WINR Hack
检查您的地址是否受到影响。
31 May 2024
$11k 被盗
Around $11k (roughly 293k WINR tokens) was stolen from users of WINR Protocol (JustBet), a gaming protocol on Arbitrum. Its MixedSwapRouter accepted a caller-supplied payer address in its Algebra swap callback and pulled tokens from that address with transferFrom, without checking that the caller was a legitimate pool. An attacker triggered the callback through a fake pool with the payer set to a wallet that had approved the router, spending that approval to drain its tokens. Anyone who approved the WINR MixedSwapRouter should revoke.
受影响的用户只要没有撤销他们的授权,就仍处于风险之中。因此我们建议您使用下方的 Revoke.cash 漏洞检查器,以确保您的安全。
来源:x.com