BBX Logo Beta

--

[Attackers Exploit EIP-7702 Vulnerability to Steal 1,988.5 QNT] According to disclosures by SlowMist, attackers exploited the EIP-7702 vulnerability to steal 1,988.5 QNT (approximately 54.93 ETH) from the QNT reserve pool. The vulnerability originated from the reserve pool administrator's EOA delegating code execution to the BatchExecutor contract, which in turn authorized the BatchCall contract without proper access control. Due to the lack of permission verification in the BatchCall.batch() function, any external caller could invoke it, resulting in the depletion of the reserve pool's assets.

Loading...