CertiK: Rikkei Finance Attacked Due to Lack of Access Control on setOracleData Function

CertiK tweeted that Rikkei Finance was attacked due to a lack of access control on function setOracleData. The attacker changed the oracle to a malicious contract, and then manipulated prices, borrowed funds to then drain $USDC, $BTCB, $DAI, $USDT, $BUSD and $BNB from the contract in successive transactions. The attacker swapped all of those tokens to 2,671 $BNB (about $1.11 million) and then used Tornado Cash to transfer those $BNB out of his address.
Source

Metaverse

DeFi

Security Incidents

In This Article

Related News
North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms
Term Finance recovers $1 million of $1.6 million loss to oracle configuration error Term Finance recovers $1 million of $1.6 million loss to oracle configuration error
Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain
Stablecoin neobank Infini exploited for $49 million: security analysts Stablecoin neobank Infini exploited for $49 million: security analysts
Wildcat, the decentralized credit platform built by Crypto Twitter mainstay Laurence Day, launches new version on Ethereum Wildcat, the decentralized credit platform built by Crypto Twitter mainstay Laurence Day, launches new version on Ethereum
Latest News More More
4 Hours Ago Daily Market Wrap | Aug. 19
1 Day Ago Daily Market Wrap | Aug. 18
4 Days Ago Daily Market Wrap | Aug. 15
5 Days Ago Daily Market Wrap | Aug. 14
6 Days Ago Daily Market Wrap | Aug. 13
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open