SlowMist: Rubic protocol wrongly adds USDC to Router whitelist

12/25 14:06

According to the SlowMist, on December 25, 2022, the Rubic cross-chain aggregator project was attacked, resulting in the theft of USDC from user accounts. The Slow Fog security team shared the following in a newsletter. 1. Rubic is a DEX cross-chain aggregator that allows users to exchange Native Token via the routerCallNative function in the RubicProxy contract. Before the exchange, it checks whether the target Router to be called is in the whitelist of the protocol. 2. After the whitelist check, the target Router is called and the call data is passed in externally by the user. 3. Unfortunately USDC is also added to the Rubic protocol's Router whitelist, so any user can invoke USDC at will via the RubicProxy contract. 4. The malicious user exploits this issue by calling the USDC contract via the routerCallNative function to transfer USDC from a user who has authorized the RubicProxy contract to the malicious user's account via the transferFrom interface. The root cause of this attack is that the Rubic protocol incorrectly adds USDCs to the Router whitelist, resulting in the theft of USDCs from users who have authorised the RubicProxy contract.
bullishbullishbullish1bearishbearishbearishAyıBeğenPaylaş
Sorumluluk ReddiYukarıdaki içerik HTX'ın tutumunu temsil etmez.HTX herhangi bir alım satım önerisinde bulunmaz.

İlgili Makaleler

  • Image

    $500 mln USDC added to Solana: What it means for liquidity

  • Image

    All about first-ever stablecoin insurance premium – USDC, PYUSD & what’s next!

  • Image

    XDC launches real-world USDC spending as stablecoins cross $307B

Tüm Yorumlar0En yeniPopüler

avatar
En yeniPopüler

İlgili Makaleler

  • Image

    $500 mln USDC added to Solana: What it means for liquidity

  • Image

    All about first-ever stablecoin insurance premium – USDC, PYUSD & what’s next!

  • Image

    XDC launches real-world USDC spending as stablecoins cross $307B