SlowMist says ether.fi AtomicQueue flaw led to theft of about 15.45 ETH

SlowMist says ether.fi AtomicQueue flaw led to theft of about 15.45 ETH

N
News Editor
2026-09-11 09:36:54
SlowMist said ether.fi’s AtomicQueue contract was exploited because the solve() function lacked access control, leading to the theft of about 15.45 ETH. According to the security alert, the attacker used updateAtomicRequest() to create a malicious request and forced a victim address to act as the solver. AtomicQueue then called the victim’s finishSolve and executed want.transferFrom, abusing an existing ERC-20 approval to move funds. SlowMist said it had privately disclosed the issue to the ether.fi team before making it public. The attacker address and the vulnerable contract address have also been released. The disclosure outlines a case in which previously granted token approvals were used in an unintended way through contract logic rather than through direct wallet compromise.

According to a SlowMist security alert cited by ChainCatcher, ether.fi’s AtomicQueue contract was exploited because its solve() function lacked access control, resulting in the theft of about 15.45 ETH.

How the exploit worked

SlowMist said the attacker used updateAtomicRequest() to create a malicious request and force a victim address to be set as the solver. AtomicQueue then called the victim’s finishSolve and executed want.transferFrom, abusing the victim’s existing ERC-20 approval to transfer funds.

Disclosure status

SlowMist said it had privately disclosed the issue to the ether.fi team before the public alert. The attacker address and the vulnerable contract address have also been published.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.