Multi-chain contracts exploited for over $17M via token approval vulnerability
BlockSec Phalcon reported on Jan. 26 that it detected suspicious transactions several hours earlier targeting contracts deployed by two creators across Ethereum, Arbitrum, Base and BSC, with total losses exceeding $17M. The non-open-source contracts appeared to allow arbitrary calls, and the attacker drained assets by leveraging existing token approvals and executing transferFrom operations. One affected deployer address, 0xbeef63AE5a2102506e8a352a5bB32aA8B30B3112, incurred around $3.67M in losses, while another, 0x9cb8d9BaE84830b7f5F11ee5048c04a80b8514BA, lost about $13.41M.