Skip to content
← Back to newsThe Whale Lost $25,000,000 Due to a Known Smart Contract Vulnerability
Security

The Whale Lost $25,000,000 Due to a Known Smart Contract Vulnerability

By ToTo BugelmanNewcomer0 rep· 11/11/2024

On November 10, user @qklpjeth on X.com posted a plea for help from anyone who could assist in extracting ezETH from a smart contract to which he appears to have mistakenly sent his assets. As an incentive, @qklpjeth is offering 10% of the lost amount, which currently amounts to $2.6 million in ezETH tokens.

 

 

What is Known About the Incident

An analysis of the transactions reveals that in April 2024, the user acquired ezETH tokens and apparently chose to store them using a Gnosis Safe multisignature wallet.

However, the second transaction turned out to be a mistake. Instead of the Gnosis Safe, 7,912.311 ezETH ($26,000,000 for now) were sent to the address of a smart contract for another cryptocurrency storage service, Cobo Safe, which can act as an additional module for Gnosis Safe.

 

 

Given that the user is seeking assistance, it is evident that he does not have access to the Cobo Safe extension. Considering this and the fact that smart contracts cannot process incoming ERC-20 token transfers and are simply unaware of incoming funds, it can be assumed that the user's funds are permanently lost.

 

Expert Comments

The situation drew a reaction from smart contract security engineer Dexaran. He emphasized that this vulnerability has been known for 7 years but has been ignored by the Ethereum Foundation.

Dexaran is known as the head of Ethereum Commonwealth and the author of the ERC-223 standard, aimed at addressing these vulnerabilities.

 

 

Solutions for ERC-20 Vulnerability

The ERC-223 standard is capable of completely resolving this ERC-20 vulnerability, offering a communication model between the token smart contract and the receiving smart contract. According to this model, the target smart contract is always aware of incoming ERC-223 tokens. If the smart contract is not designed to work with ERC-223 tokens, the transaction is rejected, keeping the user's funds safe.

The ERC-223 and ERC-20 standards are not backward-compatible; however, a converter (EIP-7417) was developed to simplify ecosystem updates, enabling token conversion in both directions as needed by users and applications.

To promote and adopt ERC-223, the DEX223 platform is currently under development, which could become a significant innovative leap for the EVM blockchain ecosystem.

Links:

Dex223 website: https://www.dex223.io

ERC-20 Issues: https://ethereum.org/en/developers/docs/standards/tokens/erc-20/#erc20-issues

ERC-20 Live Losses Calculator: https://dexaran.github.io/erc20-losses

ERC-223 official documentation published on Ethereum: https://eips.ethereum.org/EIPS/eip-223

https://ethereum.org/en/developers/docs/standards/tokens/erc-223/

Telegram: https://t.me/Dex223_defi

X: https://x.com/dex_223

https://x.com/erc_223

Youtube: https://www.youtube.com/@erc223

Reddit: https://www.reddit.com/r/Dex223

https://www.reddit.com/r/ERC223

Medium: https://dexaran820.medium.com/

https://medium.com/dex223

Github: https://GitHub.com/Dexaran/Dex223-exchange

https://github.com/Dexaran/ERC223-token-standard

 

Sources:

https://x.com/Dexaran/status/1855991828912431332

https://x.com/Dexaran/status/1855994784273580249

https://x.com/Dexaran/status/1856000084053524718

 

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

The Whale Lost $25,000,000 Due to a Known Smart Contract Vulnerability | BlockzHub