Atomic protocol hit by signature replay attack, loses about 29,984 USDC

Atomic protocol, a decentralized exchange, lost approximately 29,984 USDC in an attack tied to a signature replay vulnerability, SlowMist said. The flaw came from contract 0xa806010f, where the signature hash did not bind key parameters including position ID, position manager, caller, nonce, deadline and chain ID. That allowed the same manager signature to be replayed across 21 different position IDs. The attacker then carried out unauthorized full LP destruction during flash loan price manipulation, without TWAP (time-weighted average price) or slippage checks that are typically used to reduce execution risk and price manipulation exposure.

本网站上的信息是使用AI生成的,我们无法保证其准确性。 请仅作为参考信息使用。