Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Beosin: The administrator's private key of the wazirx multi-signature wallet was leaked, resulting in the theft of assets

Beosin: The administrator's private key of the wazirx multi-signature wallet was leaked, resulting in the theft of assets

CointimeCointime2024/07/18 09:22
By:Cointime

Beosin Alert monitoring and warning system discovered that the Indian exchange WazirX was attacked. The attacker obtained the signature data of the exchange's multi-signature wallet administrator and modified the wallet's logical contract to execute incorrect logic in order to steal assets. Based on the attacker's behavior, it is speculated that the reason for the attack was the leakage of the administrator's private key for the multi-signature wallet. Beosin's analysis of the attack is as follows:1. The attacker deployed an attack contract that extracts the specified token assets of this contract.2. The attacker obtained the signature data of the WazirX multi-signature wallet administrator and modified the wallet's logical contract to the already deployed attack contract.3. The attacker submitted a token withdrawal transaction to the WazirX multi-signature wallet. Due to the mechanism of the proxy mode, the wallet contract will use delegatecall to call the relevant functions of the attack contract, transferring the wallet tokens.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Bitget Spot Bot adds PUMP/USDT

Bitget Announcement2025/07/15 08:00

New spot margin trading pair — PUMP/USDT!

Bitget Announcement2025/07/15 06:58