🚨SlowMist TI Alert🚨
💸
@Lumi_Finance Loss: ~ $264k
🔍 Root Cause: A vulnerability in Lumi smart accounts allowed token approvals to be performed as a side effect during UserOperation validation. Due to improper validation logic, an attacker-controlled paymaster could trigger approval operations during the validation phase and obtain ERC20 allowances from multiple smart accounts without explicit user intent.
📌 Attacker: 0xce1a3bb0b98d0d90c7dd0620ab86c9a771888d88
📌 Victim: Multiple Lumi smart accounts affected by unintended token approvals during UserOp validation
📌 Malicious contract: 0x56362412ae17cac443aafbab4289946ad958e8a1
The attacker abused a flaw in Lumi smart account UserOperation validation logic to obtain token allowances from multiple wallets through validation-time side effects. The attacker then used the malicious sweeping contract to batch drain approved ERC20 tokens, swapped the stolen assets into ETH, and transferred the proceeds to the attacker-controlled address.
Powered by #
SlowMist#.AI
Tx: