Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesBotsEarnCopy
BlockSec: The attack on Unibot may be due to the lack of input validation of function 0xb2bd16ab in the 0x126c contract

BlockSec: The attack on Unibot may be due to the lack of input validation of function 0xb2bd16ab in the 0x126c contract

CointimeCointime2023/10/31 07:06
By:Cointime

BlockSec stated on social media that due to Unibot's code not being open source, we suspect that the function 0xb2bd16ab in the 0x126c contract lacks input validation, allowing for arbitrary calls. Therefore, attackers can call "transferFrom" to transfer the approved tokens out of the contract. Please revoke approval as soon as possible.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Friday charts: The Marvin Minsky moment is here

Have markets been obsessing over the wrong Minsky?

Blockworks2025/04/26 08:00
Friday charts: The Marvin Minsky moment is here

Charles Hoskinson Reveals Exciting Plans for Lace Wallet’s XRP Functionality

In Brief Charles Hoskinson announces XRP functionality for Lace wallet. Integration aims to enhance multi-chain support and user experience. Upcoming NIGHT token distribution includes XRP holders.

Cointurk2025/04/26 08:00
Charles Hoskinson Reveals Exciting Plans for Lace Wallet’s XRP Functionality