SlowMist reports that a Router contract on BNB Chain was exploited for approximately 62.28 BNB due to security flaws in its Swap entry and the uniswapV3SwapCallback function. The Router failed to verify the caller as a legitimate V3 Pool, allowing attackers to forge a pool and misuse user approvals. Users who had granted token approval to the Router are at risk of asset theft even without further interaction.
SlowMist said a Router contract on BNB Chain got exploited because of security bugs in its Swap entry and the uniswapV3SwapCallback function, with losses of about 62.28 BNB.
The issue was pretty direct. The Router did not check whether the caller was a real V3 Pool, and it also failed to tie the payer in the callback to the original transaction context.
That opened the door. The attacker spoofed a V3 Pool/adapter and slipped the victim's address in as the payer, then used the ERC-20 approval that had already been given to the Router to call transferFrom() and move assets.
And SlowMist gave a clear warning: users who had given the Router enough token approval could still have those approved assets stolen, even without doing anything else.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.