.


 

 


summarize


In response to this incident, the Beosin security team suggested that the project should use the multi-signature wallet or DAO governance to manage the addresses with important permissions, and users should also know more about whether the project involves risks when interacting with the project.


Original link


Welcome to join the official BlockBeats community:

Telegram Subscription Group: https://t.me/theblockbeats

Telegram Discussion Group: https://t.me/BlockBeats_App

Official Twitter Account: https://twitter.com/BlockBeatsAsia

举报 Correction/Report
Choose Library
Add Library
Cancel
Finish
Add Library
Visible to myself only
Public
Save
Correction/Report
Submit