CertiK: Rikkei Finance Attacked Due to Lack of Access Control on setOracleData Function

CertiK tweeted that Rikkei Finance was attacked due to a lack of access control on function setOracleData. The attacker changed the oracle to a malicious contract, and then manipulated prices, borrowed funds to then drain $USDC, $BTCB, $DAI, $USDT, $BUSD and $BNB from the contract in successive transactions. The attacker swapped all of those tokens to 2,671 $BNB (about $1.11 million) and then used Tornado Cash to transfer those $BNB out of his address.
Source

Metaverse

DeFi

Security Incidents

In This Article

Related News
Bernstein names Robinhood as top 'crypto deregulation trade,' raises price target to $51 Bernstein names Robinhood as top 'crypto deregulation trade,' raises price target to $51
Radiant Capital hacker moves $52M in stolen funds Radiant Capital hacker moves $52M in stolen funds
Tesla likely still owns $780M in Bitcoin despite recent shuffle: Arkham Tesla likely still owns $780M in Bitcoin despite recent shuffle: Arkham
Cardano shifts to decentralized governance as Chang hard fork goes live Cardano shifts to decentralized governance as Chang hard fork goes live
Ton developers adopt ‘Resistance Dog’ memecoin avatar to support Pavel Durov; token jumps 140% Ton developers adopt ‘Resistance Dog’ memecoin avatar to support Pavel Durov; token jumps 140%
Latest News More More
Arbitrum, Azuki-backed Animecoin unveils tokenomics with over 50% community allocation
Singapore bans Polymarket amid national crackdown on online gambling sites
2 Days Ago Mantra and Damac sign $1B deal to tokenize Middle Eastern assets
2 Days Ago Fetch.ai launches $10M accelerator for AI agent startups
3 Days Ago Fidelity’s spot bitcoin, ether ETFs post largest daily net outflows since inception
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open