Unibot hack for $560,000 brought down the price of the token by more than 40%

Member
Joined
Oct 14, 2023
Messages
225
Attackers hacked a popular Telegram bot used to track transactions on the Uniswap decentralized exchange. The volume of losses is estimated at $560,000.

The project team has already confirmed the fact of hacking and suspended the operation of the platform.

"We encountered an exploit on our new router and suspended its operation to fix the problem. Any funds lost due to an error on our new router will be refunded. Your keys and wallets are safe, " the team assured.

We experienced a token approval exploit from our new router and have paused our router to contain the issue.

Any funds lost due to the bug on our new router will be compensated. Your keys and wallets are safe.

We will release a detailed response after investigations conclude.
— Unibot (@TeamUnibot) October 31, 2023

Click to expand...

The company promised to publish a detailed response after the investigation is completed. Against the background of news about the hack, the value of the native UNIBOT token fell by more than 40%.

A blockchain detective named Arhat showed an alleged scheme for hacking Unibot. The attackers wrote pseudocode to break the Unibot contract, which allowed them to bypass balance checking and drain funds through repeated calls: transferFrom.

Allowed to Drain? A Devious Exploit Bypassed Unibot's Balance Checks and Made Off With 300+ ETH

More than 300 ETH was exploited from @TeamUnibot users. More than $500k, at least at the time of writing this.

The hacker wrote a pseudocode to exploit the Unibot contract.

Read…
You do not have permission to view link Log in or register now.

— Arhat (@0xArhat) October 31, 2023
Click to expand...

Beosin experts also pointed out that the attacker made changes to the bot code.

#Unibot exploited
Hacker:
You do not have permission to view link Log in or register now.


The root cause is CAll injection, where an attacker can pass custom malicious calldata into the 0xb2bd16ab() method to transfer tokens approved to Unibot contracts.

Users need to revoke approval for…
You do not have permission to view link Log in or register now.

— Beosin Alert (@BeosinAlert) October 31, 2023




Previously unknown attackers attacked the Maestro telegram bot, the largest one used for trading cryptocurrencies. The amount of damage is 280 ethers ($500,000).
 
Top