Unverified contract lost $280k due to sandwich attack.

There’s a function that can be used for swapping WBNB to EGA token in victim contract.

This function has no access control, anyone can call this function with only 1 wei.

This is vulnerable to sandwich attack. Hacker swapped large amount of WBNB to EGA, called vulnerable function, and then swapped EGA to WBNB, gained 506 WBNB for free.


Posted

in

by

Tags:

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *