Security researcher: CEX was arbitraged by MEV Bots for $300,000 due to improper interaction with 0x exchange contracts.

robot
Abstract generation in progress

[Security Researcher: CEX lost $300,000 to MEV Bots due to improper interaction with 0x exchange contract] CEX's misconfiguration in interacting with the 0xProject's "swapper" contract resulted in approximately $300,000 in Token transaction fees being intercepted by MEV Bots. Venn Network's security researcher, "X" user deeberiroz, disclosed on Wednesday that the CEX interacted with the "swapper" smart contract of the decentralized peer-to-peer trading platform 0x, which was never designed for Token authorization operations. The "swapper" contract provided by 0xProject is used for executing Token exchanges. This contract is permissionless, allowing anyone to call it to perform any operation without ownership restrictions. However, it is not designed for receiving Token authorizations, as doing so could expose funds to risk. Researchers have indicated that this design has previously led to known issues, such as an incident involving the Zora airdrop on the BaseLayer2 network.

ZRX3.53%
ZORA-5.41%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)