Skip to content

Latest commit

 

History

History
55 lines (21 loc) · 1.74 KB

CoW-Swap.md

File metadata and controls

55 lines (21 loc) · 1.74 KB

CoW Swap

CoW Swap

  • Amount Lost: $160,000.00
  • Funds Returned: $0.00
  • Category: Exchange (DEX)
  • Date: 2023-2-7

Quick Summary

On Feb. 7, the CoW Swap fee manager contract was drained of worth 160k $USD.

Details of the Exploit

The CoW Swap uses external resolvers for swap routing to find the best exchange way. The solver also receives a protocol fee. granted approval for the malicious contract. 27 Feb the malicious contract was approved by the whitelisted solver. After that, the hacker received an opportunity to drain the fee collector contract.

Block Data Reference

Exploit TX:

https://etherscan.io/tx/0x90b468608fbcc7faef46502b198471311baca3baab49242a4a85b73d4924379b

Malicious call:

https://etherscan.io/tx/0x92f906bce94bab417cccc87ae046448d7fb8c2c0350b7ed911545577acb3bfc1

Exploiter:

https://etherscan.io/address/0xc0e82c1ed4786f8b7f806d1b8a6335ec485266ff

https://etherscan.io/address/0x94b6f400df694d0de29f600b15baeed83e95658c

Proof Links: