SlowMist: ether.fi lost approximately 15.45 ETH due to a vulnerability in the access control of the AtomicQueue contract
According to SlowMist's security alert, the AtomicQueue contract of ether.fi was exploited due to the lack of access control in the solve() function, resulting in approximately 15.45 ETH being stolen.
The attacker created malicious requests using updateAtomicRequest(), forcing the victim's address to act as the solver. Subsequently, AtomicQueue called the victim's finishSolve and executed want.transferFrom, abusing the victim's existing ERC-20 authorization to transfer funds. SlowMist has privately disclosed the attacker’s address and the vulnerability contract address to the ether.fi team.






