SlowMist Reports 5.94 ETH Stolen Due to GebProxyActions Contract Vulnerability
SlowMist reported that the GebProxyActions contract suffered a loss of approximately 5.9436 ETH due to a lack of caller access control. The vulnerability occurred because affected users called the GebProxyActions.quitSystem function directly instead of using a DSProxy delegated call, which caused the ownsSAFE[safe] parameter to be incorrectly set to the GebProxyActions contract. Attackers exploited this by calling the quitSystem function directly, bypassing the GebSafeManager's safeAllowed check to transfer collateral to their own addresses.
Not investment advice.