Security firm: Aurellion Labs contract suffered a reentrancy initialization attack, resulting in the loss of approximately 455,000 USDC.
ChainCatcher news, blockchain security firm SlowMist tweeted that the Diamond contract related to Aurellion Labs was exploited because the `initialize(address)` function in the SafeOwnable Facet was unprotected. The attacker reentered to initialize and tampered with the contract owner, then executed `diamondCut` to inject a malicious Facet containing `pullERC20`, thereby transferring authorized USDC assets. SlowMist stated that the affected contracts include 0x0adc63e7... (victim contract), 0x2e933518..., 0xa90714a1..., 0xeced2d37..., and so on. The attacker’s address is 0x9f49591a3b..., and the total loss is approximately 455,003 USDC.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
BlackRock (BLK.US) and IFM are close to finalizing a $25 billion acquisition of Stack’s Asia-Pacific data centers.
According to informed sources, a consortium backed by BlackRock and IFM Investors Pty has entered exclusive talks for the potential acquisition of Stack Infrastructure Inc.'s Asia-Pacific data centers.
BHP Suspends Escondida Mining Operations After Fatal Accident
Market Chatter: BlackRock-Backed Group Enters Talks for Stack's Asia Data Centers

Four.meme: BNC4 and BNCB are open for 1:1 two-way exchange

