Flash News
GoPlusSecurity: Analysis of the 13 July attack, loss of approximately $270,000
GoPlusSecurity issued an analysis of the 13 July attack, which resulted in a loss of approximately $270,000. The analysis indicated that the Validateuserop function in the Sodium Smart Account Contract (ERC-4337) had a logical loophole in calling the validatesignature function for signature verification: in executing the Svalidsignturenow, the signaturer parameter was set as the address of the assailant. When the ecdsa.tryecover function failed, it was not able to roll back, but instead called the Svalaidsignature function in the attacker-controlled contract, which was finally validated。
