Since 09/11/2024, Blocksec monitored hundreds of suspicious tx targeting InfernoBullWin, each tx gained about $1.5k.
Victim contract has “swapTitanXForInfernoAndBurn” function which exchanges its “Titan” tokens to “Inferno” tokens, and then burns “Inferno” tokens. Anyone can call this function.
data:image/s3,"s3://crabby-images/85df6/85df6f07691d7b3c6941938ca7f4aaa1c852e4c4" alt=""
This function was used for sandwich attack. Drainers swapped large amount of “Titan” to “Blaze”, and then called “swapTitanXForInfernoAndBurn”. After that exchanged “Blaze” to “Titan”, “Titan” to “Eth”.
data:image/s3,"s3://crabby-images/c57ef/c57ef5a122f365875f3e44429acec5031b4e0443" alt=""
“swapTitanXForInfernoAndBurn” function should have modifier like “onlyOwner” to prevent being called by anyone.
Leave a Reply