Flash News
Analyst: TabProxyActions contract attacked by access control loophole, 5.94 ETH stolen
According to SlowMist monitoring, the GebProxyActions contract resulted in the theft of about 5.94 ETH because of the lack of caller access controls. The victim called directly to the gebproxyactions.quitsystem instead of dsproxy commissioning, leading to the setting of the "ownssafe " [safe] as the GebProxyActions contract, and the attackers called directly to the gebproxyactions.quitsystem (manager, safe, dst) bypassing the safeallowed inspection of the gebsafemanager and transferring the collateral to themselves。
