SlowMist Introduces xToken Hack Event Analysis
According to the SlowMist Zone report, the Ethereum DeFi xToken project has been under attack, resulting in a loss of around $ 25 million, and the review by SlowMist's security team is as follows: The two modules hacked this time are the xBNTa contract and the xSNXa contract on xToken. Both deals were marred by "counterfeit trade" attacks and oracle attacks, respectively. 1) xBNTa contract against analysis 1. The xBNTa deal contains a mint feature that allows users to trade ETH into BNT using Bancor Netowrk and exchange coins based on the exchange rate provided by the Bancor network. 2. There is a different way in the mint function used to convert ETH to BNT through the Bancor network, but the cost of the method can be passed on by the user. 3. Since the attacker is crossing a forged path, the xBNTa contract uses the previous attacker's method to exchange tokens in order to achieve the objective of exchanging coins using different pairs. The contract itself fulfills the unreliable advertising purpose, going beyond the limits that ETH / BNT trading partners are required to use for trading. 2) xSNXa contract against analysis 1. The xSNXa deal contains a special mint that allows users to transfer ETH to xSNX using the Kyber Network compiler exchange. 2. By controlling the price of the ETH / SNX trading partner in the Lightning Uniswap loan, the attacker can intercept the reports of the SNX / ETH trading partner and then intercept the quotes on the Kyber network. Therefore, this affects the value obtained from the xSNXa contract. 3. The opponent uses the amount of checks to give coins to reach the goal of the strike.
Weekly News
Cryptocurrencies Market
Flash News
-
25 01-27 07:53以太坊官推转帖:zkSync稳定币市值30天内增长55%
-
25 01-27 07:47CZ:坚持基于基本面的投资,时间将站在这一边
-
25 01-27 07:45Jupiter完成30亿枚JUP销毁,当前价值约32亿美元
-
25 01-27 07:39Vitalik呼吁加速淘汰Groth16信任设置
-
25 01-27 07:30金色晨讯|1月27日隔夜重要动态一览
-
25 01-27 07:17BTC跌破103500美元
-
25 01-27 07:15AAVE跌破320美元
-
25 01-27 07:14ORDI跌破20美元
-
25 01-27 07:11APT跌破8美元
-
25 01-27 07:02TON跌破5美元
-
25 01-27 07:02BTC跌破104000美元
-
25 01-27 06:51CryptoQuant创始人:Memecoin与艺术市场在估值逻辑上类似
-
25 01-27 06:46SOL跌破250美元
-
25 01-27 06:44美联储本周维持利率不变的概率为99.5%
-
25 01-27 06:01THETA跌破2美元
-
25 01-27 05:16BTC跌破105000美元
-
25 01-27 04:151.8亿枚USDT从TetherTreasury转移到Bitfinex
-
25 01-27 03:49目前加密货币总市值为3.762万亿美元,24小时跌幅1.3%
-
25 01-27 02:46JUP突破1.2美元,24小时涨幅超20%
-
25 01-27 02:15美国现货比特币ETF链上总持仓价值突破1240亿美元











