The security alert said missing access controls and weak target-data checks let an attacker abuse existing ERC20 allowances to trigger unauthorized transferFrom calls.
An unverified contract was exploited through an unrestricted low-level call tied to selector 0x42be3129, allowing an attacker to drain about 16.6 WETH. SlowMist said the contract lacked access control and did not properly validate target data, which let the attacker rely on existing ERC20 allowances (token spending permissions) to bypass owner checks and execute unauthorized transferFrom calls.