慢雾余弦:Ekubo contract exploited, user loses 17 WBTC
Odaily reported that MistTrack founder Yuxian posted on X platform, stating: “The Ekubo-related contract has been maliciously exploited. The reason is that if a user previously authorized the relevant tokens to: 0x8CCB1ffD5C2aa6Bd926473425Dea4c8c15DE60fd;
For example, this user 0x765DEC granted an unlimited WBTC approval (158 days ago): The attacker could designate the authorized user as the payer and, in the payCallback, make the contract call WBTC transferFrom(victim, Ekubo Core, amount). Then, through the withdraw/pay settlement process of Ekubo Core (0xe0e0e08A6A4b9Dc7bD67BCB7aadE5cF48157d444), the assets were transferred to the attacker. This operation was executed 85 times, each time with 0.2 WBTC, ultimately causing user 0x765DEC to lose 17 WBTC. It is recommended that users promptly check the following contract approvals as advised by the official notice: 0x8ccb1ffd5c2aa6bd926473425dea4c8c15de60fd (V2)
0x4f168f17923435c999f5c8565acab52c2218edf2 (V3)
Arbitrum: 0xc93c4ad185ca48d66fefe80f906a67ef859fc47d (V3).”
