最新报道:According to a report from Bijie.com on October 15th, BlockSec Phalcon issued an alert stating that its system had detected several suspicious transactions (initiated by different EOAs) targeting two unknown contracts deployed to the same Ethereum address a few hours earlier, resulting in losses of approximately $120,000. The root cause is suspected to be a lack of access control in the key functions approveERC20 and withdrawAll within the compromised contracts (which are not open source), allowing the attacker to drain all tokens held within the contracts. Notably, the withdrawAll function requires the destruction of a sufficient amount of #sil tokens. This explains why, in the second attack transaction (TX2), which caused the majority of the losses, the attacker first obtained #sil tokens through a flash loan, then conducted multiple token swaps before carrying out the actual attack.