BlockSec stated on social media that due to Unibot's code not being open source, we suspect that the function 0xb2bd16ab in the 0x126c contract lacks input validation, allowing for arbitrary calls. Therefore, attackers can call "transferFrom" to transfer the approved tokens out of the contract. Please revoke approval as soon as possible.