According to ChainCatcher, as disclosed by BlockSec Phalcon, their system detected multiple suspicious transactions targeting two unknown contracts on Ethereum, resulting in a loss of approximately $120,000. The attacker exploited vulnerabilities in the approveERC20 and withdrawAll key functions of the victim contracts, which lacked access control, successfully extracting tokens from the contracts. These victim contracts are not open source and were all deployed by the same address.