The Initial Analysis of the bZx Security Incident

2021-11-06 Block Sec

https://blocksecteam.medium.com/the-initial-analysis-of-the-bzx-security-incident-7daf2c6b58f3

Thumbnail for The Initial Analysis of the bZx Security Incident

The attacker drained tokens in the affected smart contracts. After the initial analysis of the attack transactions, we suspect it’s due to the compromised private key of the developer. The privileged function transferOwnership is invoked to transfer the ownership of affected smart contract to a new one, e.g., 0x0acc0e5faa09cb1976237c3a9af3d3d4b2f35fa5. Then the new contract owner can transfer all the tokens that have been approved to the smart contract to arbitrary addresses.

Related Reports

« Back