Buy Crypto
Markets
Spot
Futures
Earn
Promotion
More
reward-centerNewcomer Zone
Feed HomeFlash details
밸런서 V1 풀 $23만 취약점 공격 피해
  • BAL0%
  • USDC0%
  • WBTC0%
  • WBTC-0.34%

밸런서(BAL) V1 BPool에서 계산 오차를 악용한 공격으로 약 23만4000달러어치 자산을 탈취당했다고 슬로우미스트(SlowMist)가 전했다. 공격자는 공개 스왑을 반복해 풀 내 WBTC 잔액을 거의 바닥까지 줄인 뒤, `joinswapPoolAmountOut` 함수에서 필요한 WBTC 투입량이 1 sat에 해당하는 수준으로 계산되도록 만들었다. 이후 이 극소량의 WBTC을 입금하고 총 4408.8 BPT를 발행받아 풀에서 DPI, USDC, WETH, WBTC를 빼냈다. 공격에 필요한 자금은 스파크·아베, 모포, 유니스왑 V3에서 플래시론으로 조달했다. 슬로우미스트는 최소 투입량이나 최소 풀 잔액 기준, 계산 오차를 걸러내는 검증 절차가 없었던 점을 취약점의 원인으로 지목했다.

Source: CoinNess

Disclaimer: The current content is sourced from third-party perspectives or directly translated by AI from third-party perspectives. CoinEx does not guarantee the authenticity, accuracy, and originality of the content, and it does not constitute any investment advice from CoinEx. The prices of cryptocurrencies are highly volatile, please be aware of the potential risks.

Hot
  • Coins
    Price
    24H Change