Original Title: Analysis of zkSync Ecodex Merlin Security Incident that Earned About $1.8 Million
Foresightnews
On April 26, 2023, according to the Beosin-Eagle Eye situational awareness platform, a security incident occurred at Merlin Dex, and all funds from the USDC-WETH liquidity pool have been withdrawn, resulting in a total profit of about $1.8 million for the attackers. It is understood that Merlin Dex is a decentralized exchange. As for this security incident, the Beosin security team immediately analyzed the incident and the results are as follows.

Let's take one of those deals as an example
Attack transaction
0xf21bedfb0e40bc4e98fd89d6b2bdaf82f0c452039452ca71f2cac9d8fea29ab2
Attacker address
0xc0D6987d10430292A3ca994dd7A31E461eb28182
0x2744d62a1e9ab975f4d77fe52e16206464ea79b7
Attacked contract
0 x82cf66e9a45df1cd3837cf623f7e73c1ae6dff1e (USDC - WETH pool)
1. The first step, the pool creator (0 xc0d6987d10430292a3ca994dd7a31e461eb28182) created the factory contract
(0 x63e6fdadb86ea26f917496beeeaea4efb319229f), when the initialization Feeto address has been set to
Xc0d6987d10430292a3ca994dd7a31e461eb28182 (0).

2. The attacker USDC deployment over the factory contract - WETH pond (0 x82cf66e9a45df1cd3837cf623f7e73c1ae6dff1e), pool initialization time and gave the USDC pool and WETH maximize license contract Feeto address of the factory, You can see that there is a clear risk of centralization.

3. Then, with the maximum authorization, the attacker transfers all the tokens in the pool.

4. It is worth noting that the Owner and Feeto addresses of the factory contract were changed before the attack occurred, but this step is not necessary for the attack. It may be the attacker's operation to confuse others.


Finally, it can be seen that all the funds in the USDC-WETH liquidity pool have been withdrawn, and the attacker has made a total profit of about 1.8 million dollars.
Beosin security team analyzed that this attack mainly took advantage of the centralization problem of the pair contract, which maximized the authorization of the Feeto address in the factory contract during initialization, so that the funds in the pool could be extracted at any time by the Feeto address specified during initialization.
Attacker calls the transferFrom function from the pool turned out 811 k USDC to attackers address 1 (0 x2744d62a1e9ab975f4d77fe52e16206464ea79b7). Attacker address 2 (0 xce4ee0e01bb729c1c5d6d2327bb0f036fa2ce7e2) extracted from token1 contracts (WETH) 435.2 eth, After through Anyswap across the chain to the etheric fang (0 xa7d481944730a88b862eb57248cb1b2c8aa358ad) and addresses
X0b8a3ef6307049aa0ff215720ab1fc885007393d (0), a total profit of about $1.8 million.
As of the time of publication, the anti-money laundering analysis platform Beosin KYT has found that the stolen funds are still stored on the two main Ethereum addresses of the aforementioned attackers. The Beosin security team will continue to monitor and track the stolen funds.



In response to this incident, the Beosin security team suggested that the project should use the multi-signature wallet or DAO governance to manage the addresses with important permissions, and users should also know more about whether the project involves risks when interacting with the project.
Original link
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia