Atomic protocol suffers signature replay vulnerability attack, resulting in a loss of approximately 29984 USDC

--

According to SlowMist Monitoring, the decentralized exchange Atomic protocol was attacked due to a signature replay vulnerability, resulting in a loss of approximately 29984 USDC. The vulnerability arises from the lack of position ID, position manager, caller, nonce, deadline, and chain ID binding in the signature digest of contract 0xa806010f, which allows the same manager signature to be replayed on 21 different position IDs, resulting in unauthorized full LP destruction under lightning loan price manipulation without TWAP or slippage checks.

Loading...