SlowMist: ether.fi Suffers 15.45 ETH Loss Due to AtomicQueue Access Control Vulnerability
According to a SlowMist security alert, ether.fi lost approximately 15.45 ETH due to an access control vulnerability in the solve() function of its AtomicQueue contract. The attacker created a malicious request via updateAtomicRequest() to force a victim's address as the solver, subsequently triggering the victim's finishSolve and executing want.transferFrom to misappropriate funds using existing ERC-20 approvals. SlowMist has disclosed the incident to the ether.fi team, and the addresses of the attacker and the vulnerable contract have been identified.
Summaries are written by AI from the original article. Not investment advice.