SlowMist detected an unverified contract being attacked, resulting in 16.6 WETH stolen
The SlowMist security team detected an unverified contract that exposed an unrestricted low-level call vulnerability due to selector 0x42be3129, lacking access control and target data verification, resulting in 16.6 WETH stolen. The attacker used the existing ERC20 authorization limit of the contract to bypass the owner's check and execute unauthorized transferFrom operations.