SlowMist: Rubic protocol wrongly adds USDC to Router whitelist

12/25 14:06

According to the SlowMist, on December 25, 2022, the Rubic cross-chain aggregator project was attacked, resulting in the theft of USDC from user accounts. The Slow Fog security team shared the following in a newsletter. 1. Rubic is a DEX cross-chain aggregator that allows users to exchange Native Token via the routerCallNative function in the RubicProxy contract. Before the exchange, it checks whether the target Router to be called is in the whitelist of the protocol. 2. After the whitelist check, the target Router is called and the call data is passed in externally by the user. 3. Unfortunately USDC is also added to the Rubic protocol's Router whitelist, so any user can invoke USDC at will via the RubicProxy contract. 4. The malicious user exploits this issue by calling the USDC contract via the routerCallNative function to transfer USDC from a user who has authorized the RubicProxy contract to the malicious user's account via the transferFrom interface. The root cause of this attack is that the Rubic protocol incorrectly adds USDCs to the Router whitelist, resulting in the theft of USDCs from users who have authorised the RubicProxy contract.
bullishbullishbullish1bearishbearishbearishGiảm giáThíchChia sẻ
Tuyên bố miễn trừ trách nhiệmNội dung trên không đại diện cho quan điểm của HTX.HTX không đưa ra bất kỳ lời khuyên giao dịch nào.

Bài viết liên quan

  • Image

    $500 mln USDC added to Solana: What it means for liquidity

  • Image

    All about first-ever stablecoin insurance premium – USDC, PYUSD & what’s next!

  • Image

    XDC launches real-world USDC spending as stablecoins cross $307B

Tất cả bình luận0Mới nhấtPhổ biến

avatar
Mới nhấtPhổ biến

Bài viết liên quan

  • Image

    $500 mln USDC added to Solana: What it means for liquidity

  • Image

    All about first-ever stablecoin insurance premium – USDC, PYUSD & what’s next!

  • Image

    XDC launches real-world USDC spending as stablecoins cross $307B