Arbitrum ecosystem exposes new vulnerabilities. According to monitoring data, a series of suspicious transactions involving proxy contracts have recently appeared on the Arbitrum network, with an estimated initial loss of $1.5 million.



From a technical perspective, the culprits are traced back to a single deployer account for USDGambit and TLP projects. The attacker gained access to these accounts through some means and immediately deployed new malicious contracts. More importantly, they also modified the permissions of ProxyAdmin, gaining complete control over the entire proxy contract system.

The stolen funds have already begun to be transferred across chains. The hacker moved these funds from the Arbitrum network to Ethereum, then into the privacy mixer Tornado, demonstrating clear anti-tracking intentions. This serves as a reminder for projects and users within the ecosystem to remain vigilant in contract deployment and permission management, especially considering the risks associated with single-account control configurations.
ARB-2.33%
ETH1.05%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Repost
  • Share
Comment
0/400
TokenSleuthvip
· 01-05 09:33
Here we go again, controlling permissions for a single account is really damn frustrating.
View OriginalReply0
ThatsNotARugPullvip
· 01-05 09:30
Single account control permissions are really a big pitfall; if one private key is compromised, everything is lost.
View OriginalReply0
HodlTheDoorvip
· 01-05 09:27
Here we go again, how many times has it been with Arbitrum? Single account control permissions really damn it
View OriginalReply0
bridge_anxietyvip
· 01-05 09:26
Here we go again. Deploying with a single account is really asking for trouble. How can such a basic mistake still be made...
View OriginalReply0
GasFeeNightmarevip
· 01-05 09:25
Here we go again, Arbitrum is really testing our patience... Single account control permissions are truly a ticking time bomb, how many times have I said this...
View OriginalReply0
TradFiRefugeevip
· 01-05 09:21
The control permissions for a single account really need to be changed. Once again, this has been a lesson for everyone.
View OriginalReply0
MidnightSnapHuntervip
· 01-05 09:17
Here we go again, single account control is really amazing. It should have been disabled long ago.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)