DEX Atomic was attacked due to a signature replay vulnerability, resulting in a loss of approximately 30,000 USDC
According to SlowMist monitoring, the decentralized exchange Atomic protocol was attacked due to a signature replay vulnerability, resulting in a loss of approximately 29,984 USDC.
The vulnerability originated from contract 0xa806010f, which lacked binding of position ID, position manager, caller, nonce, deadline, and chain ID in the signature hash, allowing the same manager's signature to be replayed on 21 different position IDs, executing unauthorized full LP destruction under flash loan price manipulation, and without TWAP or slippage checks.
Related tags






