SlowMist said the EtherVistaPair contract contained an integer overflow flaw in its swap() function, allowing an attacker to drain liquidity from the pool. According to the security team’s post on X, both reserves in the contract were stored as uint112 values. Their product could overflow and wrap around, which meant the K-value check could still pass even when the actual reserve product had fallen sharply. SlowMist said the attacker used a malicious contract that had been registered as an authorized router and carried out two carefully structured swap transactions. The exploit drained WETH and VISTA from the liquidity pool. SlowMist also disclosed the addresses tied to the incident, including the attacker wallet, the attack contract used as the router, and the vulnerable contract. The reported loss was about $18,600.
Techub News reported that SlowMist said in a post on X that the EtherVistaPair contract had an integer overflow vulnerability in its swap() function.
According to SlowMist, both reserves were stored as uint112 values. Their product could overflow and wrap around, allowing the K-value check to pass even when the actual product of the reserves had dropped sharply.
SlowMist said the attacker used a malicious contract that had been registered as an authorized router and executed two carefully crafted swap transactions, draining WETH and VISTA from the liquidity pool.
The attacker address was 0xbbf8f3fe8e4fdf6b594e6107144d78293d2018fa. The attack contract, used as the router, was 0x469424b628a9d2036e41496e814db500d683b120. The vulnerable contract address was 0xfdd05552f1377aa488afed744c8024358af02041. SlowMist said the attack caused losses of about $18,600.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.