Der Hack des Seneca-Protokolls verdeutlicht die Gefahren des Token-Genehmigungsmechanismus von Ethereum
A bug in crypto lending platform Seneca Protocol was exploited on Wednesday to steal funds directly from users wallets. Losses so far exceed $3 million on the Ethereum and Arbitrum networks. Seneca is a decentralized finance (DeFi) project that allows users to borrow the stablecoin senUSD against yield-bearing assets such as deposit tokens and liquid staking tokens (LSTs). The suspicious transactions were brought to the attention of the crypto community by pseudonymous X (formerly Twitter) user Spreek. Crypto security researcher Daniel Von Fange identifiziert the bug in Seneca‘s code, adding that he was removed from the project’s Discord where the team was deleting references to the exploit. Another user, going by ‘cawfree’ on X, aus aller Welt to have warned the project of this exact issue in November, before being blocked by Seneca. An audit contest was also verlassen in November, five days before launch. Laut Sicherheitsfirma Peckschild, the contracts in question are unable to be paused, leaving the users themselves responsible for revoking token approvals to the affected addresses. We are actively working with security specialists to investigate the approval bug found today. In the meantime, REVOKE approvals for the following addresses:#Ethereum PT-ezETH 0x529eBB6D157dFE5AE2AA7199a6f9E0e9830E6Dc1 apxETH 0xD837321Fc7fabA9af2f37EFFA08d4973A9BaCe34… — Seneca (@SenecaUSD) 28. Februar 2024 What are token approvals? Unlike regular users Ethereum addresses,