SlowMist|Aug 26, 2026 03:34
🚨SlowMist TI Alert🚨
💸 @enjin Loss: ~$162k
🔍 Root Cause: The protocol allows adapters with different storage layouts to execute in the storage context of the Managed Delegate Proxy via DELEGATECALL. However, the public initialize(uint256) function of a registered adapter writes to the adapter's slot 1, while the proxy also uses slot 1 to store pendingManager. An attacker can exploit this storage slot collision by invoking the adapter's initialize(uint256) through DELEGATECALL, causing their own address to be written into the proxy's pendingManager slot. They can then simply call acceptManager() to complete the privilege takeover and gain managerial control of the protocol.
- Attacker EOA: 0x5ec1ba7892d11059c39557b762a97dd695778ca5
- Attack Contract: 0x7083ddece38216c7741fa76c75326bea744ed321
- Compromised Proxy: 0x268c039a3127d3107c014f0dc6c390a53e6db27f
⚠️ After gaining manager rights, the attacker registered a malicious adapter to steal victims' assets and routed them through `melt(0xf6089e12)` path for liquidation.
Powered by http://SlowMist.AI
Tx: https://etherscan.io/tx/0xd4a382da03c99ce3084661b913b50b525a4b283f66f510bcf1040152830b2a7e(SlowMist)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink