CertiK: Rikkei Finance Attacked Due to Lack of Access Control on setOracleData Function

CertiK tweeted that Rikkei Finance was attacked due to a lack of access control on function setOracleData. The attacker changed the oracle to a malicious contract, and then manipulated prices, borrowed funds to then drain $USDC, $BTCB, $DAI, $USDT, $BUSD and $BNB from the contract in successive transactions. The attacker swapped all of those tokens to 2,671 $BNB (about $1.11 million) and then used Tornado Cash to transfer those $BNB out of his address.
Source

Metaverse

DeFi

Security Incidents

In This Article

Related News
Daily Market Wrap | Apr. 20 Daily Market Wrap | Apr. 20
Daily Market Wrap | Apr. 02 Daily Market Wrap | Apr. 02
Daily Market Wrap | Mar. 20 Daily Market Wrap | Mar. 20
Daily Market Wrap | Feb. 17 Daily Market Wrap | Feb. 17
Daily Market Wrap | Jan. 27 Daily Market Wrap | Jan. 27
Latest News More More
7 Hours Ago Daily Market Wrap | Apr. 27
3 Days Ago Daily Market Wrap | Apr. 24
4 Days Ago Daily Market Wrap | Apr. 23
5 Days Ago Daily Market Wrap | Apr. 22
6 Days Ago Daily Market Wrap | Apr. 21
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open