BBX Logo Beta

Aurellion Labs contract stolen 455000 USDC due to vulnerability

--

According to SlowMist, a blockchain security agency, Aurellion Labs' Diamond contract was hacked by an attacker due to the unprotected 'initialize (address)' function in the SafeOwnable Facet. The attacker then re initialized and tampered with the contract owner, injecting malicious Facet containing 'pullERC20' through 'diamondCut' to transfer authorized USDC assets. The affected contracts include addresses 0x0adc63e7..., 0x2e933518..., 0xa90714a1..., 0xeced2d37..., and the attacker's address is 0x9f49591a3b... The loss this time is approximately 455000 USDC.

Loading...