Security Alert: The Ekubo EVM Chain Trading Router Contract in the DEX Protocol Has a Security Vulnerability

BlockBeats News, May 6 — Starknet ecosystem DEX protocol Ekubo issued a security alert, stating that there is a security vulnerability in the transaction routing contract on its EVM chain. Liquidity providers and users on Starknet are not affected. An investigation into the scope of the impact is currently underway, and all users are advised to immediately revoke related contract permissions.

Additionally, Cosine, founder of SlowMist, stated that Ekubo attackers used the payCallback mechanism to designate users who had previously granted unlimited token permissions to the contract as payers, thereby calling the WBTC transferFrom function to transfer the victim’s assets. A total of 85 operations were executed, each transferring 0.2 WBTC, with user 0x765DEC suffering a total loss of 17 WBTC.

WBTC0.94%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin